SlideShare a Scribd company logo
CTFs - Bringing back
                        more than sexy ;-)

                           Mark Hillick - @markofu

                                    KTF

                             Creator of HackEire



Thursday 9 June 2011
Usual stuff - disclaimer!

                       Own views - not representative of Citrix
                       Systems, IrissCert nor Phyllis and Ferb. I am
                       speaking here entirely of my own opinion,
                       which isn’t saying much but hey :)



                       No dolphins were hurt in the making of this
                       presentation!




Thursday 9 June 2011
Who are ya?
                       too many years working in IT

                       now @ vendor, used to be @ bank so I’m

                       Ex-@IrissCert handler, #IrissCon, @HackEire
                       @OwaspIreland

                       Previous Owasp Presentations

                           Cert Handler;

                           WAF Implementation;

                           Scareware via Web App Exploit
Thursday 9 June 2011
What’s this about?
                       Nope



                       Nor this guy




                       CTFs - history, now & the future

                       My experiences from building a CTF contest
                       from scratch with no $$$$$
Thursday 9 June 2011
So sorry!!!

                       I know I had ‘sexy’ in the title but




Thursday 9 June 2011
What’s a CTF? (1)
                              WAR-GAMES.......COMPETITION!




                             ATTACK, ATTACK, ATTACK!!!!
Thursday 9 June 2011
What’s a CTF? (2)


                       CTF contests.....serve as an educational
                       exercise to give participants experience in
                       securing a machine, as well as conducting
                       and reacting to the sort of attacks found in
                       the real world.


                       source: http://en.wikipedia.org/wiki/Capture_the_flag#Computer_security && I agree with this partly :)




Thursday 9 June 2011
CTF? Nah, I’m not.....




Thursday 9 June 2011
We can’t all be.......




                         Or.....




Thursday 9 June 2011
I’m not a hacker........




                Source:   http://img.wikinut.com/img/hzbaiyv.qfkbuofg/jpeg/0/The-comfort-circle.jpeg


Thursday 9 June 2011
Thursday 9 June 2011
Thursday 9 June 2011
but maybe try a CTF?




                        learn outside of the norm


Thursday 9 June 2011
But I’d like to attend
                         the conference!!
                       You going to remember every talk?




                       Didn’t think so......
Thursday 9 June 2011
1337
                       Test your l33t skillz



                       NSFW



                       Copious amounts of caffeine



                       Do cool stuff with old/new friends


Thursday 9 June 2011
Get a job?
                       Companies attempting to recruit off HackEire



                       HackEire => winners got postgrad funding &
                       several business cards :)



                       SANS/US Govt Challenges => JOBS GALORE



                       UK Cyberchallenge won by an ex-postman!

Thursday 9 June 2011
CTF Feedback 2010

                       I learnt a shitload today. I learnt more
                       about what I don’t know than what I do
                       know. Thanks!



                       Thanks very much! I had so much fun and
                       would be happy to pay 100 yoyos (pps) to
                       enter in future.



Thursday 9 June 2011
Why allow your staff to
                    compete in a CTF?
                       Learn about defensive & offensive security in
                       a safe environment! As opposed to........



                       You will learn & increase your awareness
                       because you will be surprised.....



                       $1000/day != good CTF competitor


Thursday 9 June 2011
So why run a CTF?


                       Make a name...



                       Spot talent



                       Help others & give back a little



Thursday 9 June 2011
Why did I do it?



                                   & @edskoudis



                       I wanted to learn & improve




Thursday 9 June 2011
Would I start it all now?

                       Probably not



                       > 250 hours last year



                       Project & People Management



                       Not everyone as passionate

Thursday 9 June 2011
What have I gained?
               I used to ‘not like’ my job very much & was bored. I
               wanted to play with tools I wouldn’t normally get to......




Thursday 9 June 2011
What often happens in a
                         CTF?
             In......




                        Out......




Thursday 9 June 2011
Why?




                       Is sadly all too infrequent.....

                       Assign Roles/Functions
Thursday 9 June 2011
2000 v 2011
                       NT4                 W7, MacOS10, Linux

                       Brick Phones        iOS, Android

                       $$$$$$$$            Credit Crunch

                       West                East

                       Kazaa, Napster      Twitter, FB, Skype...

                       Books, Newspapers   eBooks, Blogs, Web2.0

                       Man Utd :)          Man Utd :)

                       Q&A Interviews      Interactive, Hands-On

Thursday 9 June 2011
The future?
                       #ebooks            #Virtualisation

                       #Tablets/#Phones   #OpenSource




                       #CyberChallenges
                       Galore :)


Thursday 9 June 2011
Today?
 Competitions are increasingly recognised as an effective way
 of promoting innovation......prize industry has boomed,
 increasing more than 15-fold. The US Space and Security
 authorities have been supporting world leading competitions
 for many years. The Obama administration has re-authorised
 the America COMPETES act to support innovation and
 innovators. Is it time for Europe to catch up?


                   Source:   http://www.europeansecuritychallenge.com/




Thursday 9 June 2011
UK Cyber Challenge



                       Secure Network Design



                       Informed Defence



                       Investigate & Understand

Thursday 9 June 2011
CTFs in the future?



                       Part of Hands-On Interview



                       Looking for skillz => USA/SANS, UK, EU



                       Book Smart != Enough

Thursday 9 June 2011
It’d be nice if.....




               Goal: Keep improving.......

               Evolve, understand & innovate
Thursday 9 June 2011
2011 for HackEire?
                       Even better than last year & still free......

                         Huge improvements - more realistic

                         New web portal

                         Social Media

                         PCAP Analysis

                         More defensive controls

                         Want to introduce images to defend but
                         no time :(


Thursday 9 June 2011
Learn more about CTFs?




               Check out the DefCon, Sans, EthicalHacker.net (& more)
               websites

Thursday 9 June 2011
It’s all here.......




               Teamwork & Preparedness

               Constant Improvement
Thursday 9 June 2011
Q&A




Thursday 9 June 2011
All done, no more!

                       If you’re still awake.....




Thursday 9 June 2011

More Related Content

Similar to CTF: Bringing back more than sexy!

Jeremiah Pliché's PBE 2011
Jeremiah Pliché's PBE 2011Jeremiah Pliché's PBE 2011
Jeremiah Pliché's PBE 2011
jpliche12
 
When machines think
When machines thinkWhen machines think
When machines think
University of Hertfordshire
 
ITP / SED Day 4
ITP / SED Day 4ITP / SED Day 4
ITP / SED Day 4
Sami Niemelä
 
Designing Science and Literacy Games for Nintendo DS
Designing Science and Literacy Games for Nintendo DSDesigning Science and Literacy Games for Nintendo DS
Designing Science and Literacy Games for Nintendo DS
John Parris
 
Devopsdays Goteborg 2011 - State of the Union
Devopsdays Goteborg 2011 - State of the UnionDevopsdays Goteborg 2011 - State of the Union
Devopsdays Goteborg 2011 - State of the Union
John Willis
 
Kin Global Kellogg 2011 Chicago
Kin Global Kellogg 2011 ChicagoKin Global Kellogg 2011 Chicago
Kin Global Kellogg 2011 Chicago
Carlos Dominguez
 
Celebrate Texas Voices: Empowering Digital Witnesses
Celebrate Texas Voices: Empowering Digital WitnessesCelebrate Texas Voices: Empowering Digital Witnesses
Celebrate Texas Voices: Empowering Digital Witnesses
Wesley Fryer
 
Mo' Dimensions Mo' Problems
Mo' Dimensions Mo' ProblemsMo' Dimensions Mo' Problems
Mo' Dimensions Mo' Problems
Seantron
 
Boston Globe: Responsive Web Design
Boston Globe: Responsive Web DesignBoston Globe: Responsive Web Design
Boston Globe: Responsive Web Design
The Media Consortium
 
Netcultfunding frontlineclub-rendeiro
Netcultfunding frontlineclub-rendeiroNetcultfunding frontlineclub-rendeiro
Netcultfunding frontlineclub-rendeiro
bicyclemark
 
Opensource Authentication and Authorization
Opensource Authentication and AuthorizationOpensource Authentication and Authorization
Opensource Authentication and Authorization
ConFoo
 
From Apples to Augmented Cognition (Current and Future Trends in Mobile)
From Apples to Augmented Cognition (Current and Future Trends in Mobile)From Apples to Augmented Cognition (Current and Future Trends in Mobile)
From Apples to Augmented Cognition (Current and Future Trends in Mobile)
Paul Golding
 
Rise of devops
Rise of devopsRise of devops
Rise of devops
atmosorg
 
Digital & Social Media Marketing
Digital & Social Media MarketingDigital & Social Media Marketing
Digital & Social Media Marketing
Frank Dinolfo
 
Destroy the box
Destroy the boxDestroy the box
Destroy the box
jsokohl
 
Made by Many Sweden
Made by Many SwedenMade by Many Sweden
Made by Many Sweden
Made by Many
 
State of Social & Informal Learning
State of Social & Informal LearningState of Social & Informal Learning
State of Social & Informal Learning
Tom Hood, CPA,CITP,CGMA
 
Godoggo
GodoggoGodoggo
Godoggo
mskmoorthy
 
YOU WILL REGRET THIS
YOU WILL REGRET THISYOU WILL REGRET THIS
YOU WILL REGRET THIS
MononcQc
 
Ready to Play: JavaScript / HTML5 Game Development
Ready to Play: JavaScript / HTML5 Game DevelopmentReady to Play: JavaScript / HTML5 Game Development
Ready to Play: JavaScript / HTML5 Game Development
Zachary Johnson
 

Similar to CTF: Bringing back more than sexy! (20)

Jeremiah Pliché's PBE 2011
Jeremiah Pliché's PBE 2011Jeremiah Pliché's PBE 2011
Jeremiah Pliché's PBE 2011
 
When machines think
When machines thinkWhen machines think
When machines think
 
ITP / SED Day 4
ITP / SED Day 4ITP / SED Day 4
ITP / SED Day 4
 
Designing Science and Literacy Games for Nintendo DS
Designing Science and Literacy Games for Nintendo DSDesigning Science and Literacy Games for Nintendo DS
Designing Science and Literacy Games for Nintendo DS
 
Devopsdays Goteborg 2011 - State of the Union
Devopsdays Goteborg 2011 - State of the UnionDevopsdays Goteborg 2011 - State of the Union
Devopsdays Goteborg 2011 - State of the Union
 
Kin Global Kellogg 2011 Chicago
Kin Global Kellogg 2011 ChicagoKin Global Kellogg 2011 Chicago
Kin Global Kellogg 2011 Chicago
 
Celebrate Texas Voices: Empowering Digital Witnesses
Celebrate Texas Voices: Empowering Digital WitnessesCelebrate Texas Voices: Empowering Digital Witnesses
Celebrate Texas Voices: Empowering Digital Witnesses
 
Mo' Dimensions Mo' Problems
Mo' Dimensions Mo' ProblemsMo' Dimensions Mo' Problems
Mo' Dimensions Mo' Problems
 
Boston Globe: Responsive Web Design
Boston Globe: Responsive Web DesignBoston Globe: Responsive Web Design
Boston Globe: Responsive Web Design
 
Netcultfunding frontlineclub-rendeiro
Netcultfunding frontlineclub-rendeiroNetcultfunding frontlineclub-rendeiro
Netcultfunding frontlineclub-rendeiro
 
Opensource Authentication and Authorization
Opensource Authentication and AuthorizationOpensource Authentication and Authorization
Opensource Authentication and Authorization
 
From Apples to Augmented Cognition (Current and Future Trends in Mobile)
From Apples to Augmented Cognition (Current and Future Trends in Mobile)From Apples to Augmented Cognition (Current and Future Trends in Mobile)
From Apples to Augmented Cognition (Current and Future Trends in Mobile)
 
Rise of devops
Rise of devopsRise of devops
Rise of devops
 
Digital & Social Media Marketing
Digital & Social Media MarketingDigital & Social Media Marketing
Digital & Social Media Marketing
 
Destroy the box
Destroy the boxDestroy the box
Destroy the box
 
Made by Many Sweden
Made by Many SwedenMade by Many Sweden
Made by Many Sweden
 
State of Social & Informal Learning
State of Social & Informal LearningState of Social & Informal Learning
State of Social & Informal Learning
 
Godoggo
GodoggoGodoggo
Godoggo
 
YOU WILL REGRET THIS
YOU WILL REGRET THISYOU WILL REGRET THIS
YOU WILL REGRET THIS
 
Ready to Play: JavaScript / HTML5 Game Development
Ready to Play: JavaScript / HTML5 Game DevelopmentReady to Play: JavaScript / HTML5 Game Development
Ready to Play: JavaScript / HTML5 Game Development
 

More from Mark Hillick

Introduction to MongoDB
Introduction to MongoDBIntroduction to MongoDB
Introduction to MongoDB
Mark Hillick
 
HackEire 2009
HackEire 2009HackEire 2009
HackEire 2009
Mark Hillick
 
Integrated Cache on Netscaler
Integrated Cache on NetscalerIntegrated Cache on Netscaler
Integrated Cache on Netscaler
Mark Hillick
 
Scareware - Irisscon 2009
Scareware - Irisscon 2009Scareware - Irisscon 2009
Scareware - Irisscon 2009
Mark Hillick
 
Implementing a WAF
Implementing a WAFImplementing a WAF
Implementing a WAF
Mark Hillick
 
MongoDB - Who, What & Where!
MongoDB - Who, What & Where!MongoDB - Who, What & Where!
MongoDB - Who, What & Where!
Mark Hillick
 

More from Mark Hillick (6)

Introduction to MongoDB
Introduction to MongoDBIntroduction to MongoDB
Introduction to MongoDB
 
HackEire 2009
HackEire 2009HackEire 2009
HackEire 2009
 
Integrated Cache on Netscaler
Integrated Cache on NetscalerIntegrated Cache on Netscaler
Integrated Cache on Netscaler
 
Scareware - Irisscon 2009
Scareware - Irisscon 2009Scareware - Irisscon 2009
Scareware - Irisscon 2009
 
Implementing a WAF
Implementing a WAFImplementing a WAF
Implementing a WAF
 
MongoDB - Who, What & Where!
MongoDB - Who, What & Where!MongoDB - Who, What & Where!
MongoDB - Who, What & Where!
 

Recently uploaded

Climate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing DaysClimate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing Days
Kari Kakkonen
 
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to ProductionGenerative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Aggregage
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
SOFTTECHHUB
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
ControlCase
 
UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5
DianaGray10
 
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdfObservability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Paige Cruz
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
Daiki Mogmet Ito
 
Artificial Intelligence for XMLDevelopment
Artificial Intelligence for XMLDevelopmentArtificial Intelligence for XMLDevelopment
Artificial Intelligence for XMLDevelopment
Octavian Nadolu
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
Matthew Sinclair
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
innovationoecd
 
Enchancing adoption of Open Source Libraries. A case study on Albumentations.AI
Enchancing adoption of Open Source Libraries. A case study on Albumentations.AIEnchancing adoption of Open Source Libraries. A case study on Albumentations.AI
Enchancing adoption of Open Source Libraries. A case study on Albumentations.AI
Vladimir Iglovikov, Ph.D.
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
Ana-Maria Mihalceanu
 
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Speck&Tech
 
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
James Anderson
 
Mind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AIMind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AI
Kumud Singh
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
Alpen-Adria-Universität
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
DianaGray10
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
Neo4j
 
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
SOFTTECHHUB
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
KatiaHIMEUR1
 

Recently uploaded (20)

Climate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing DaysClimate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing Days
 
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to ProductionGenerative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to Production
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
 
UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5
 
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdfObservability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
 
Artificial Intelligence for XMLDevelopment
Artificial Intelligence for XMLDevelopmentArtificial Intelligence for XMLDevelopment
Artificial Intelligence for XMLDevelopment
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
 
Enchancing adoption of Open Source Libraries. A case study on Albumentations.AI
Enchancing adoption of Open Source Libraries. A case study on Albumentations.AIEnchancing adoption of Open Source Libraries. A case study on Albumentations.AI
Enchancing adoption of Open Source Libraries. A case study on Albumentations.AI
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
 
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
 
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
 
Mind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AIMind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AI
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
 
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
 

CTF: Bringing back more than sexy!

  • 1. CTFs - Bringing back more than sexy ;-) Mark Hillick - @markofu KTF Creator of HackEire Thursday 9 June 2011
  • 2. Usual stuff - disclaimer! Own views - not representative of Citrix Systems, IrissCert nor Phyllis and Ferb. I am speaking here entirely of my own opinion, which isn’t saying much but hey :) No dolphins were hurt in the making of this presentation! Thursday 9 June 2011
  • 3. Who are ya? too many years working in IT now @ vendor, used to be @ bank so I’m Ex-@IrissCert handler, #IrissCon, @HackEire @OwaspIreland Previous Owasp Presentations Cert Handler; WAF Implementation; Scareware via Web App Exploit Thursday 9 June 2011
  • 4. What’s this about? Nope Nor this guy CTFs - history, now & the future My experiences from building a CTF contest from scratch with no $$$$$ Thursday 9 June 2011
  • 5. So sorry!!! I know I had ‘sexy’ in the title but Thursday 9 June 2011
  • 6. What’s a CTF? (1) WAR-GAMES.......COMPETITION! ATTACK, ATTACK, ATTACK!!!! Thursday 9 June 2011
  • 7. What’s a CTF? (2) CTF contests.....serve as an educational exercise to give participants experience in securing a machine, as well as conducting and reacting to the sort of attacks found in the real world. source: http://en.wikipedia.org/wiki/Capture_the_flag#Computer_security && I agree with this partly :) Thursday 9 June 2011
  • 8. CTF? Nah, I’m not..... Thursday 9 June 2011
  • 9. We can’t all be....... Or..... Thursday 9 June 2011
  • 10. I’m not a hacker........ Source: http://img.wikinut.com/img/hzbaiyv.qfkbuofg/jpeg/0/The-comfort-circle.jpeg Thursday 9 June 2011
  • 13. but maybe try a CTF? learn outside of the norm Thursday 9 June 2011
  • 14. But I’d like to attend the conference!! You going to remember every talk? Didn’t think so...... Thursday 9 June 2011
  • 15. 1337 Test your l33t skillz NSFW Copious amounts of caffeine Do cool stuff with old/new friends Thursday 9 June 2011
  • 16. Get a job? Companies attempting to recruit off HackEire HackEire => winners got postgrad funding & several business cards :) SANS/US Govt Challenges => JOBS GALORE UK Cyberchallenge won by an ex-postman! Thursday 9 June 2011
  • 17. CTF Feedback 2010 I learnt a shitload today. I learnt more about what I don’t know than what I do know. Thanks! Thanks very much! I had so much fun and would be happy to pay 100 yoyos (pps) to enter in future. Thursday 9 June 2011
  • 18. Why allow your staff to compete in a CTF? Learn about defensive & offensive security in a safe environment! As opposed to........ You will learn & increase your awareness because you will be surprised..... $1000/day != good CTF competitor Thursday 9 June 2011
  • 19. So why run a CTF? Make a name... Spot talent Help others & give back a little Thursday 9 June 2011
  • 20. Why did I do it? & @edskoudis I wanted to learn & improve Thursday 9 June 2011
  • 21. Would I start it all now? Probably not > 250 hours last year Project & People Management Not everyone as passionate Thursday 9 June 2011
  • 22. What have I gained? I used to ‘not like’ my job very much & was bored. I wanted to play with tools I wouldn’t normally get to...... Thursday 9 June 2011
  • 23. What often happens in a CTF? In...... Out...... Thursday 9 June 2011
  • 24. Why? Is sadly all too infrequent..... Assign Roles/Functions Thursday 9 June 2011
  • 25. 2000 v 2011 NT4 W7, MacOS10, Linux Brick Phones iOS, Android $$$$$$$$ Credit Crunch West East Kazaa, Napster Twitter, FB, Skype... Books, Newspapers eBooks, Blogs, Web2.0 Man Utd :) Man Utd :) Q&A Interviews Interactive, Hands-On Thursday 9 June 2011
  • 26. The future? #ebooks #Virtualisation #Tablets/#Phones #OpenSource #CyberChallenges Galore :) Thursday 9 June 2011
  • 27. Today? Competitions are increasingly recognised as an effective way of promoting innovation......prize industry has boomed, increasing more than 15-fold. The US Space and Security authorities have been supporting world leading competitions for many years. The Obama administration has re-authorised the America COMPETES act to support innovation and innovators. Is it time for Europe to catch up? Source: http://www.europeansecuritychallenge.com/ Thursday 9 June 2011
  • 28. UK Cyber Challenge Secure Network Design Informed Defence Investigate & Understand Thursday 9 June 2011
  • 29. CTFs in the future? Part of Hands-On Interview Looking for skillz => USA/SANS, UK, EU Book Smart != Enough Thursday 9 June 2011
  • 30. It’d be nice if..... Goal: Keep improving....... Evolve, understand & innovate Thursday 9 June 2011
  • 31. 2011 for HackEire? Even better than last year & still free...... Huge improvements - more realistic New web portal Social Media PCAP Analysis More defensive controls Want to introduce images to defend but no time :( Thursday 9 June 2011
  • 32. Learn more about CTFs? Check out the DefCon, Sans, EthicalHacker.net (& more) websites Thursday 9 June 2011
  • 33. It’s all here....... Teamwork & Preparedness Constant Improvement Thursday 9 June 2011
  • 35. All done, no more! If you’re still awake..... Thursday 9 June 2011