PROTOCOLS
Rules
Last updated October 2026
Capture The Flag (CTF) Competition Guidelines.
01
Mechanics
Capture The Flag (Jeopardy-Style). The competition is a "Jeopardy-style" event where challenges are hosted on a centralized platform.
02
Eligibility
- Target Participants: Open to all students currently enrolled in the College of Computing Education (CCE).
- Team Composition: Each team must consist of exactly one (1) to four (4) members.
- All members of a team must be currently enrolled students of the CCE.
- Teams must register their team name and all members before the announced deadline to confirm their participation and facilitate smooth coordination.
03
Coverage of Topics
The competition will consist of various challenges categorized by domain:
- Web Exploitation: Identifying and exploiting vulnerabilities in web applications (e.g., SQLi, XSS, IDOR).
- Cryptography: Deciphering hidden messages using classical and modern cryptographic techniques.
- Forensics: Analyzing file metadata, memory dumps, network captures (PCAP), and deleted files.
- Open Source Intelligence (OSINT): Gathering information from public sources to track down specific data.
- General Computing & Logic: Basic networking, Linux commands, and algorithmic problem-solving.
- PWN (Binary Exploitation): Exploiting vulnerabilities in compiled programs, such as buffer overflows, format string vulnerabilities, and memory corruption, to gain control of program execution.
04
Preparation Phase
- Equipment: It is highly recommended that each of the four (4) team members bring their own laptop for maximum efficiency. However, sharing laptops within the team is allowed.
- Power Supply: Each team must bring their own extension cords to ensure all members' laptops are powered throughout the event.
- Software: Required tools (e.g., Kali Linux, Burp Suite Community, Wireshark, Python) should be preinstalled and up to date to help participants feel prepared and capable during the event.
- Tool Restriction: Only free, open-source, or community-edition tools are permitted. The use of premium or paid software (e.g., Burp Suite Professional) is strictly prohibited.
- AI/LLM Prohibition: The use of Artificial Intelligence (AI), Large Language Models (LLMs), or any AI-powered tools and extensions (e.g., ChatGPT, Claude, GitHub Copilot, Gemini) is strictly prohibited. All solutions must be generated by the participants' own technical skills and logic.
- Briefing: A mandatory technical briefing will be held 15 minutes before the timer starts.
CONNECTIVITY & HARDWARE RESTRICTIONS
- The use of headsets, earphones, or any wearable audio devices is strictly prohibited.
- The use of VPNs (Virtual Private Networks) or Private/Custom DNS settings is not allowed. All participants must use the provided event network configuration.
- Accessing cloud storage services (e.g., Google Drive, Dropbox, OneDrive) during the competition is prohibited.
- The use of communication platforms (e.g., Discord, Telegram, Messenger, Slack) for any purpose—internal or external—is strictly prohibited. Teams must communicate verbally within their designated area.
05
The Main Event
- Duration: The competition will run for a continuous block of four (4) hours.
- Access: All challenge categories are unlocked simultaneously at the start of the event.
- Flag Format: Standard format is CTC{string_here} unless otherwise specified in the challenge description.
06
Scoring System
The competition utilizes a Fixed Scoring system:
- Challenge Points: Each challenge is assigned a specific point value based on its individual complexity and technical requirements, as indicated on the CTF platform.
07
Answering Mechanics
- Flags must be submitted via the official CTF platform.
- Submissions are case-sensitive.
- Brute-force Protection: Five (5) consecutive incorrect guesses will trigger a 30-second submission lockout for that specific user/team.
08
Tie-Breaker Rule
If teams are tied on total points:
- Time-to-Solve: The team that reached the tied score first is ranked higher.
- Efficiency: If timestamps are identical, the team with the fewest incorrect submissions wins.
09
General Rules
- Independence: Teams must work strictly within their group of four. Communication with other teams or external parties is prohibited.
- Platform Integrity: Any attempt to attack the scoring server or infrastructure results in immediate disqualification.
- No Flag Sharing: Sharing flags or "leaking" hints to other teams will result in the removal of all involved parties.
- Internet Usage: External research for documentation and technical references is allowed, provided it does not violate the communication, AI, or cloud storage rules.
10
Disqualification
- Network Interference: Launching DoS/DDoS attacks against the network or other participants.
- Unauthorized Connectivity: Use of VPNs, unauthorized Private DNS, or proxies to bypass network restrictions.
- Forbidden Communication: Use of any messaging apps, social media, or communication platforms.
- AI Usage: Any confirmed use of AI/LLM tools or AI-powered code assistants.
- Equipment Violations: Use of headsets or earphones during the competition.
- Tool Misuse: Use of premium/paid versions of security tools to gain an unfair technical advantage.
- Misconduct: Harassment, cheating, or disrespect toward organizers or fellow participants.
- Late Submission: No flags will be accepted once the countdown timer reaches zero.
NOTEThe decision of the Lead Technical Judge and the CCE Event Committee is final and unappealable.