Difference between revisions of "CTF-practice-evening:2014-01-27"

From Technologia Incognita
Jump to: navigation, search
Line 20: Line 20:
 
** We should be proud of ourselves!!!!
 
** We should be proud of ourselves!!!!
  
* Repository of tools: VMs (Architectures: Linux and Windows, 64-bits), Tools: IDA Pro, Burp)
+
* Repository of tools: VMs (Architectures: Linux and Windows, 64-bits), Tools: IDA Pro, Burp, Selenium)
 
** (Brainsmoke has some VMs already prepared)
 
** (Brainsmoke has some VMs already prepared)
 
** There's a few servers and shared storage here at Tech Inc  
 
** There's a few servers and shared storage here at Tech Inc  
Line 51: Line 51:
 
* It's also nice to have a blog for posting write-ups afterwards
 
* It's also nice to have a blog for posting write-ups afterwards
  
= Other stuff =
+
= Other ideas =
 
   
 
   
 
* Brainsmoke should give a presentation on his taint tracker some evening
 
* Brainsmoke should give a presentation on his taint tracker some evening
 +
* We should have an evening where we play with Selenium

Revision as of 19:49, 27 January 2014

CTF-practice-evening:2014-01-27
Date 2014/01/27
Time
Location Tech Inc
Type Workshop
Contact Melanie

Capture The Flag evening - Part 5

  • 27 January, 2014 - 8 PM
  • Please bring along a laptop with you!!!

General CTF Info

Comments about the PhDays CTF

  • We think that our first CTF went fantastic!  :-)
    • We should be proud of ourselves!!!!
  • Repository of tools: VMs (Architectures: Linux and Windows, 64-bits), Tools: IDA Pro, Burp, Selenium)
    • (Brainsmoke has some VMs already prepared)
    • There's a few servers and shared storage here at Tech Inc
    • (Wizzup administers it.) - it's not really safe though. We're better off maintaining our own infra
    • We can run our own server w/ Etherpad, etc…
    • If I can't get a server, we can rent a VPS for 15 Euros/year.
    • Several people also have their own VPS systems and/or VMs
  • We need to structure the Etherpad better
    • We should setup our own Etherpad
    • You can create an Etherpad manager
    • We should archive the pads somehow in either case…
  • Coordination
    • We should make a quick inventory of what challenges are available, and what skills they require
    • We should put our name next to the challenge that we're working on
    • IRC also helps with coordination
    • We could write up a quick skills DB of who knows what
    • Then we could use IRC to ask people if they can work on something
    • If you go to sleep, or are unavailable, put your partial results in the Etherpad
  • knuffelhackers.nl - who owns it? Can we use it?
  • Archiving
    • A git repository helps (for challenges almost solved, pads, etc…)
  • Private mailing list and IRC, for single individual CTFs
    • A password protected IRC channel is low-hanging fruit
  • It's also nice to have a blog for posting write-ups afterwards

Other ideas

  • Brainsmoke should give a presentation on his taint tracker some evening
  • We should have an evening where we play with Selenium