TGViewer
Channel Public Channel
RuCTF in english [DEPRECATED]

RuCTF in english [DEPRECATED]

@ructf_en

RuCTF is annual open intercollegiate competition and conference on information security.
This is old channel, please follow @RuCTF
Subscribers
85
Photos
192
Videos
8
Links
101

Showing posts older than #64 · Back to latest

Older Posts 20 shown
Post #63 29
We stated our traditional round table! First topic to discuss — Andrey Gein's presentation.
Post #62 29
But, as you know, if you criticise, you have to offer something instead. Today Andrey presents us the idea of "neoclassic" CTF.

1. We check, how the participants can attack and defend. Not explore the image, not sniff the traffic, but create exploits and close the vulnerabilities. So the first idea: allow to defense only after a successful attack.
2. The teams don't have to make their images available from the internet, meaning they don't have to host it. That's how we solve the problem of slow computers and connection.

How do we do this? The attack proof would be the exploit. We won't need flags, we need proofs of vulnerability usage. Teams send exploits to the jury, who then run them. The jury can patch them and depending on the results rate the attack. Then the defence begins, the jury give images, teams create defences and "throw out" (can't see the attack). The jury send special exploits written by them or other teams which gains them special rates for attack.

"I don't suggest to kill classic CTF, but I suggest to do a small revolution and have it reborn!"
Post #61 26
The problems which Andrey pointed out were slow network, different computer configurations, inability to train and, as a result, the victory of those teams that participate more in competitions, the stealing of flags through other services, unplanned vulnerabilities, possibilities to simply watch how you are attacked and repeated the same actions, possibility to fill your own services and services of others with fake flags, difficulty of checksystem organisations, which leads to chaotic results.
Post #60 27
Right now Andrey is talking about all the disadvantages of classic CTF, and we invite you to discuss your solutions to the problems, one representative from each team and anyone who has the desire, to the round table, which starts at Demidov hall at 19:30.
Post #58 26
It's time for the last presentation for today. We'll tell you a secret: it's working title was "Why classic CTF has to die". Andrey Gein, the member of team "Переподвысмотрит", is going to talk on why Attack/Defense CTF in its current form is bad and how to improve it.
Post #57 25
We've got some changes in the timetable! Right now it's a coffee break, and at 18:15 Andrey Gein will start his presentation.
Post #55 25
Evgeny Andryukhin, the expert researcher from "Advanced Monitoring", will tell us about the industrial protocol S7Comm, analysis of its security and successful attacks on it.
Post #53 25
Nobody solved the task! Both participants found the interpreters but their versions were too new. Author's code was written for the older Logo language, so some command could not work.
Post #52 24
It turns out that it's not assembly, but Logo language!
Post #49 23
The task is "What the shell?". Participants get strange text files, which contents look pretty much like a program on unknown assembly dialect.
Post #48 23
Members of keva and Tower of Hanoi started to solve Fun-2!
Post #47 23
One participant had one cable with two connectors, and the other had two cables with one connector on each cable :) Congratulations to both winners!
Post #46 22
Yes, they make patchcords!
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →