But, as you know, if you criticise, you have to offer something instead. Today Andrey presents us the idea of "neoclassic" CTF.
1. We check, how the participants can attack and defend. Not explore the image, not sniff the traffic, but create exploits and close the vulnerabilities. So the first idea: allow to defense only after a successful attack.
2. The teams don't have to make their images available from the internet, meaning they don't have to host it. That's how we solve the problem of slow computers and connection.
How do we do this? The attack proof would be the exploit. We won't need flags, we need proofs of vulnerability usage. Teams send exploits to the jury, who then run them. The jury can patch them and depending on the results rate the attack. Then the defence begins, the jury give images, teams create defences and "throw out" (can't see the attack). The jury send special exploits written by them or other teams which gains them special rates for attack.
"I don't suggest to kill classic CTF, but I suggest to do a small revolution and have it reborn!"
Post #62
29