Skip to content

HITB SECCONF CTF 2022. Developed with ❤️ by Hackerdom team and HITB.

License

Notifications You must be signed in to change notification settings

HITB-CyberWeek/hitbsecconf-ctf-2022

Repository files navigation

HITB SECCONF CTF 2022

HITB SECCONF CTF is an onsite + online international challenge in information security. Developed by Hackerdom team for HITB SECCONF in Singapore. HITB SECCONF CTF 2022 was held on August 25th–26th, 2022.

The contest is driven by almost classic rules for Attack-Defense CTF. Each team is given a set of vulnerable services. Organizers regularly fill services with private information — the flags. The goal of each team is to find vulnerabilities, fix them in their services and exploit them to get flags from other teams.

This year we have had some innovations:

  • New scoring system (we use it for the second time, first one was at HITB PRO CTF 2021)
  • New flag format: TEAM042_PNFP4DKBOV6BTYL9YFGBQ9006582ADCX
  • Non-playable teams
  • Reverse proxies with per-team limits for services
  • DNS names for all services (e.g. example.team42.ctf.hitb.org)

You can read the details on the official contest website: https://ctf.hackerdom.ru/hitb-ctf-singapore-2022/.

Official conference website: https://conference.hitb.org/hitbsecconf2022sin/.

This repository contains

  • source of all services in folder services/
  • checkers for checksystem in folder checkers/
  • ... and config for it in cs/.
  • exploits for all services in folder sploits/
  • writeups with vulnerabilities and exploitation description for all services in folder writeups/

Also, we share with you some of our internal infrastructure magic:

All materials are licensed under MIT License.

Final scoreboard

Congratulations for 🇷🇺 Bushwhackers, hacked all services, for the first place!

Second place: 🇷🇺 C4T BuT S4D

Third place: 🇩🇪 saarsec

Final scoreboard

First bloods

SERVICE TEAM
linkextractor Bushwhackers
obscurity C4T BuT S4D
kv C4T BuT S4D
smallword C4T BuT S4D
n0tes Bushwhackers
sh Bushwhackers
crs Bushwhackers
wallet Bushwhackers
mypack RedRocket
issuecker C4T BuT S4D

Authors

This CTF is brought to you by these amazing guys:

If you have any question about services, platform or competition write us an email to [email protected] or [email protected].

© 2022 HackerDom