SlideShare ist ein Scribd-Unternehmen logo
1 von 35
Downloaden Sie, um offline zu lesen
CTFs - Bringing back
                        more than sexy ;-)

                           Mark Hillick - @markofu

                                    KTF

                             Creator of HackEire



Thursday 9 June 2011
Usual stuff - disclaimer!

                       Own views - not representative of Citrix
                       Systems, IrissCert nor Phyllis and Ferb. I am
                       speaking here entirely of my own opinion,
                       which isn’t saying much but hey :)



                       No dolphins were hurt in the making of this
                       presentation!




Thursday 9 June 2011
Who are ya?
                       too many years working in IT

                       now @ vendor, used to be @ bank so I’m

                       Ex-@IrissCert handler, #IrissCon, @HackEire
                       @OwaspIreland

                       Previous Owasp Presentations

                           Cert Handler;

                           WAF Implementation;

                           Scareware via Web App Exploit
Thursday 9 June 2011
What’s this about?
                       Nope



                       Nor this guy




                       CTFs - history, now & the future

                       My experiences from building a CTF contest
                       from scratch with no $$$$$
Thursday 9 June 2011
So sorry!!!

                       I know I had ‘sexy’ in the title but




Thursday 9 June 2011
What’s a CTF? (1)
                              WAR-GAMES.......COMPETITION!




                             ATTACK, ATTACK, ATTACK!!!!
Thursday 9 June 2011
What’s a CTF? (2)


                       CTF contests.....serve as an educational
                       exercise to give participants experience in
                       securing a machine, as well as conducting
                       and reacting to the sort of attacks found in
                       the real world.


                       source: http://en.wikipedia.org/wiki/Capture_the_flag#Computer_security && I agree with this partly :)




Thursday 9 June 2011
CTF? Nah, I’m not.....




Thursday 9 June 2011
We can’t all be.......




                         Or.....




Thursday 9 June 2011
I’m not a hacker........




                Source:   http://img.wikinut.com/img/hzbaiyv.qfkbuofg/jpeg/0/The-comfort-circle.jpeg


Thursday 9 June 2011
Thursday 9 June 2011
Thursday 9 June 2011
but maybe try a CTF?




                        learn outside of the norm


Thursday 9 June 2011
But I’d like to attend
                         the conference!!
                       You going to remember every talk?




                       Didn’t think so......
Thursday 9 June 2011
1337
                       Test your l33t skillz



                       NSFW



                       Copious amounts of caffeine



                       Do cool stuff with old/new friends


Thursday 9 June 2011
Get a job?
                       Companies attempting to recruit off HackEire



                       HackEire => winners got postgrad funding &
                       several business cards :)



                       SANS/US Govt Challenges => JOBS GALORE



                       UK Cyberchallenge won by an ex-postman!

Thursday 9 June 2011
CTF Feedback 2010

                       I learnt a shitload today. I learnt more
                       about what I don’t know than what I do
                       know. Thanks!



                       Thanks very much! I had so much fun and
                       would be happy to pay 100 yoyos (pps) to
                       enter in future.



Thursday 9 June 2011
Why allow your staff to
                    compete in a CTF?
                       Learn about defensive & offensive security in
                       a safe environment! As opposed to........



                       You will learn & increase your awareness
                       because you will be surprised.....



                       $1000/day != good CTF competitor


Thursday 9 June 2011
So why run a CTF?


                       Make a name...



                       Spot talent



                       Help others & give back a little



Thursday 9 June 2011
Why did I do it?



                                   & @edskoudis



                       I wanted to learn & improve




Thursday 9 June 2011
Would I start it all now?

                       Probably not



                       > 250 hours last year



                       Project & People Management



                       Not everyone as passionate

Thursday 9 June 2011
What have I gained?
               I used to ‘not like’ my job very much & was bored. I
               wanted to play with tools I wouldn’t normally get to......




Thursday 9 June 2011
What often happens in a
                         CTF?
             In......




                        Out......




Thursday 9 June 2011
Why?




                       Is sadly all too infrequent.....

                       Assign Roles/Functions
Thursday 9 June 2011
2000 v 2011
                       NT4                 W7, MacOS10, Linux

                       Brick Phones        iOS, Android

                       $$$$$$$$            Credit Crunch

                       West                East

                       Kazaa, Napster      Twitter, FB, Skype...

                       Books, Newspapers   eBooks, Blogs, Web2.0

                       Man Utd :)          Man Utd :)

                       Q&A Interviews      Interactive, Hands-On

Thursday 9 June 2011
The future?
                       #ebooks            #Virtualisation

                       #Tablets/#Phones   #OpenSource




                       #CyberChallenges
                       Galore :)


Thursday 9 June 2011
Today?
 Competitions are increasingly recognised as an effective way
 of promoting innovation......prize industry has boomed,
 increasing more than 15-fold. The US Space and Security
 authorities have been supporting world leading competitions
 for many years. The Obama administration has re-authorised
 the America COMPETES act to support innovation and
 innovators. Is it time for Europe to catch up?


                   Source:   http://www.europeansecuritychallenge.com/




Thursday 9 June 2011
UK Cyber Challenge



                       Secure Network Design



                       Informed Defence



                       Investigate & Understand

Thursday 9 June 2011
CTFs in the future?



                       Part of Hands-On Interview



                       Looking for skillz => USA/SANS, UK, EU



                       Book Smart != Enough

Thursday 9 June 2011
It’d be nice if.....




               Goal: Keep improving.......

               Evolve, understand & innovate
Thursday 9 June 2011
2011 for HackEire?
                       Even better than last year & still free......

                         Huge improvements - more realistic

                         New web portal

                         Social Media

                         PCAP Analysis

                         More defensive controls

                         Want to introduce images to defend but
                         no time :(


Thursday 9 June 2011
Learn more about CTFs?




               Check out the DefCon, Sans, EthicalHacker.net (& more)
               websites

Thursday 9 June 2011
It’s all here.......




               Teamwork & Preparedness

               Constant Improvement
Thursday 9 June 2011
Q&A




Thursday 9 June 2011
All done, no more!

                       If you’re still awake.....




Thursday 9 June 2011

Weitere ähnliche Inhalte

Ähnlich wie CTF: Bringing back more than sexy!

Devopsdays Goteborg 2011 - State of the Union
Devopsdays Goteborg 2011 - State of the UnionDevopsdays Goteborg 2011 - State of the Union
Devopsdays Goteborg 2011 - State of the Union
John Willis
 
Kin Global Kellogg 2011 Chicago
Kin Global Kellogg 2011 ChicagoKin Global Kellogg 2011 Chicago
Kin Global Kellogg 2011 Chicago
Carlos Dominguez
 
Boston Globe: Responsive Web Design
Boston Globe: Responsive Web DesignBoston Globe: Responsive Web Design
Boston Globe: Responsive Web Design
The Media Consortium
 
Netcultfunding frontlineclub-rendeiro
Netcultfunding frontlineclub-rendeiroNetcultfunding frontlineclub-rendeiro
Netcultfunding frontlineclub-rendeiro
bicyclemark
 
Opensource Authentication and Authorization
Opensource Authentication and AuthorizationOpensource Authentication and Authorization
Opensource Authentication and Authorization
ConFoo
 
Destroy the box
Destroy the boxDestroy the box
Destroy the box
jsokohl
 

Ähnlich wie CTF: Bringing back more than sexy! (20)

Jeremiah Pliché's PBE 2011
Jeremiah Pliché's PBE 2011Jeremiah Pliché's PBE 2011
Jeremiah Pliché's PBE 2011
 
When machines think
When machines thinkWhen machines think
When machines think
 
ITP / SED Day 4
ITP / SED Day 4ITP / SED Day 4
ITP / SED Day 4
 
Designing Science and Literacy Games for Nintendo DS
Designing Science and Literacy Games for Nintendo DSDesigning Science and Literacy Games for Nintendo DS
Designing Science and Literacy Games for Nintendo DS
 
Devopsdays Goteborg 2011 - State of the Union
Devopsdays Goteborg 2011 - State of the UnionDevopsdays Goteborg 2011 - State of the Union
Devopsdays Goteborg 2011 - State of the Union
 
Kin Global Kellogg 2011 Chicago
Kin Global Kellogg 2011 ChicagoKin Global Kellogg 2011 Chicago
Kin Global Kellogg 2011 Chicago
 
Celebrate Texas Voices: Empowering Digital Witnesses
Celebrate Texas Voices: Empowering Digital WitnessesCelebrate Texas Voices: Empowering Digital Witnesses
Celebrate Texas Voices: Empowering Digital Witnesses
 
Mo' Dimensions Mo' Problems
Mo' Dimensions Mo' ProblemsMo' Dimensions Mo' Problems
Mo' Dimensions Mo' Problems
 
Boston Globe: Responsive Web Design
Boston Globe: Responsive Web DesignBoston Globe: Responsive Web Design
Boston Globe: Responsive Web Design
 
Netcultfunding frontlineclub-rendeiro
Netcultfunding frontlineclub-rendeiroNetcultfunding frontlineclub-rendeiro
Netcultfunding frontlineclub-rendeiro
 
Opensource Authentication and Authorization
Opensource Authentication and AuthorizationOpensource Authentication and Authorization
Opensource Authentication and Authorization
 
From Apples to Augmented Cognition (Current and Future Trends in Mobile)
From Apples to Augmented Cognition (Current and Future Trends in Mobile)From Apples to Augmented Cognition (Current and Future Trends in Mobile)
From Apples to Augmented Cognition (Current and Future Trends in Mobile)
 
Rise of devops
Rise of devopsRise of devops
Rise of devops
 
Digital & Social Media Marketing
Digital & Social Media MarketingDigital & Social Media Marketing
Digital & Social Media Marketing
 
Destroy the box
Destroy the boxDestroy the box
Destroy the box
 
Made by Many Sweden
Made by Many SwedenMade by Many Sweden
Made by Many Sweden
 
State of Social & Informal Learning
State of Social & Informal LearningState of Social & Informal Learning
State of Social & Informal Learning
 
Godoggo
GodoggoGodoggo
Godoggo
 
YOU WILL REGRET THIS
YOU WILL REGRET THISYOU WILL REGRET THIS
YOU WILL REGRET THIS
 
Ready to Play: JavaScript / HTML5 Game Development
Ready to Play: JavaScript / HTML5 Game DevelopmentReady to Play: JavaScript / HTML5 Game Development
Ready to Play: JavaScript / HTML5 Game Development
 

Mehr von Mark Hillick (6)

Introduction to MongoDB
Introduction to MongoDBIntroduction to MongoDB
Introduction to MongoDB
 
HackEire 2009
HackEire 2009HackEire 2009
HackEire 2009
 
Integrated Cache on Netscaler
Integrated Cache on NetscalerIntegrated Cache on Netscaler
Integrated Cache on Netscaler
 
Scareware - Irisscon 2009
Scareware - Irisscon 2009Scareware - Irisscon 2009
Scareware - Irisscon 2009
 
Implementing a WAF
Implementing a WAFImplementing a WAF
Implementing a WAF
 
MongoDB - Who, What & Where!
MongoDB - Who, What & Where!MongoDB - Who, What & Where!
MongoDB - Who, What & Where!
 

Kürzlich hochgeladen

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Kürzlich hochgeladen (20)

ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 

CTF: Bringing back more than sexy!

  • 1. CTFs - Bringing back more than sexy ;-) Mark Hillick - @markofu KTF Creator of HackEire Thursday 9 June 2011
  • 2. Usual stuff - disclaimer! Own views - not representative of Citrix Systems, IrissCert nor Phyllis and Ferb. I am speaking here entirely of my own opinion, which isn’t saying much but hey :) No dolphins were hurt in the making of this presentation! Thursday 9 June 2011
  • 3. Who are ya? too many years working in IT now @ vendor, used to be @ bank so I’m Ex-@IrissCert handler, #IrissCon, @HackEire @OwaspIreland Previous Owasp Presentations Cert Handler; WAF Implementation; Scareware via Web App Exploit Thursday 9 June 2011
  • 4. What’s this about? Nope Nor this guy CTFs - history, now & the future My experiences from building a CTF contest from scratch with no $$$$$ Thursday 9 June 2011
  • 5. So sorry!!! I know I had ‘sexy’ in the title but Thursday 9 June 2011
  • 6. What’s a CTF? (1) WAR-GAMES.......COMPETITION! ATTACK, ATTACK, ATTACK!!!! Thursday 9 June 2011
  • 7. What’s a CTF? (2) CTF contests.....serve as an educational exercise to give participants experience in securing a machine, as well as conducting and reacting to the sort of attacks found in the real world. source: http://en.wikipedia.org/wiki/Capture_the_flag#Computer_security && I agree with this partly :) Thursday 9 June 2011
  • 8. CTF? Nah, I’m not..... Thursday 9 June 2011
  • 9. We can’t all be....... Or..... Thursday 9 June 2011
  • 10. I’m not a hacker........ Source: http://img.wikinut.com/img/hzbaiyv.qfkbuofg/jpeg/0/The-comfort-circle.jpeg Thursday 9 June 2011
  • 13. but maybe try a CTF? learn outside of the norm Thursday 9 June 2011
  • 14. But I’d like to attend the conference!! You going to remember every talk? Didn’t think so...... Thursday 9 June 2011
  • 15. 1337 Test your l33t skillz NSFW Copious amounts of caffeine Do cool stuff with old/new friends Thursday 9 June 2011
  • 16. Get a job? Companies attempting to recruit off HackEire HackEire => winners got postgrad funding & several business cards :) SANS/US Govt Challenges => JOBS GALORE UK Cyberchallenge won by an ex-postman! Thursday 9 June 2011
  • 17. CTF Feedback 2010 I learnt a shitload today. I learnt more about what I don’t know than what I do know. Thanks! Thanks very much! I had so much fun and would be happy to pay 100 yoyos (pps) to enter in future. Thursday 9 June 2011
  • 18. Why allow your staff to compete in a CTF? Learn about defensive & offensive security in a safe environment! As opposed to........ You will learn & increase your awareness because you will be surprised..... $1000/day != good CTF competitor Thursday 9 June 2011
  • 19. So why run a CTF? Make a name... Spot talent Help others & give back a little Thursday 9 June 2011
  • 20. Why did I do it? & @edskoudis I wanted to learn & improve Thursday 9 June 2011
  • 21. Would I start it all now? Probably not > 250 hours last year Project & People Management Not everyone as passionate Thursday 9 June 2011
  • 22. What have I gained? I used to ‘not like’ my job very much & was bored. I wanted to play with tools I wouldn’t normally get to...... Thursday 9 June 2011
  • 23. What often happens in a CTF? In...... Out...... Thursday 9 June 2011
  • 24. Why? Is sadly all too infrequent..... Assign Roles/Functions Thursday 9 June 2011
  • 25. 2000 v 2011 NT4 W7, MacOS10, Linux Brick Phones iOS, Android $$$$$$$$ Credit Crunch West East Kazaa, Napster Twitter, FB, Skype... Books, Newspapers eBooks, Blogs, Web2.0 Man Utd :) Man Utd :) Q&A Interviews Interactive, Hands-On Thursday 9 June 2011
  • 26. The future? #ebooks #Virtualisation #Tablets/#Phones #OpenSource #CyberChallenges Galore :) Thursday 9 June 2011
  • 27. Today? Competitions are increasingly recognised as an effective way of promoting innovation......prize industry has boomed, increasing more than 15-fold. The US Space and Security authorities have been supporting world leading competitions for many years. The Obama administration has re-authorised the America COMPETES act to support innovation and innovators. Is it time for Europe to catch up? Source: http://www.europeansecuritychallenge.com/ Thursday 9 June 2011
  • 28. UK Cyber Challenge Secure Network Design Informed Defence Investigate & Understand Thursday 9 June 2011
  • 29. CTFs in the future? Part of Hands-On Interview Looking for skillz => USA/SANS, UK, EU Book Smart != Enough Thursday 9 June 2011
  • 30. It’d be nice if..... Goal: Keep improving....... Evolve, understand & innovate Thursday 9 June 2011
  • 31. 2011 for HackEire? Even better than last year & still free...... Huge improvements - more realistic New web portal Social Media PCAP Analysis More defensive controls Want to introduce images to defend but no time :( Thursday 9 June 2011
  • 32. Learn more about CTFs? Check out the DefCon, Sans, EthicalHacker.net (& more) websites Thursday 9 June 2011
  • 33. It’s all here....... Teamwork & Preparedness Constant Improvement Thursday 9 June 2011
  • 35. All done, no more! If you’re still awake..... Thursday 9 June 2011