Sat, 26 March 2016, 20:00 UTC — Sun, 27 March 2016, 20:00 UTC
On-line
A Securinets CTF event.
Format: Jeopardy
Official URL: https://www.ctfsecurinets.com/app.php/login
This event's future weight is subject of public voting!
Event organizersCTF Securinets Quals 2016 is an on-line jeopardy style CTF organized by Securinets Club.
You can find more details on our website: www.ctfsecurinets.com
or www.securinets.com
77 teams total
Place | Team | CTF points | Rating points | |
---|---|---|---|---|
1 | Pwnium | 5265.000 | 28.520 | |
2 | SpectriX_BestCheaterz | 5265.000 | 21.390 | |
3 | DATATECH | 5190.000 | 18.810 | |
4 | pwnspiracy | 5040.000 | 17.216 | |
5 | HackXore | 5040.000 | 16.503 | |
6 | th3jackers | 4940.000 | 15.756 | |
7 | ISITDTU | 4940.000 | 15.417 | |
8 | Batman's Kitchen | 4915.000 | 15.095 | |
9 | dcua | 4590.000 | 14.016 | |
10 | soft cotton | 4149.000 | 12.663 | |
11 | 0wn3r5-bugMakers | 3315.000 | 10.275 | |
12 | Raccoons | 2774.000 | 8.702 | |
13 | The DHARMA Initiative | 2665.000 | 8.315 | |
14 | Sw1ssFr13nds | 2624.000 | 8.126 | |
15 | NowaySec | 2499.000 | 7.719 | |
16 | SecuriNets ISI 1 | 2449.000 | 7.524 | |
17 | Snatch The Root | 2374.000 | 7.269 | |
18 | k18DTU | 2274.000 | 6.951 | |
19 | Bugs_Bunny | 2199.000 | 6.706 | |
20 | TapuTeam | 2024.000 | 6.195 | |
21 | Mammon Machine | 1890.000 | 5.798 | |
22 | noraneco | 1874.000 | 5.724 | |
23 | SecuriNets ISI 2 | 1674.000 | 5.154 | |
24 | kaijo | 1624.000 | 4.993 | |
25 | Marsupilamis | 1599.000 | 4.901 | |
26 | UCCU | 1425.000 | 4.408 | |
27 | PENSIUN | DFCI | SUKSMA | 1349.000 | 4.182 | |
28 | ZGomBa | 1074.000 | 3.418 | |
29 | Fourchette Bombe | 1024.000 | 3.265 | |
30 | jinmo123 | 1024.000 | 3.249 | |
31 | mathboy7 | 1024.000 | 3.233 | |
32 | taurus | 974.000 | 3.084 | |
33 | sina | 924.000 | 2.935 | |
34 | Execut3 | 874.000 | 2.787 | |
35 | KillMePLZ | 799.000 | 2.571 | |
36 | hAIXer | 775.000 | 2.495 | |
37 | LoneWolf | 774.000 | 2.482 | |
38 | thuong123abc | 749.000 | 2.404 | |
39 | DjigIT | 724.000 | 2.327 | |
40 | vanhelsing | 724.000 | 2.317 | |
41 | MV9rwGOf08 | 716.000 | 2.287 | |
42 | kasper | 649.000 | 2.097 | |
43 | thebestd92 | 649.000 | 2.089 | |
44 | 11-Digit Prime Number | 649.000 | 2.082 | |
45 | Oleg | 624.000 | 2.007 | |
46 | n0pster | 624.000 | 2.000 | |
47 | gmilte | 524.000 | 1.723 | |
48 | NIS | 449.000 | 1.513 | |
49 | FSoc!3ty | 424.000 | 1.439 | |
50 | h4ckf0rf00dz | 424.000 | 1.434 | |
51 | Secureal | 249.000 | 0.954 | |
52 | iSome | 224.000 | 0.881 | |
53 | JoeGaje | 224.000 | 0.876 | |
54 | pwnplay | 224.000 | 0.871 | |
55 | IIT_WHM | 149.000 | 0.663 | |
56 | ENSIT-INFO | 124.000 | 0.590 | |
57 | IIT-Sec | 124.000 | 0.586 | |
58 | cafmin | 124.000 | 0.582 | |
59 | Splinter | 99.000 | 0.510 | |
59 | Ossec_Team | 124.000 | 0.578 | |
60 | Jeramy | 124.000 | 0.574 | |
61 | H3RM1T | 124.000 | 0.570 | |
62 | honc | 124.000 | 0.566 | |
63 | NeOLux-C1Ph3r | 124.000 | 0.562 | |
64 | zbaber united | 124.000 | 0.559 | |
65 | BlackSpace | 124.000 | 0.555 | |
66 | Ninja Turtle | 100.000 | 0.487 | |
67 | _tomcat_ | 99.000 | 0.481 | |
68 | xor00 | 99.000 | 0.478 | |
70 | MrMugiwara | 99.000 | 0.472 | |
71 | ASIS | 99.000 | 0.469 | |
72 | hy00un | 99.000 | 0.466 | |
73 | astrodroids | 99.000 | 0.463 | |
74 | TheFuckUps | 99.000 | 0.461 | |
75 | SecuriTeam | 99.000 | 0.458 | |
76 | The Emperørs | 99.000 | 0.456 | |
77 | unicornsandrainbows | 99.000 | 0.227 |
registration is broken for this student ctf.
Hello,
You have to check these two teams SpectriX and SpectriX_II
os:~ amine$ curl -ks https://ctfsecurinets.com/getTask/14 -b "PHPSESSID=0" | grep SpectriX
<div class="errSub">SpectriX has submitteda an invalid response at 11:33:55 at 27/03/2016</div>
<div class="errSub">SpectriX has submitteda an invalid response at 11:54:27 at 27/03/2016</div>
<div class="sucSub">SpectriX_II has submitteda a valid response at 13:07:44 at 27/03/2016</div>
<div class="sucSub">SpectriX has submitteda a valid response at 13:08:34 at 27/03/2016</div>
os:~ amine$ curl -ks https://ctfsecurinets.com/getTask/16 -b "PHPSESSID=0" | grep SpectriX
<div class="errSub">SpectriX has submitteda an invalid response at 05:42:35 at 27/03/2016</div>
<div class="errSub">SpectriX has submitteda an invalid response at 05:47:52 at 27/03/2016</div>
<div class="errSub">SpectriX has submitteda an invalid response at 11:34:28 at 27/03/2016</div>
os:~ amine$ curl -ks https://ctfsecurinets.com/getTask/28 -b "PHPSESSID=0" | grep SpectriX
<div class="sucSub">SpectriX has submitteda a valid response at 22:13:54 at 26/03/2016</div>
<div class="sucSub">SpectriX_II has submitteda a valid response at 22:52:24 at 26/03/2016</div>
os:~ amine$ curl -ks https://ctfsecurinets.com/getTask/10 -b "PHPSESSID=0" | grep SpectriX
<div class="sucSub">SpectriX_II has submitteda a valid response at 22:00:32 at 26/03/2016</div>
<div class="sucSub">SpectriX has submitteda a valid response at 22:33:12 at 26/03/2016</div>
os:~ amine$ curl -ks https://ctfsecurinets.com/getTask/11 -b "PHPSESSID=0" | grep SpectriX
<div class="sucSub">SpectriX_II has submitteda a valid response at 00:14:14 at 27/03/2016</div>
<div class="sucSub">SpectriX has submitteda a valid response at 03:34:17 at 27/03/2016</div>
....
Spectrix cheaaaaaat level god
i think that double account and submitting flag are prohibitted!!
admin check their submits plzzzzzz
Check submittion log , SpectriX Cheat !
Spectrix Stop Sharing Flag's With Others TEAM
+ Double Accounts WTF
So Fuck You a Lot :D
you want To qualify With All Your Familly as 2 Team hhhhhhh Fuck Your Level
Securinets you have locked My account Fucks All Of You
But Securinets gives Flags To Spectrix and you Think Nobody Know About This All Memmers In Ctf Know This Bull Sheat
I guess I am now glad that the registration is broken...
There vvas a bug if server...............players can see disabled challenge ===> played before admin publish challenge -.-'
Really -_- ?? dafuq
SpectriX
SpectriX_II
the same score in the end hahahhah
SpectriX and SpectriX 2 and DATATECH and S1
all is cheating teams
GGWP
cheat ? wkwkw like gta pc "hesoyam" :V
First of all, registration is finished before the CTF, it's useless to cry if you are not accepted after the start of the CTF.
With that we took the risk of leaving the open enrollment provided to activate their account. Each period registered accounts are activated.
Those who were violating the rules deserve to be banished (1 attempt to validate at least every 5 seconds). So if there is someone who has been banned is not because of us. In addition there is the IRC channel if you have a problem you could tell us. Banished every team we unblock his account.
The top five winning teams are provisional. We'll check the logs attempts and validation to check if there are teams that have cheated.
The team that receives flags will be disqualified in the final round if it is among the top teams.
About Spectrix, SpectriX_II, DATATECH, according to the names of registered participants, they are the best CTF participants in Tunisia. They did not need to share the flags. With that we will check if there are teams that have cheated.
Instead, we receive their questions on IRC like other teams and were never given a flag and never advantaged one team over another.
Congratulations everyone.
I hope you have fun during this CTF and you saw new tasks.
What about this :) yes they are the best CTF participants cheated in Tunisia (y)
os:~ amine$ curl -ks https://ctfsecurinets.com/getTask/14 -b "PHPSESSID=0" | grep SpectriX
<div class="errSub">SpectriX has submitteda an invalid response at 11:33:55 at 27/03/2016</div>
<div class="errSub">SpectriX has submitteda an invalid response at 11:54:27 at 27/03/2016</div>
<div class="sucSub">SpectriX_II has submitteda a valid response at 13:07:44 at 27/03/2016</div>
<div class="sucSub">SpectriX has submitteda a valid response at 13:08:34 at 27/03/2016</div>
os:~ amine$ curl -ks https://ctfsecurinets.com/getTask/16 -b "PHPSESSID=0" | grep SpectriX
<div class="errSub">SpectriX has submitteda an invalid response at 05:42:35 at 27/03/2016</div>
<div class="errSub">SpectriX has submitteda an invalid response at 05:47:52 at 27/03/2016</div>
<div class="errSub">SpectriX has submitteda an invalid response at 11:34:28 at 27/03/2016</div>
os:~ amine$ curl -ks https://ctfsecurinets.com/getTask/28 -b "PHPSESSID=0" | grep SpectriX
<div class="sucSub">SpectriX has submitteda a valid response at 22:13:54 at 26/03/2016</div>
<div class="sucSub">SpectriX_II has submitteda a valid response at 22:52:24 at 26/03/2016</div>
os:~ amine$ curl -ks https://ctfsecurinets.com/getTask/10 -b "PHPSESSID=0" | grep SpectriX
<div class="sucSub">SpectriX_II has submitteda a valid response at 22:00:32 at 26/03/2016</div>
<div class="sucSub">SpectriX has submitteda a valid response at 22:33:12 at 26/03/2016</div>
os:~ amine$ curl -ks https://ctfsecurinets.com/getTask/11 -b "PHPSESSID=0" | grep SpectriX
<div class="sucSub">SpectriX_II has submitteda a valid response at 00:14:14 at 27/03/2016</div>
<div class="sucSub">SpectriX has submitteda a valid response at 03:34:17 at 27/03/2016</div>
I'm not defending them, I don't know why for the easy tasks like task14 (hideen1) they have submitted after one minute (if they do use firefox only for this task as mentionned in the hint they can sove it quickly). The same thing with task16 (hidden3) (scanning the records of hidden.ctfsecurinets.com) and the task28 (pwn0) the easiest pwn task.
But in the other difficult tasks they take more time like task 10 (more than 30 minutes) and 11 (3 hours 15 minutes).
zebi la?
@Empereur Paradis zebi la? ntoma 3attaya tmadelhom flags nik zabour mkom 3attaaayaaa
Interesting case with this CTF as an example of how a bad CTF rating can be gamed. Shows an issue with the system.
@Matt I totally agree. I think the problem with this CTF's weighting is because of multiple CTFs happening at the same time, and not many top50 teams have participated in it. I think the polled weighting should also be weighted by the team's ranking on CTFTime last year. This way higher ranked team's poll get's weighted higher, which makes a lot more sense to me. I also think that organizers definitely should not get to vote for their own CTF and to punish these people from boosting the weighting rate of this CTF too high, ctftime admin should give them a weight of 0.
I do find it amusing that when I looked at Empereur's profile just a couple of days ago, he/she wasn't a member of any team. But is now on a team that participated just enough to vote as a team. I doubt he/she could have voted otherwise. Another way to work the system. I have to wonder, considering all of the gaming ,if the CTF was planned to happen on a weekend with two major CTFs in order to avoid getting the better teams involved.
@h0twinter this is a terrible idea. Already there are some top teams voting with approach: "did we win? score to max!" and "did we lose? score to min!". If you give their votes higher weight then this will make it even harder for a different/new team to get to the top. This would work of people were honest and impartial with their votes, and they're not.
I thought there was a cap at 1,5x the original weight? How did this get up to 16? I feel like the same happened for Insomni'Hack
Current voting max seems 1.5x of last year, but not less than 25 for new CTFs. This sounds reasonable, because gives equal opportunity to old CTFs to improve and new one to get good weight. If you make less than 1.5x factor it will be hard for old CTFs with solid backgroud to get more rating (e.g. see InsomniHack CTF runs for 3 years and have solid foundation of high-quality tasks; organizing team is very good, check last year DefCon Finals if unsure; it is ridiculous to cap its weight on the same level as Pwn2Win). If you make low start limit for new CTFs, they will not be able take good score forever, regardless of quality of tasks (look for example of some latest chinese CTFs, they are very good -- if you limit them to e.g. 5.0 rating on first year, max what they can get in e.g. 4 years is ~25 regardless what they will do).
To give top teams more voice in votes than others is not good idea. Top teams will likely to put most of the efforts to best available CTF in case of time clash, and may not pay attention to the tasks of others so not have enough info to make concise decision. It is extremely hard to play in all CTFs in the same time, I know because my team and I done it on previous weekend -- we were focused on VogaCTF, but played in parallel on Pwn2Win, Securinet and Mates CTF (some non-rated vietnamese CTF, with decent pwnables). There is a risk however that some non-top teams will play in mean quality CTFs and then try to upvote their rating to max (what is happening now on Pwn2Win), but I think this is OK -- when they realise that they are top teams too, they will join others on more descent CTFs. Rights to vote give advantage to young teams and will involve more people to CTF community and discussion, I think this is very important. The possible risks of equal voting seems minimal, it will increase average rating weight of ctfs in worst case.
What can be improved in current system -- the minor improvement is that orgs and associated teams should be excluded from voting for their own CTF. If they want to respond to players -- there is comments here, without voting. The more global improvement -- there is seems need of some authority, maybe some "CTFtime decision board", to ban CTFs, regardless of votes. Its a shame what is happening on Securinets right now, there are obvious cheating, manipulation of voting system via team names squatting, orgs seems are in collusion with cheating teams, and the cheating teams have upvoted it to the sky. This CTF should be removed from CTFtime, and next year ctfs from the same org team banned. The other potential cases for CTFtime bans are unethical behaviour of orgs (public personal insults of players, political or national hatred, discrimination based on nationality, race, religion), low quality of tasks (hypothetical example is a group of people can make 20 CTFs with 1 task base64.b64decode("QnJlYWtJbntmbGFnfQ") and there will be alot of votes to make this ctf 25.0+ rating weight).