Showing posts with label competition. Show all posts
Showing posts with label competition. Show all posts

Wednesday, 6 November 2013

Symantec Cyber Readiness Challenge is Back in Singapore

"Symantec Security hosts the Cyber Readiness Challenge - an interactive 'capture the flag' style competition modelled after real-life security issues – at Cloud Expo Asia 2013.

The challenge positions participants as cyber security experts who will compete for system penetration within a simulated environment set with diverse and realistic vulnerabilities.

Within a fictitious scenario, participants will face challenges of increasing complexity and difficulty as they move through the various stages of a security breach."

Conference cum CTF



Register Here

For more information about Symantec's CRC
Link: http://www.symantec.com/page.jsp?id=cyber-readiness-challenge

Watch the introductory video about Symantec's CRC


Sunday, 3 November 2013

SANS 560 GPEN Training and CTF Event

Went for a GPEN course that was held in Singapore at the Grand Copthorne Waterfront Hotel last week and had a great time learning some of the network hacking stuffs that i am not aware of. Unlike the previous course i attended which was the GWAPT (Web Application Pen Test), the books for GPEN was much thicker. The trainer was an official GIAC trainer and was from Belgium and spoke good, clear and understandable English. He was fun and approachable and explain things confidently when we were unsure.

At the last day of the course, like GWAPT in Bangkok, there was a Capture the Flag event, a mini hacking competition for all the participants and whoever wins it will get a special medal. This limited edition medal can only be given to those who successfully managed to capture all the flags and present to the participants how they win it. 

The GPEN CTF was much harder than GWAPT. Only after the event was over that the trainer confessed that there were no vulnerable machines for us to exploit and we had to find another weakness in the system instead. So it was a disappointment when we found NOTHING after running tools like Nessus and NMAP vuln nse scripts. There were both Linux and Windows machines and we had to think out of the box on getting the flags! It wasn't as straight forward as i would have thought. Even the CTF organized by Symantec previously wasn't as tough as this. We needed to know how to use password cracking/guessing tools, had to know how to sniff and analyze traffic using Wireshark/TCPdump. We had to know how to crack the hashes and compile an exploit to try and exploit a Linux machine! And who would have guessed that one of the flags was stored in a VOIP traffic!!!??? It was a quite tough 3-4 hrs event.

And eventually, despite all the toughness, our team won and was the only team to capture all the flags after the hour is over. 

Here are some pictures: 

The Course

The Training Room

One of the Chapters

The Trainer

The Books

Posing beside the SANS banner

The Medals

Our team with the medals

Me with the GPEN Medal

The Medal Close Up


For more information about the GIAC GPEN course: 







Friday, 20 September 2013

Symantec Cyber Readiness Challenge - First in Asia (Singapore)

BT got second place in the Symantec Cyber Readiness Challenge- CTF Hacking Competition!



The CTF competition was not something we expected. Before that day, we spent countless nights familiarizing ourselves with Kali and BackTrack and focusing solely on the Network hacking. Of course, we performed our recon in finding out more about similar CTFs by other organizers in the past such as from DEFCon, HITB, Black Hat and read what sort of challenges await us.

So when we arrived, we were quite shocked to see players from big named companies and also from the Big Four joining which made us humble seeing their presence but then again... hackers constantly challenge one another and thats when the fun started!

As a rule of thumb, we cant expose the content of the competition but for those who are joining the Symantec CRC competition, better get yourselves prepared with Web, Network and Database pentest. Be good with the tools used such as Metasploit and NMAP.

It was a full 4 hrs competition that made us exhausted at the end of the hour. Unfortunately, there were also hiccups during the competition and as a personal advice: better use your own dongle rather than using the available made Wifi or LAN network.

We also experienced unethical hackers during capturing the flag. One of the rules is to NOT CHANGE anything that will not allow other players to compete and one of the teams were literally changing the passwords of the accounts they cracked which if reported could be disqualified. There were some tug of war to control the system each one kicking a session from one another.

It was tough but eventually we nailed it. We got second spot and the winner got a Flag more than us! Damn it! But all in all, this was indeed a fun competition that allowed us to hack/crack/pentest a real world scenario...


The BT Team


The Banner

Another huge Banner 

WE ARE THE second placed WINNER! 

The Trophy 

The Team-Up