7 ms·
Capture the flag 2013
- duked 13y agoTried to sign up and got the same message no matter what email/password I use: " Invalid email or password. "
- IronWhale 13y agoIt worked for me on mobile safari. It's actually a nice sign up process - I was immediately directed to a dashboard.
- IronWhale 13y agoOh, btw, for sign up there is no password field. You must be using the sign in form (it could still be a bug, e.g. Clicking sign in shows the sign up form for your browser).
- abraininavat 13y agoDad?
- kerosen 13y agoAn email to support@ctf365.com would help us a lot to make you happy. Thanks!
- IronWhale 13y agoThis is cool. Please hammer home the C&C nostalgia - we all love it.
- thejosh 13y agoReally hard to read the text, but really nice homepage.
- recursive 13y agoHow is that possible? What's the purpose of the homepage?
- rquantz 13y agoThe apparent trouble with signup notwithstanding, this seems like great fun. The thing is, I didn't find out about those problems, because I didn't even try to sign up. I have no idea how I would go about getting started being able to do this. Can anybody suggest resources for lowly web developers to make our way into security? Even if just for fun?
- bfish510 13y agoI've been reading though Hacking: The Art of Exploitation. So far I'm enjoying it.
- BWStearns 13y agoDefinitely agree. Also highly recommend setting up a Kali or Backtrack box. It's a lot less time consuming than starting your toolkit from scratch.
- haydenchambers 13y agohttp://www.hackthissite.org/ http://www.hackthissite.org/
- fduran 13y agoYou may like http://google-gruyere.appspot.com/ http://google-gruyere.appspot.com/
- Ellipsis753 13y agoThank you. I had not heard of that before and it looks very helpful.
- gverri 13y agoAlso: http://www.amazon.com/The-Web-Application-Hackers-Handbook/dp/1118026470 http://www.amazon.com/The-Web-Application-Hackers-Handbook/d...
- kerosen 13y agoYou should start with http://www.securitytube.net/ http://www.securitytube.net/ also on youtube you'll find very insightful information.
- stephengillie 13y agoMobile browser fail Edit: The signup/signin box is half off to the left of the screen.
- gailees 13y agoLove it. But very janky website makes me worried about the quality.
- chameco 13y agoYeah, the site seems to leak memory like a sieve. I had to kill -9 firefox.
- angrydev 13y agoAlso hanging my browser.
- grey-area 13y agoIt's a good illustration of a misuse of the webapp single-page formula for a simple informational site. This could have been simple HTML with a proper url for each page, so that you could actually link to the subpages, but instead they're trying to load the content in with js, and performing terribly with no feedback on clicks when I last looked. The actual content is here (and loads pretty quick as it should): http://ctf365.com/pages/game http://ctf365.com/pages/game http://ctf365.com/pages/rules http://ctf365.com/pages/rules http://ctf365.com/pages/prize http://ctf365.com/pages/prize Looks like a rails site, not sure what all the gmaps code is all about, perhaps backend pages? A fun idea, but I'd prefer if they just specified a simple set of services that you have to support, say something like: IMAP Serve this json Serve this html and let people edit it Serve this information from any db and let people edit it and leave the backends to people's imagination. It sounds like they're going to actually specify different CMSs etc, and installing browsers?!?, when they should be specifying what protocols and data are required - that would let you use whatever service and backend tools you wanted. The maps on the blog look pretty though.
- mjolk 13y agoThis will be interesting to see when finished, but it would be better if each 'Fortress" had to offer services, instead of dictating that each camp has to run POP + Wordpress + some bullshit plugins. Also, this type of activity definitely will break terms of service for internet service and hosting providers, as well as potentially several laws.
- dkokelley 13y ago> "...this type of activity definitely will break terms of service for internet service and hosting providers, as well as potentially several laws." How so? Is the activity itself inherently against TOS or laws? It seems to me that by running the competition, ctf365 intends to have users purposefully exploit sandboxed systems.
- talmand 13y agoI would imagine one example could be a website hosted by a third party. Possibly you would have to inform the host of the situation and get their approval. Otherwise you might be breaking a generic law about gaining unauthorized access to a computer.
- dkokelley 13y agoSee my reply to mjolk. I am under the impression that the "fortress" infrastructure is provided by ctf365.
- talmand 13y agoAh, I suppose that would cover most bases. If they own the servers and they are giving permission to access them in such a way then there's likely no worries over unauthorized access type laws.
- BWStearns 13y agoI took a look at this a while back (excited to see it's still going), but there is the chance that your ISP might send you a nastygram/suspend service if they notice a lot of activity that looks like port scanning, though that depends on how intrusive/vigilant your ISP is being.
- kyle_martin1 13y agoInterestingly, they're using the same technique for the cloud effect as that Japanese energy drink site that was posted here not too long ago.
- talmand 13y agoI hope their use of imagery from the Captain America movie is covered under fair use or derivative work. http://comicbookmarks.com/wp-content/uploads/2011/08/detail-6.jpg http://comicbookmarks.com/wp-content/uploads/2011/08/detail-...
- kyle_martin1 13y agoAgreed!
- kerosen 13y agoThe internet is full of information and we've find this 3D Cloud Effect tutorial http://www.clicktorelease.com/blog/how-to-make-clouds-with-css-3d http://www.clicktorelease.com/blog/how-to-make-clouds-with-c... You should try it too.
- Buzaga 13y agowish I knew anything about hacking to play this, just know development :( setting up the server would be some work to me already
- stephengillie 13y agoHopefully they'll at least link to good configuration sites for each service, to give new players at least a fighting chance. I wonder how long it would take someone to spin up a script to install all of these services... SMTP, POP, IMAP, FTP, etc., one CMS + specific plugins, 2 different internet browsers, 3 web applications & at least 2 different databases So...a mail server, file servers, multi-webhost, databases, and CMS with many plugins. I assume that "different databases" means different database stacks on different clusters, not "both MySQL and SQL Server 2012" on the same server, right? (In Windowsville this would all be within an AD domain, I'm not sure what the Linux equivalent is.) Will there be a required volume of photo/social datamass to be stored on the server? Maybe instead of some kind of "flag file", we'll have to store embarrassing photos of ourselves? Who installs a second browser on a server?
- Hello71 13y agocurl and wget, right?
- herge 13y agoWho installs a first browser on a server?
- stephengillie 13y ago1. They come preinstalled on some closed-source OSes 2. How else would you connect to a datacenter server's integrated lights out (ILO) webpage from a bastion server within the datacenter and domain, to which you're only allowed an RDP connection?
- redblacktree 13y agoOf course, this introduces a meta-game where script writers can include their own malicious code. :)
- grimtrigger 13y agoIs there anything to stop me from signing up random people's websites?
- BWStearns 13y agoPer another branch of the conversation, they set up the servers, you just control them, so the entire conflict happens in a relatively sandboxed environment.
- joyeuse6701 13y agoI don't think there is anywhere on the website that explicitly tells you what the objective of this is, nor exactly what a flag is (even if it is more of a concept). As much as I can infer from it, in game instructions, they should be explicit.
- neumino 13y agoLooks like they got too much traffic...
- BWStearns 13y agoAnyone interested in making a HN team? (possibly a few given that it's limited members/team)
- andrewbuss 13y agoI'd be interested in joining one if there is space for someone with limited administration experience.
- BWStearns 13y agoShoot me an email, brianw.stearns@gmail.com. I have [very] limited practical admin experience, but I will try to scare up a friend who can devote some time to it.
- kerosen 13y agoCTF365 It's a Startup on bootstrap mode (self funded) that will change the way Information Security is learned. We try to do our best with very few resources. No seed money, no Kickstarter money but full of passion and dedication.