You are not expected to reach the infrastructure yet, the links will become active once the testing phase starts.
Infrastructure#
Since not everyone has a lot of Attack/Defense experience and some have very advanced custom tooling that could create unfair advantages, we want to provide a level playing field. Therefore, you will be provided with an all inclusive offering and no root access to your machine.
You are only allowed to access your own team’s tools and are not allowed to give this access to anybody outside of your team (as stated in the rules). You will be able to interact with the other team’s services, but automated attacks are supposed to be run through the provided attacker tool.
During the competition, access to the infrastructure will be restricted to authorized IP addresses. So make sure you are able to connect to LAN as required in the Equipment guidelines.
Scoreboard#
A publicly available Scoreboard shows the state of the game (there will be a scoreboard freeze in the last hour). Keep in mind, that this will only display the scores for A/D and not integrate the Hardware challenge / LiveCTF.
Dashboard#
You have a dashboard at portal.testing.acsc.land which gives you the status of your services, links to all provided tooling and the option to download pcaps for custom traffic monitoring.
Tulip#
For easy network monitoring, we provide you with a pre-configured Tulip instance. It is the easiest option of analyzing the traffic for attack patterns, but if you want to go more sophisticated then we can recommend downloading the pcaps from the Dashboard.
Gitea#
Management of the source code for your services will be through a hosted Gitea instance per-team. There you can push changes and the integrated CI/CD pipeline will take care of building and deploying the service for you.
You will not be able to change all files in a project, the limitations are listed in PROTECTED_FILES in the meta.env file of every repository.
Attacker#
The attack tool of choice for this CTF is a custom attacker tool integrated into the platform. While would be possible to use your own attacker tooling, we ask you to use the provided tooling.
Testing#
We will provide a testing phase from August 31st to September 6th. Further information and credentials will be provided to you in your team channel.
This will be played with the challenges that were provided for ECSC2022, and is therefore not representative of how the challenges will look and what difficulty they will be (as ECSC is a 10 player per team competition). Rather, it is provided for you to get aquainted to the infrastructure and be able to play with the tooling.
Bugs and Vulnerabilities#
No software is perfect and our infrastructure will certainly not be either. We therefore want to ask you to respect the rules and not attack anything that is not clearly made to be attacked (this means no attacking the infrastructure).
Do not go looking for them please, but if you do find a bug, weird behaviour or even vulnerability during the testing phase or during the running CTF then please report it to us by opening a ticket. We will promise you a spot in the Hall of Fame and eternal glory.
If we catch you attacking or even exploiting the infrastructure, especially during the finale but also during the test run, then we retain the full rights to reduce your points, disqualify your team, or put in place other actions.
