Last week-end was great. I was at Insomni'Hack 2011 security event organized by SCRT. Conferences during the day (read Bruno Kerouanton or Emilien Girault), security challenges during the evening (6pm-1am). Short time and adapted challenges, staff did great! We missed the internet but we had beers :)
I played the challenges with some friends and we ended up in the first place winning a nice trophee, a Fortinet Firewall, some tshirts and other goodies. Thanks SCRT! If you are interested in the challenges, shell-storm has mirrored some of them (offline ones at least) while Djo, Emilien Girault and Pascal Junod have already published some write-ups. Also, staff said they will publish all challenges and solutions soon.
Last week-end were also Codegate 2011 qualifications, which I unfortunately did not play this year. Different kind of challenges, strong competition. Many write-ups have been shared by @codegate_yut.
Also, some cool stuff ahead: Honeynet public conference, HITB Amsterdam CTF prequals, HES 2011, and maybe a Plaid Parliament of Pwning (PPP) CTF.
And if you don't know what to do, there's a new wargame at Smash The Stack: amateria. Worth playing :)
Showing posts with label codegate. Show all posts
Showing posts with label codegate. Show all posts
Tuesday, March 08, 2011
Friday, April 23, 2010
Codegate, HES2010, citctf
As you may know, I played Codegate CTF quals with Nibbles and we managed to be #11. As you can see, there was many good write-ups on the challenges. Despite being 11th, my friend SiD & I had the chance to go in Korea to play CTF finals and it was great: discovering Korea, playing CTF (managed to arrive 4th!), meeting other teams, conference speakers and other nice people. Also, networking session was awesome! I didn't have the time to see the conferences, but it reported to be very good as well.
Challenges by LM**2 were again interesting, excellent write-up from HFS (winners) for the encrypted shellcode (only team to solve it!). I should write-up on some challenges too if I have time. In the meantime I would love to see the challenges available on the net, maybe on intruded?
To conclude Codegate 2010 was amazing, well-organized by Softforum, great people and a lot of fun. You can find nice pictures of the whole event from yoggy0 and team PPP our CTF friends. I will definitely do my best to return next year if there is a Codegate 2011 :)
At the same time, Hackito Ergo Sum (HES) security conference was happening in France: impressive program and speakers (slides are available), they also organized a wargame with OverTheWire guys (reputed for their good online challenges), and recently even made it available among their other wargames (thank you, starting to play hehe!).
Among the next events are CIT CTF on May 15-16 (registration) from our Russian friends of Codegate, and obviously Defcon CTF quals on May 21-24 (registration). Good luck and have fun if you're a player too!
Challenges by LM**2 were again interesting, excellent write-up from HFS (winners) for the encrypted shellcode (only team to solve it!). I should write-up on some challenges too if I have time. In the meantime I would love to see the challenges available on the net, maybe on intruded?
To conclude Codegate 2010 was amazing, well-organized by Softforum, great people and a lot of fun. You can find nice pictures of the whole event from yoggy0 and team PPP our CTF friends. I will definitely do my best to return next year if there is a Codegate 2011 :)
At the same time, Hackito Ergo Sum (HES) security conference was happening in France: impressive program and speakers (slides are available), they also organized a wargame with OverTheWire guys (reputed for their good online challenges), and recently even made it available among their other wargames (thank you, starting to play hehe!).
Among the next events are CIT CTF on May 15-16 (registration) from our Russian friends of Codegate, and obviously Defcon CTF quals on May 21-24 (registration). Good luck and have fun if you're a player too!
Wednesday, March 17, 2010
Write-up Codegate 2010 #17 - Crypto, Linear Congruential Generators and Vernam Cipher, the power of XOR
Challenge #17 was crypto, based on Linear Congruential Generators (LCG), a well known pseudorandom number generator (PRNG), and the Vernam Cipher which is basically a XOR cipher relying on exclusive OR . Sadly, we did not succeed this challenge in time. However my friend Ivan found it afterwards thanks to Julianor (a staff member).
Basically, there is a TCP server listening to incoming connections. We simply use netcat (or telnet) to connect to it:
Basically, there is a TCP server listening to incoming connections. We simply use netcat (or telnet) to connect to it:
$ nc ctf3.codegate.org 10909 a? c? m? Bad values
Tuesday, March 16, 2010
Write-up Codegate 2010 #19 - Forensic, introduction to the Sleuth Kit and Autopsy
Challenge #19 was also interesting, at least for the story:
Found a dead guy on the street, assumed that a guy committed suicide. How can you assume that? Find the clue.And they gave us a simple binary file: 56DACF1C6CF363F27501FFCA50CC0415 (9.6MB).
Monday, March 15, 2010
Write-up Codegate 2010 #7 - Decrypting HTTPS SSL/TLSv1 using RSA 768bits with Wireshark
Last week-end, I was a challenger at Codegate 2010 Capture the Flag with team Nibbles. Well organized by Koreans guys (who didn't sleep a lot either ;), the CTF proposed quality challenges and I thought it would be a great subject for a few posts.
Challenge #7 was a network capture file (ssl.pcap) containing an encrypted https session. The hint was: does the modulus look familiar?. The goal is obviously to decrypt the https to find the flag. Let's see how we can do that!
Steps:
Challenge #7 was a network capture file (ssl.pcap) containing an encrypted https session. The hint was: does the modulus look familiar?. The goal is obviously to decrypt the https to find the flag. Let's see how we can do that!
Steps:
- Extract public certificate
- Identify encryption
- Create private certificate
- Decrypt https
Subscribe to:
Posts (Atom)