Welcome back to year 3 of BreakICT!
We've got mo chals, mo shenanigans, and mo fun
Flow
- Competition starts, you can have a maximum team of 3 people. Single sign ups are allowed.
- Submit flags until you can't! Day 1 will be frozen at the end of the day (5:30pm CST), you can still solve challenges but you can't submit flags overnight!
- Flag submissions will open back up the next day.9:00AM CST
Details
- Some challenges require being on premise to obtain the flag.
- There MAY be issues with challenges, if unsure, contact admins over discord.
- Challenge types are: Decay, first blood, container, and static
- Decay: a challenge is worth less the more people solve it, even if its been solved before at a higher point value
- first blood: you get bonus points for being the first, or second/third. Time is of the essence
- container: a docker container is spawned for you to connect to and exploit. Your scope is strictly that device, pivoting is against scope unless specifically stated.
- standard: you solve challenge and get points. Yippee
RULES
- No flag/ solution sharing between teams. If we see this, teams involved are disqualified entirely.
- No Denial of Service, ARP/DNS poison/MiTM attacks permitted. You want to pass a bot check every 15 seconds??
- Be respectful of scope! Each challenge with other systems will have a defined scope of what to target. Go outside of that scope and you will be forcefully removed/ disqualified.
- Team size limit is 3.
- For challenges that require enumeration/brute force against a live host, wordlists will be specified / provided.
- Be respectful of other players. Entirely up to you to help others, but follow rule #1.