// CYBERSECURITY CAPTURE THE FLAG  ·  OFFENSIVE SECURITY CHALLENGE

Think Like an Attacker. Defend Like a Professional.

24
Hours
3
Domains
550
Total Points
VulnHub
Based Challenges
SCROLL DOWN

// EVENT COUNTDOWN TIMER  ·  STARTS 09:00 AM NPT (UTC+05:45)

00
Days
:
00
Hours
:
00
Minutes
:
00
Seconds

// ABOUT THE EVENT

What is the CTF Competition?

Participants have 24 hours to investigate deliberately vulnerable machines sourced from VulnHub. Each team must identify security weaknesses, exploit them methodically, and capture all available flags.

This is not just a hacking competition — it is a full professional security assessment. Teams are required to document every step of their investigation, propose practical mitigations, and present their findings to a panel of judges.

Successful participants demonstrate both offensive and defensive security thinking: the ability to attack systems and the discipline to communicate findings clearly and responsibly.

Reconnaissance

Discover services, endpoints & attack surface

Exploitation

Leverage real-world CVEs & misconfigurations

Priv Escalation

Gain root access through privilege chains

Documentation

Evidence-based technical reporting

Flag Collection

Capture all available proof-of-compromise flags

Presentation

Defend your methodology before the panel

// CHALLENGE DOMAINS

Three Machines. One Mission.

  WEB SECURITY
DC-1

DC Corp has deployed an internal web portal for employee use. The security team has reported suspicious activity and possible unauthorized access to the system hosted on the DC-1 machine. The portal contains multiple web pages, authentication mechanisms, and hidden resources. It is suspected that misconfigurations and weak security controls exist within the application. Your task is to act as a security analyst and investigate the web application to identify vulnerabilities and compromised areas.

// OBJECTIVES

  • Perform reconnaissance on the web application
  • Identify hidden directories and files
  • Exploit web application vulnerabilities
  • Retrieve every available flag

// EXPECTED METHODOLOGY

  • Directory Enumeration
  • robots.txt Analysis
  • Login Enumeration
  • Hidden File Discovery
  • Authentication Bypass
  • Flag Collection

// DELIVERABLES

  • Enumeration Report
  • Attack Chain
  • Evidence
  • Retrieved Flags
  • Mitigation Recommendations
  SYSTEM EXPLOITATION
Kioptrix L1

Kioptrix Corporation is operating a legacy Linux server that has been exposed to the Internet. The infrastructure contains outdated software, insecure services, and weak configurations. Your objective is to conduct a full penetration test and obtain root access.

// OBJECTIVES

  • Discover active services
  • Enumerate vulnerabilities
  • Gain initial access
  • Escalate privileges
  • Capture all flags

// EXPECTED METHODOLOGY

  • Nmap
  • Service Enumeration
  • Vulnerability Assessment
  • Exploitation
  • Linux Privilege Escalation

// DELIVERABLES

  • Attack Timeline
  • Vulnerability Analysis
  • Root Access Evidence
  • Retrieved Flags
  • Security Recommendations
  PRIVILEGE ESCALATION
DC-6

A compromised internal server is suspected to contain sensitive information and multiple privilege escalation opportunities. You begin with limited access and must fully compromise the system while documenting every step.

// OBJECTIVES

  • Enumerate the system
  • Identify privilege escalation vectors
  • Gain root access
  • Retrieve all hidden flags

// EXPECTED METHODOLOGY

  • Manual Enumeration
  • LinPEAS
  • Sudo Enumeration
  • Cron Jobs
  • Credentials Discovery
  • Root Exploitation

// DELIVERABLES

  • Enumeration Report
  • Privilege Escalation Report
  • Evidence
  • Retrieved Flags
  • Hardening Recommendations

// COMPETITION RULES

Event Rules & Constraints

// CTF-RULES.sh — READ ONLY
root@ctf-server:~$ cat rules.txt
01.Duration: 24 Hours from competition start time
02.Team Size: 4 Members per registered team
03.Internet access is allowed for research and tool downloads
04.Communication between competing teams is strictly prohibited
05.Brute-force attacks against competition infrastructure are prohibited
06.Denial-of-Service attacks of any kind are prohibited
07.Any attack outside the provided lab machines results in immediate disqualification
08.Every flag must be documented with evidence (screenshots, output logs)
09.Teams must submit a final technical report by the deadline
10.Teams must deliver a final presentation and defense before the judging panel

// EVENT SCHEDULE

Competition Timeline

08:00
Registration
09:00
Opening Briefing
09:30
Competition Starts
09:30 – 22:00
Investigation Phase
22:00 – 07:00
Report Preparation
08:00
Presentation
09:00
Judging
10:00
Award Ceremony

// POINT DISTRIBUTION

Scoring Breakdown

Web Security
100 pts
System Exploitation
150 pts
Privilege Escalation
200 pts
Presentation
50 pts
Documentation
50 pts
MAXIMUM ACHIEVABLE SCORE
550
TOTAL POINTS

// FINAL PRESENTATION

Present & Defend

Reconnaissance Process
Attack Chain
Vulnerability Explanation
Exploitation Method
Screenshots & Evidence
Retrieved Flags
Security Recommendations
Lessons Learned
Maximum presentation time per team
15 Minutes