DEF CON CTF 2015 Qualification Update: February Edition

Hello!

We'd like to share the current DEF CON CTF 2015 qualification status, two hours before the start of Boston Key Party!

Competition Start Date End Date Link Notes
DEF CON CTF 2014 May 17, 2014 Aug. 10, 2014 https://legitbs.net/2014/ Qualified the Plaid Parliament of Pwning.
SECCON CTF 2014 Dec. 12, 2014 Feb. 8, 2015 http://ctf.seccon.jp/timeline.html Qualified TOEFL Beginner.
RuCTFE 2014 Dec. 20, 2014 Dec. 20, 2014 http://ructf.org/e/2014/ Qualified Bushwhackers.
Ghost in the Shellcode Jan. 16, 2015 Jan. 18, 2015 http://ghostintheshellcode.com/ Qualified Samurai.
Boston Key Party Feb. 27, 2015 Mar. 1, 2015 http://bostonkeyparty.net Online jeopardy style game.
PlaidCTF Apr. 17, 2015 Apr. 19, 2015 http://www.plaidctf.com/ Online jeopardy style game.
DEF CON CTF Qualifiers 2015 May 16, 2015 May 17, 2015 https://legitbs.net/ Online jeopardy style, more information soon!
Congratulations to the teams that have qualified so far, and good luck to all the teams still hacking! Enjoy Boston Key Party, PlaidCTF, and we hope to see you in our qualifiers in May!

Quick Qualification Update

DEF CON CTF qualifications will be held from UTC Midnight at the start of May 16, 2015, to UTC Midnight at the end of May 17, 2015. Forty-eight hours total.

Competition Start Date End Date Link Notes
DEF CON CTF 2014 May 17, 2014 Aug. 10, 2014 https://legitbs.net/2014/ Qualified the Plaid Parliament of Pwning
SECCON CTF 2014 Dec. 12, 2014 Feb. 8, 2015 http://ctf.seccon.jp/timeline.html Qualifications round finished, finals in February 2015.
RuCTFE 2014 Dec. 20, 2014 Dec. 20, 2014 http://ructf.org/e/2014/ Finished.
Ghost in the Shellcode Jan. 16, 2015 Jan. 18, 2015 http://ghostintheshellcode.com/ Finished.
Boston Key Party Feb. 27, 2015 Mar. 1, 2015 http://bostonkeyparty.net Online jeopardy style game.
PlaidCTF Apr. 17, 2015 Apr. 19, 2015 http://www.plaidctf.com/ Online jeopardy style game.
DEF CON CTF Qualifiers 2015 May 16, 2015 May 17, 2015 https://legitbs.net/ Online jeopardy style, more announcements in 2015.

Thanks to skolor for the reminder to update this.

Announcing DEF CON CTF 2015 Qualifying Contests

We are pleased to announce that the following competitions will pre-qualify competitors for DEF CON Capture the Flag 2015. In order of contest start dates:

Competition Start Date End Date Link Notes
DEF CON CTF 2014 May 17, 2014 Aug. 10, 2014 https://legitbs.net/2014/ Qualified the Plaid Parliament of Pwning
SECCON CTF 2014 Dec. 12, 2014 Feb. 8, 2015 http://ctf.seccon.jp/timeline.html Qualifications round finished, finals in February 2015.
RuCTFE 2014 Dec. 20, 2014 Dec. 20, 2014 http://ructf.org/e/2014/ Online attack-defense, register now!
Ghost in the Shellcode Jan. 16, 2015 Jan. 18, 2015 http://ghostintheshellcode.com/ Jeopardy-style, on-site at ShmooCon or play online.
Boston Key Party Feb. 27, 2015 Mar. 1, 2015 http://bostonkeyparty.net Online jeopardy style game.
PlaidCTF Apr. 17, 2015 Apr. 19, 2015 http://www.plaidctf.com/ Online jeopardy style game.
DEF CON CTF Qualifiers 2015 TBA TBA https://legitbs.net/ Online jeopardy style, more announcements in 2015.

The best way to get good at Capture the Flag is by playing CTF games, learning what the experience is like, becoming familiar with the flow for solving challenges and writing exploits, and documenting your process. Your road to Vegas, no matter how long it is, starts with competition.

Becoming a DEF CON CTF 2015 Qualifying Competition

Do you run a Capture the Flag or other computer security competition? Want to have that elite prize that brings top-tier competitors? Want to have your winners move on to DEF CON finals? Become a DEF CON CTF 2015 Qualifying Competition!

UPDATED Nov. 17 2014: "Your competition MAY have both offensive and defensive components." The previous version had "SHOULD" there.

The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in RFC 2119.

Running a Competitive Competition

DEF CON CTF competitors are the best in the world. When less-qualified teams compete, they don’t enjoy the game, and don’t provide a lot of enjoyment for other teams either. Therefore, we must ensure  only the most qualified teams are invited. Our standards are as follows:

  1. Your competition MUST be open to all. You MUST NOT restrict entry or winning to students or professionals. You MAY structure your game with separate qualifying and finals events.
  2. You MUST NOT charge a fee to competitors, except for normal admission to a conference.
  3. Your competition MUST allow teams of at least four people.
  4. You MUST publish a final scoreboard within seven days of competition ending.
  5. You MUST be able to privately share the winning team’s contact information with us within seven days of competition ending.
  6. You MUST NOT publish personal information about competitors for any reason.
  7. You MUST NOT announce DEF CON CTF qualifying status prior to a Legitimate Business Syndicate announcement of same.
  8. You MUST either have run a competition previously, or be willing to share details and challenge samples with Legitimate Business Syndicate prior to approval.
  9. Your competition MAY have both offensive and defensive components.
  10. Your competition MAY be either online or local/in-person, or both!

If you don’t or can’t meet these requirements, please don’t ask for an exception. It’s possible we might not be a good fit for your competition as designed, and we don’t want to force you to compromise how you run your event.

Sending a Proposal

Send us an email to [email protected] before Midnight, Dec. 1, 2014 (1417392000) with answers to the following questions:

  1. Who is your group?
  2. What is your game named?
  3. Where and when are you hosting it?
  4. How do you design and build challenges?
  5. What’s your favorite vulnerability or exploit (CVE-number or well-recognized name)? Why?
  6. Do you have a favorite CTF challenge or service? How did you solve it?
  7. How do you plan to handle cheating?
  8. Have you or members of your team ever organized a CTF before? Provide details.
  9. Have you or members of your team participated in a CTF event? Provide details.
  10. How many people are involved in the following: challenge writing, game design, infrastructure, and support?

The earlier we get your submission, the earlier we'll read it and form a concrete opinion. Slots are limited. Expect a response by Dec. 9, 2014.

Rules, Disclaimers, and Caveats

  1. Legitimate Business Syndicate may terminate your qualifying event status at any time for any reason, including reasons not covered in this document.
  2. Competitions that publicly publish personal information about competitors will be forbidden from being qualifying events.
  3. Competitions that announce their qualifying event status before a Legitimate Business Syndicate announcement of their status will be forbidden from being qualifying events.
  4. Legitimate Business Syndicate reserves the right to use your competition’s name, logo, and description in promotional materials.
  5. Legitimate Business Syndicate will not use your or your competitors’ contact information for anything besides internal decision-making and official game communication.

All qualifying competition decisions made by Legitimate Business Syndicate members are final.

Two Weeks until 2014 Finals

Fewer than two weeks until our finals game kicks off at DEF CON 22 in sunny Las Vegas, Nevada.

If you're competing:

Subscribe to this blog and @legitbs_ctf on Twitter for updates. We'll email you about truly important coordinating stuff, but there will be supplemental stuff here.

If you're spectating:

See you in Vegas!

The CTF room will be open for everyone to drop by, watch videos, gawk at teams, and enjoy a DJ set or two throughout the contest. Enjoy yourself, but please be respectful and do not interrupt hackers at work. Do not photograph screens. Above all, don't be a jerk. If you have questions about the contest, talk to a member of Legitimate Business Syndicate. Competitors may be willing to talk when they are not engrossed in the game.

Our room is in the same location in 2013. If you're not completely sure where that is, check the conference program when you get your badge, and this year's DEF CON 22 maps should be available online soon.

Quals 2014 Data Dump

Good morning.

Legitimate Business Syndicate headquarters is mostly cleaned up, and we're almost recovered from the DEF CON Capture The Flag qualifiers last weekend. It's been slow, because we're still a bit shocked, amazed, and otherwise floored at how well you all played.

We're working through the results and pre-qualifying events right now, and as part of that, we're releasing our scoreboard data. Much like last year's release, this includes leaderboard and challenge data in JSON format. It also includes team information, a bit of user information, and detailed information about who solved what, when. Most of this information is not just in JSON, but human-readable HTML, and with a public-domain/CC0 license, so you can do whatever you want. We think you'll love it.

Scoreboard Data Dump, with cryptographic signature by Vito.

News and information about our competition at DEF CON is forthcoming; we're still confirming with competing teams and the DEF CON organizers, but we will definitely be running DEF CON CTF August 8-10, 2014.

THREE HOURS

EVERY MORNING I WAKE UP AND OPEN PALM SLAM A BINARY INTO IDA. IT’S DEF CON CTF QUALIFIERS AND RIGHT THEN AND THERE I START DOING THE MOVES ALONGSIDE WITH THE MAIN CHARACTER, GYNOPHAGE. I DO EVERY MOVE AND I DO EVERY MOVE HARD. MAKIN WHOOSHING SOUNDS WHEN I SLAM DOWN SOME HEAP SPRAY OR EVEN WHEN I MESS UP TECHNIQUE. NOT MANY CAN SAY THEY QUALIFIED FOR THE GALAXYS MOST AWESOME CTF. I CAN. I SAY IT AND I SAY IT OUTLOUD EVERYDAY TO PEOPLE IN MY COLLEGE CLASS AND ALL THEY DO IS PROVE PEOPLE IN COLLEGE CLASS CAN STILL BE IMMATURE JEKRS. AND IVE LEARNED ALL THE SOLUTIONS AND IVE LEARNED HOW TO MAKE MYSELF AND MY APARTMENT LESS LONELY BY SHOUTING EM ALL. 2 HOURS INCLUDING WIND DOWN EVERY MORNIng