But, as you know, if you criticise, you have to offer something instead. Today Andrey presents us the idea of "neoclassic" CTF.
1. We check, how the participants can attack and defend. Not explore the image, not sniff the traffic, but create exploits and close the vulnerabilities. So the first idea: allow to defense only after a successful attack. 2. The teams don't have to make their images available from the internet, meaning they don't have to host it. That's how we solve the problem of slow computers and connection.
How do we do this? The attack proof would be the exploit. We won't need flags, we need proofs of vulnerability usage. Teams send exploits to the jury, who then run them. The jury can patch them and depending on the results rate the attack. Then the defence begins, the jury give images, teams create defences and "throw out" (can't see the attack). The jury send special exploits written by them or other teams which gains them special rates for attack.
"I don't suggest to kill classic CTF, but I suggest to do a small revolution and have it reborn!"
The problems which Andrey pointed out were slow network, different computer configurations, inability to train and, as a result, the victory of those teams that participate more in competitions, the stealing of flags through other services, unplanned vulnerabilities, possibilities to simply watch how you are attacked and repeated the same actions, possibility to fill your own services and services of others with fake flags, difficulty of checksystem organisations, which leads to chaotic results.
Right now Andrey is talking about all the disadvantages of classic CTF, and we invite you to discuss your solutions to the problems, one representative from each team and anyone who has the desire, to the round table, which starts at Demidov hall at 19:30.
It's time for the last presentation for today. We'll tell you a secret: it's working title was "Why classic CTF has to die". Andrey Gein, the member of team "Переподвысмотрит", is going to talk on why Attack/Defense CTF in its current form is bad and how to improve it.
Evgeny Andryukhin, the expert researcher from "Advanced Monitoring", will tell us about the industrial protocol S7Comm, analysis of its security and successful attacks on it.
Nobody solved the task! Both participants found the interpreters but their versions were too new. Author's code was written for the older Logo language, so some command could not work.