Capture the flag 2013
ctf365.com
ctf365.com
Can anybody suggest resources for lowly web developers to make our way into security? Even if just for fun?
How so? Is the activity itself inherently against TOS or laws? It seems to me that by running the competition, ctf365 intends to have users purposefully exploit sandboxed systems.
-----------------Network-----------------------------------
my_fortress <- targeted by: competitors_command&control_box
my_command&control_box :targets -> competitors_fortress
-----------------------------------------------------------
No shady traffic ever needs to traverse the public internet. Only ssh access to my_command&control_box and my_fortress is required. This has the added benefit of normalizing the attacking horsepower of the entrants.For example, see 'Prohibited Usage' for Linode: https://www.linode.com/tos.cfm
Unless you're paying for raw bandwidth, you're subject to the ToS of each resource provider along the way.
From their rules:
Don't try to conduct underground activities with your Fortress (system) from our platform in the Real World (e.g. using our platform to spam others, attack other servers on the internet and so on). We don't care who you are, but we do care what you are doing in our home (CTF365 Platform). Please remember that you are our guest and please behave accordingly.
I read this to imply that they will provide the "fortress". So when I say "sandboxed" system, I mean a system provided by ctf365 on their own infrastructure - infrastructure which permission is implicitly granted to attack.
http://comicbookmarks.com/wp-content/uploads/2011/08/detail-...
The actual content is here (and loads pretty quick as it should):
http://ctf365.com/pages/game http://ctf365.com/pages/rules http://ctf365.com/pages/prize
Looks like a rails site, not sure what all the gmaps code is all about, perhaps backend pages?
A fun idea, but I'd prefer if they just specified a simple set of services that you have to support, say something like:
IMAP
Serve this json
Serve this html and let people edit it
Serve this information from any db and let people edit it
and leave the backends to people's imagination. It sounds like they're going to actually specify different CMSs etc, and installing browsers?!?, when they should be specifying what protocols and data are required - that would let you use whatever service and backend tools you wanted.
The maps on the blog look pretty though.
Edit: The signup/signin box is half off to the left of the screen.
I wonder how long it would take someone to spin up a script to install all of these services...
SMTP, POP, IMAP, FTP, etc., one CMS + specific plugins, 2 different internet browsers, 3 web applications & at least 2 different databases
So...a mail server, file servers, multi-webhost, databases, and CMS with many plugins. I assume that "different databases" means different database stacks on different clusters, not "both MySQL and SQL Server 2012" on the same server, right? (In Windowsville this would all be within an AD domain, I'm not sure what the Linux equivalent is.) Will there be a required volume of photo/social datamass to be stored on the server? Maybe instead of some kind of "flag file", we'll have to store embarrassing photos of ourselves?
Who installs a second browser on a server?
2. How else would you connect to a datacenter server's integrated lights out (ILO) webpage from a bastion server within the datacenter and domain, to which you're only allowed an RDP connection?