Coder Social home page Coder Social logo

hitb-cyberweek / hitbsecconf-ctf-2022 Goto Github PK

View Code? Open in Web Editor NEW
19.0 11.0 2.0 19.18 MB

HITB SECCONF CTF 2022. Developed with ❤️ by Hackerdom team and HITB.

License: MIT License

Dockerfile 0.30% PHP 29.61% HTML 2.19% Python 11.19% C++ 47.55% Shell 1.25% HCL 0.12% Jinja 0.46% C# 3.89% JavaScript 0.30% CSS 0.09% Go 0.29% Twig 0.74% CMake 0.01% C 0.61% Java 1.39% Perl 0.02%
attack-defence ctf hackerdom hacking hitb security

hitbsecconf-ctf-2022's Introduction

HITB SECCONF CTF 2022

HITB SECCONF CTF is an onsite + online international challenge in information security. Developed by Hackerdom team for HITB SECCONF in Singapore. HITB SECCONF CTF 2022 was held on August 25th–26th, 2022.

The contest is driven by almost classic rules for Attack-Defense CTF. Each team is given a set of vulnerable services. Organizers regularly fill services with private information — the flags. The goal of each team is to find vulnerabilities, fix them in their services and exploit them to get flags from other teams.

This year we have had some innovations:

  • New scoring system (we use it for the second time, first one was at HITB PRO CTF 2021)
  • New flag format: TEAM042_PNFP4DKBOV6BTYL9YFGBQ9006582ADCX
  • Non-playable teams
  • Reverse proxies with per-team limits for services
  • DNS names for all services (e.g. example.team42.ctf.hitb.org)

You can read the details on the official contest website: https://ctf.hackerdom.ru/hitb-ctf-singapore-2022/.

Official conference website: https://conference.hitb.org/hitbsecconf2022sin/.

This repository contains

  • source of all services in folder services/
  • checkers for checksystem in folder checkers/
  • ... and config for it in cs/.
  • exploits for all services in folder sploits/
  • writeups with vulnerabilities and exploitation description for all services in folder writeups/

Also, we share with you some of our internal infrastructure magic:

All materials are licensed under MIT License.

Final scoreboard

Congratulations for 🇷🇺 Bushwhackers, hacked all services, for the first place!

Second place: 🇷🇺 C4T BuT S4D

Third place: 🇩🇪 saarsec

Final scoreboard

First bloods

SERVICE TEAM
linkextractor Bushwhackers
obscurity C4T BuT S4D
kv C4T BuT S4D
smallword C4T BuT S4D
n0tes Bushwhackers
sh Bushwhackers
crs Bushwhackers
wallet Bushwhackers
mypack RedRocket
issuecker C4T BuT S4D

Authors

This CTF is brought to you by these amazing guys:

If you have any question about services, platform or competition write us an email to [email protected] or [email protected].

© 2022 HackerDom

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.