📜 ⬆️ ⬇️

PHDays IV CTF: how it was

image

As part of the international forum Positive Hack Days IV, held in Moscow on May 21 and 22, according to tradition, the hacker competition Capture The Flag was held. For two days, 10 teams from 6 countries of the world hacked into the networks of rivals and fought off their attacks.

Traditionally, the infrastructure and tasks Positive Hack Days CTF are developed according to a common legend, which is a real highlight of the competition. During last year’s CTF, participants reincarnated as the rescuers of the fairy-tale world D'Errorim, who was threatened with death. Having coped with the task, they realized that they were fighting on the wrong side, and now the danger threatens their own home. Thus, the storyline combines PHDays III CTF, through the qualifying rounds of CTF Quals, with the final battle during PHDays IV.
')
The full text of the competition legend is on the forum website.

Principle of play


Typically, CTF competitions are divided into two types - task-based, where the main task is to solve tasks prepared by the organizers, and attack & defense, when teams need to protect their networks and attack their opponents' systems. Positive Hack Days CTF combines both of these concepts, complementing them with individual game mechanics. In particular, in addition to standard tasks (“tasks”) and services containing vulnerabilities, the organizers of PHDays CTF have developed unique quests - tasks that have a limited lifespan, and the bonus for completing them depends on the number of coped teams.

image

In addition, each year the organizers give CTF members the opportunity to earn extra points by taking part in main program competitions. In 2012, teams searched for flags in a special container with garbage (dumpster diving), and on PHDays III you could earn points by getting out of the hacker maze.

This time, members of the participating teams could test their strengths in searching for vulnerabilities in industrial systems and protocols during the Critical Infrastructure Attack contest. Earn additional points managed team RDot.

On the second day of the competition, the central task was the QIWI terminal security analysis - for this, a real terminal connected to the network was installed at the forum site. The teams received copies of the analysis software installed on it in advance, and during the competition they were given full physical access to the terminal (for example, to connect external devices). The task of the participants was the withdrawal of money (313,370 rubles) to a special electronic wallet. The closest to the victory in this competition was the team More Smoked Leet Chicken.

Visualization


In order to make the competition even more spectacular, last year the organizers developed a special fantasy-style visualization system. This year this system has been updated. With the help of special applications for iOS and Android, anyone could follow the course of the battle on the screen of their smartphone (visualization applications are still working, displaying the course of the CTF battle in demo mode).

image

On the site of the forum images were broadcast on large screens.

Winners


Competitions were held in a fierce fight. During the two days of the PHDays forum, the change of leader took place repeatedly: intr3pids, More Smoked Leet Chicken, Dragon Sector, SecurityFirst, Reallynonamesfor, BalalaikaCr3w and Ufologists managed to visit the top three.

In the end, the victory was won by the team Dragon Sector, representing Poland. The second place was taken by the Spaniards from int3pids, and the third were the Russians from Balalaika Cr3w.

image

Every year teams from around the world take part in PHDays CTF - from the USA to Japan. In qualifying competitions this year, more than 600 teams registered.

PHDays CTF was held for the fourth time: for the first time the competitions were held during the Positive Hack Days forum in 2011, then the participants of the American PPP team became winners, the next year the Russian Leet More team won, and Eindbazen from Holland won the PHDays III champions. After the victory of the Polish Dragon Sector team, it can be argued that a true tradition took shape: every year a new team that represents a new country wins.

Source: https://habr.com/ru/post/226803/


All Articles