SlideShare une entreprise Scribd logo
1  sur  35
Télécharger pour lire hors ligne
CTFs - Bringing back
                        more than sexy ;-)

                           Mark Hillick - @markofu

                                    KTF

                             Creator of HackEire



Thursday 9 June 2011
Usual stuff - disclaimer!

                       Own views - not representative of Citrix
                       Systems, IrissCert nor Phyllis and Ferb. I am
                       speaking here entirely of my own opinion,
                       which isn’t saying much but hey :)



                       No dolphins were hurt in the making of this
                       presentation!




Thursday 9 June 2011
Who are ya?
                       too many years working in IT

                       now @ vendor, used to be @ bank so I’m

                       Ex-@IrissCert handler, #IrissCon, @HackEire
                       @OwaspIreland

                       Previous Owasp Presentations

                           Cert Handler;

                           WAF Implementation;

                           Scareware via Web App Exploit
Thursday 9 June 2011
What’s this about?
                       Nope



                       Nor this guy




                       CTFs - history, now & the future

                       My experiences from building a CTF contest
                       from scratch with no $$$$$
Thursday 9 June 2011
So sorry!!!

                       I know I had ‘sexy’ in the title but




Thursday 9 June 2011
What’s a CTF? (1)
                              WAR-GAMES.......COMPETITION!




                             ATTACK, ATTACK, ATTACK!!!!
Thursday 9 June 2011
What’s a CTF? (2)


                       CTF contests.....serve as an educational
                       exercise to give participants experience in
                       securing a machine, as well as conducting
                       and reacting to the sort of attacks found in
                       the real world.


                       source: http://en.wikipedia.org/wiki/Capture_the_flag#Computer_security && I agree with this partly :)




Thursday 9 June 2011
CTF? Nah, I’m not.....




Thursday 9 June 2011
We can’t all be.......




                         Or.....




Thursday 9 June 2011
I’m not a hacker........




                Source:   http://img.wikinut.com/img/hzbaiyv.qfkbuofg/jpeg/0/The-comfort-circle.jpeg


Thursday 9 June 2011
Thursday 9 June 2011
Thursday 9 June 2011
but maybe try a CTF?




                        learn outside of the norm


Thursday 9 June 2011
But I’d like to attend
                         the conference!!
                       You going to remember every talk?




                       Didn’t think so......
Thursday 9 June 2011
1337
                       Test your l33t skillz



                       NSFW



                       Copious amounts of caffeine



                       Do cool stuff with old/new friends


Thursday 9 June 2011
Get a job?
                       Companies attempting to recruit off HackEire



                       HackEire => winners got postgrad funding &
                       several business cards :)



                       SANS/US Govt Challenges => JOBS GALORE



                       UK Cyberchallenge won by an ex-postman!

Thursday 9 June 2011
CTF Feedback 2010

                       I learnt a shitload today. I learnt more
                       about what I don’t know than what I do
                       know. Thanks!



                       Thanks very much! I had so much fun and
                       would be happy to pay 100 yoyos (pps) to
                       enter in future.



Thursday 9 June 2011
Why allow your staff to
                    compete in a CTF?
                       Learn about defensive & offensive security in
                       a safe environment! As opposed to........



                       You will learn & increase your awareness
                       because you will be surprised.....



                       $1000/day != good CTF competitor


Thursday 9 June 2011
So why run a CTF?


                       Make a name...



                       Spot talent



                       Help others & give back a little



Thursday 9 June 2011
Why did I do it?



                                   & @edskoudis



                       I wanted to learn & improve




Thursday 9 June 2011
Would I start it all now?

                       Probably not



                       > 250 hours last year



                       Project & People Management



                       Not everyone as passionate

Thursday 9 June 2011
What have I gained?
               I used to ‘not like’ my job very much & was bored. I
               wanted to play with tools I wouldn’t normally get to......




Thursday 9 June 2011
What often happens in a
                         CTF?
             In......




                        Out......




Thursday 9 June 2011
Why?




                       Is sadly all too infrequent.....

                       Assign Roles/Functions
Thursday 9 June 2011
2000 v 2011
                       NT4                 W7, MacOS10, Linux

                       Brick Phones        iOS, Android

                       $$$$$$$$            Credit Crunch

                       West                East

                       Kazaa, Napster      Twitter, FB, Skype...

                       Books, Newspapers   eBooks, Blogs, Web2.0

                       Man Utd :)          Man Utd :)

                       Q&A Interviews      Interactive, Hands-On

Thursday 9 June 2011
The future?
                       #ebooks            #Virtualisation

                       #Tablets/#Phones   #OpenSource




                       #CyberChallenges
                       Galore :)


Thursday 9 June 2011
Today?
 Competitions are increasingly recognised as an effective way
 of promoting innovation......prize industry has boomed,
 increasing more than 15-fold. The US Space and Security
 authorities have been supporting world leading competitions
 for many years. The Obama administration has re-authorised
 the America COMPETES act to support innovation and
 innovators. Is it time for Europe to catch up?


                   Source:   http://www.europeansecuritychallenge.com/




Thursday 9 June 2011
UK Cyber Challenge



                       Secure Network Design



                       Informed Defence



                       Investigate & Understand

Thursday 9 June 2011
CTFs in the future?



                       Part of Hands-On Interview



                       Looking for skillz => USA/SANS, UK, EU



                       Book Smart != Enough

Thursday 9 June 2011
It’d be nice if.....




               Goal: Keep improving.......

               Evolve, understand & innovate
Thursday 9 June 2011
2011 for HackEire?
                       Even better than last year & still free......

                         Huge improvements - more realistic

                         New web portal

                         Social Media

                         PCAP Analysis

                         More defensive controls

                         Want to introduce images to defend but
                         no time :(


Thursday 9 June 2011
Learn more about CTFs?




               Check out the DefCon, Sans, EthicalHacker.net (& more)
               websites

Thursday 9 June 2011
It’s all here.......




               Teamwork & Preparedness

               Constant Improvement
Thursday 9 June 2011
Q&A




Thursday 9 June 2011
All done, no more!

                       If you’re still awake.....




Thursday 9 June 2011

Contenu connexe

Similaire à CTF: Bringing back more than sexy!

Jeremiah Pliché's PBE 2011
Jeremiah Pliché's PBE 2011Jeremiah Pliché's PBE 2011
Jeremiah Pliché's PBE 2011jpliche12
 
Designing Science and Literacy Games for Nintendo DS
Designing Science and Literacy Games for Nintendo DSDesigning Science and Literacy Games for Nintendo DS
Designing Science and Literacy Games for Nintendo DSJohn Parris
 
Devopsdays Goteborg 2011 - State of the Union
Devopsdays Goteborg 2011 - State of the UnionDevopsdays Goteborg 2011 - State of the Union
Devopsdays Goteborg 2011 - State of the UnionJohn Willis
 
Kin Global Kellogg 2011 Chicago
Kin Global Kellogg 2011 ChicagoKin Global Kellogg 2011 Chicago
Kin Global Kellogg 2011 ChicagoCarlos Dominguez
 
Celebrate Texas Voices: Empowering Digital Witnesses
Celebrate Texas Voices: Empowering Digital WitnessesCelebrate Texas Voices: Empowering Digital Witnesses
Celebrate Texas Voices: Empowering Digital WitnessesWesley Fryer
 
Mo' Dimensions Mo' Problems
Mo' Dimensions Mo' ProblemsMo' Dimensions Mo' Problems
Mo' Dimensions Mo' ProblemsSeantron
 
Boston Globe: Responsive Web Design
Boston Globe: Responsive Web DesignBoston Globe: Responsive Web Design
Boston Globe: Responsive Web DesignThe Media Consortium
 
Netcultfunding frontlineclub-rendeiro
Netcultfunding frontlineclub-rendeiroNetcultfunding frontlineclub-rendeiro
Netcultfunding frontlineclub-rendeirobicyclemark
 
Opensource Authentication and Authorization
Opensource Authentication and AuthorizationOpensource Authentication and Authorization
Opensource Authentication and AuthorizationConFoo
 
From Apples to Augmented Cognition (Current and Future Trends in Mobile)
From Apples to Augmented Cognition (Current and Future Trends in Mobile)From Apples to Augmented Cognition (Current and Future Trends in Mobile)
From Apples to Augmented Cognition (Current and Future Trends in Mobile)Paul Golding
 
Rise of devops
Rise of devopsRise of devops
Rise of devopsatmosorg
 
Digital & Social Media Marketing
Digital & Social Media MarketingDigital & Social Media Marketing
Digital & Social Media MarketingFrank Dinolfo
 
Destroy the box
Destroy the boxDestroy the box
Destroy the boxjsokohl
 
Made by Many Sweden
Made by Many SwedenMade by Many Sweden
Made by Many SwedenMade by Many
 
YOU WILL REGRET THIS
YOU WILL REGRET THISYOU WILL REGRET THIS
YOU WILL REGRET THISMononcQc
 
Ready to Play: JavaScript / HTML5 Game Development
Ready to Play: JavaScript / HTML5 Game DevelopmentReady to Play: JavaScript / HTML5 Game Development
Ready to Play: JavaScript / HTML5 Game DevelopmentZachary Johnson
 

Similaire à CTF: Bringing back more than sexy! (20)

Jeremiah Pliché's PBE 2011
Jeremiah Pliché's PBE 2011Jeremiah Pliché's PBE 2011
Jeremiah Pliché's PBE 2011
 
When machines think
When machines thinkWhen machines think
When machines think
 
ITP / SED Day 4
ITP / SED Day 4ITP / SED Day 4
ITP / SED Day 4
 
Designing Science and Literacy Games for Nintendo DS
Designing Science and Literacy Games for Nintendo DSDesigning Science and Literacy Games for Nintendo DS
Designing Science and Literacy Games for Nintendo DS
 
Devopsdays Goteborg 2011 - State of the Union
Devopsdays Goteborg 2011 - State of the UnionDevopsdays Goteborg 2011 - State of the Union
Devopsdays Goteborg 2011 - State of the Union
 
Kin Global Kellogg 2011 Chicago
Kin Global Kellogg 2011 ChicagoKin Global Kellogg 2011 Chicago
Kin Global Kellogg 2011 Chicago
 
Celebrate Texas Voices: Empowering Digital Witnesses
Celebrate Texas Voices: Empowering Digital WitnessesCelebrate Texas Voices: Empowering Digital Witnesses
Celebrate Texas Voices: Empowering Digital Witnesses
 
Mo' Dimensions Mo' Problems
Mo' Dimensions Mo' ProblemsMo' Dimensions Mo' Problems
Mo' Dimensions Mo' Problems
 
Boston Globe: Responsive Web Design
Boston Globe: Responsive Web DesignBoston Globe: Responsive Web Design
Boston Globe: Responsive Web Design
 
Netcultfunding frontlineclub-rendeiro
Netcultfunding frontlineclub-rendeiroNetcultfunding frontlineclub-rendeiro
Netcultfunding frontlineclub-rendeiro
 
Opensource Authentication and Authorization
Opensource Authentication and AuthorizationOpensource Authentication and Authorization
Opensource Authentication and Authorization
 
From Apples to Augmented Cognition (Current and Future Trends in Mobile)
From Apples to Augmented Cognition (Current and Future Trends in Mobile)From Apples to Augmented Cognition (Current and Future Trends in Mobile)
From Apples to Augmented Cognition (Current and Future Trends in Mobile)
 
Rise of devops
Rise of devopsRise of devops
Rise of devops
 
Digital & Social Media Marketing
Digital & Social Media MarketingDigital & Social Media Marketing
Digital & Social Media Marketing
 
Destroy the box
Destroy the boxDestroy the box
Destroy the box
 
Made by Many Sweden
Made by Many SwedenMade by Many Sweden
Made by Many Sweden
 
State of Social & Informal Learning
State of Social & Informal LearningState of Social & Informal Learning
State of Social & Informal Learning
 
Godoggo
GodoggoGodoggo
Godoggo
 
YOU WILL REGRET THIS
YOU WILL REGRET THISYOU WILL REGRET THIS
YOU WILL REGRET THIS
 
Ready to Play: JavaScript / HTML5 Game Development
Ready to Play: JavaScript / HTML5 Game DevelopmentReady to Play: JavaScript / HTML5 Game Development
Ready to Play: JavaScript / HTML5 Game Development
 

Plus de Mark Hillick

Introduction to MongoDB
Introduction to MongoDBIntroduction to MongoDB
Introduction to MongoDBMark Hillick
 
Integrated Cache on Netscaler
Integrated Cache on NetscalerIntegrated Cache on Netscaler
Integrated Cache on NetscalerMark Hillick
 
Scareware - Irisscon 2009
Scareware - Irisscon 2009Scareware - Irisscon 2009
Scareware - Irisscon 2009Mark Hillick
 
Implementing a WAF
Implementing a WAFImplementing a WAF
Implementing a WAFMark Hillick
 
MongoDB - Who, What & Where!
MongoDB - Who, What & Where!MongoDB - Who, What & Where!
MongoDB - Who, What & Where!Mark Hillick
 

Plus de Mark Hillick (6)

Introduction to MongoDB
Introduction to MongoDBIntroduction to MongoDB
Introduction to MongoDB
 
HackEire 2009
HackEire 2009HackEire 2009
HackEire 2009
 
Integrated Cache on Netscaler
Integrated Cache on NetscalerIntegrated Cache on Netscaler
Integrated Cache on Netscaler
 
Scareware - Irisscon 2009
Scareware - Irisscon 2009Scareware - Irisscon 2009
Scareware - Irisscon 2009
 
Implementing a WAF
Implementing a WAFImplementing a WAF
Implementing a WAF
 
MongoDB - Who, What & Where!
MongoDB - Who, What & Where!MongoDB - Who, What & Where!
MongoDB - Who, What & Where!
 

Dernier

Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessPixlogix Infotech
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 

Dernier (20)

Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 

CTF: Bringing back more than sexy!

  • 1. CTFs - Bringing back more than sexy ;-) Mark Hillick - @markofu KTF Creator of HackEire Thursday 9 June 2011
  • 2. Usual stuff - disclaimer! Own views - not representative of Citrix Systems, IrissCert nor Phyllis and Ferb. I am speaking here entirely of my own opinion, which isn’t saying much but hey :) No dolphins were hurt in the making of this presentation! Thursday 9 June 2011
  • 3. Who are ya? too many years working in IT now @ vendor, used to be @ bank so I’m Ex-@IrissCert handler, #IrissCon, @HackEire @OwaspIreland Previous Owasp Presentations Cert Handler; WAF Implementation; Scareware via Web App Exploit Thursday 9 June 2011
  • 4. What’s this about? Nope Nor this guy CTFs - history, now & the future My experiences from building a CTF contest from scratch with no $$$$$ Thursday 9 June 2011
  • 5. So sorry!!! I know I had ‘sexy’ in the title but Thursday 9 June 2011
  • 6. What’s a CTF? (1) WAR-GAMES.......COMPETITION! ATTACK, ATTACK, ATTACK!!!! Thursday 9 June 2011
  • 7. What’s a CTF? (2) CTF contests.....serve as an educational exercise to give participants experience in securing a machine, as well as conducting and reacting to the sort of attacks found in the real world. source: http://en.wikipedia.org/wiki/Capture_the_flag#Computer_security && I agree with this partly :) Thursday 9 June 2011
  • 8. CTF? Nah, I’m not..... Thursday 9 June 2011
  • 9. We can’t all be....... Or..... Thursday 9 June 2011
  • 10. I’m not a hacker........ Source: http://img.wikinut.com/img/hzbaiyv.qfkbuofg/jpeg/0/The-comfort-circle.jpeg Thursday 9 June 2011
  • 13. but maybe try a CTF? learn outside of the norm Thursday 9 June 2011
  • 14. But I’d like to attend the conference!! You going to remember every talk? Didn’t think so...... Thursday 9 June 2011
  • 15. 1337 Test your l33t skillz NSFW Copious amounts of caffeine Do cool stuff with old/new friends Thursday 9 June 2011
  • 16. Get a job? Companies attempting to recruit off HackEire HackEire => winners got postgrad funding & several business cards :) SANS/US Govt Challenges => JOBS GALORE UK Cyberchallenge won by an ex-postman! Thursday 9 June 2011
  • 17. CTF Feedback 2010 I learnt a shitload today. I learnt more about what I don’t know than what I do know. Thanks! Thanks very much! I had so much fun and would be happy to pay 100 yoyos (pps) to enter in future. Thursday 9 June 2011
  • 18. Why allow your staff to compete in a CTF? Learn about defensive & offensive security in a safe environment! As opposed to........ You will learn & increase your awareness because you will be surprised..... $1000/day != good CTF competitor Thursday 9 June 2011
  • 19. So why run a CTF? Make a name... Spot talent Help others & give back a little Thursday 9 June 2011
  • 20. Why did I do it? & @edskoudis I wanted to learn & improve Thursday 9 June 2011
  • 21. Would I start it all now? Probably not > 250 hours last year Project & People Management Not everyone as passionate Thursday 9 June 2011
  • 22. What have I gained? I used to ‘not like’ my job very much & was bored. I wanted to play with tools I wouldn’t normally get to...... Thursday 9 June 2011
  • 23. What often happens in a CTF? In...... Out...... Thursday 9 June 2011
  • 24. Why? Is sadly all too infrequent..... Assign Roles/Functions Thursday 9 June 2011
  • 25. 2000 v 2011 NT4 W7, MacOS10, Linux Brick Phones iOS, Android $$$$$$$$ Credit Crunch West East Kazaa, Napster Twitter, FB, Skype... Books, Newspapers eBooks, Blogs, Web2.0 Man Utd :) Man Utd :) Q&A Interviews Interactive, Hands-On Thursday 9 June 2011
  • 26. The future? #ebooks #Virtualisation #Tablets/#Phones #OpenSource #CyberChallenges Galore :) Thursday 9 June 2011
  • 27. Today? Competitions are increasingly recognised as an effective way of promoting innovation......prize industry has boomed, increasing more than 15-fold. The US Space and Security authorities have been supporting world leading competitions for many years. The Obama administration has re-authorised the America COMPETES act to support innovation and innovators. Is it time for Europe to catch up? Source: http://www.europeansecuritychallenge.com/ Thursday 9 June 2011
  • 28. UK Cyber Challenge Secure Network Design Informed Defence Investigate & Understand Thursday 9 June 2011
  • 29. CTFs in the future? Part of Hands-On Interview Looking for skillz => USA/SANS, UK, EU Book Smart != Enough Thursday 9 June 2011
  • 30. It’d be nice if..... Goal: Keep improving....... Evolve, understand & innovate Thursday 9 June 2011
  • 31. 2011 for HackEire? Even better than last year & still free...... Huge improvements - more realistic New web portal Social Media PCAP Analysis More defensive controls Want to introduce images to defend but no time :( Thursday 9 June 2011
  • 32. Learn more about CTFs? Check out the DefCon, Sans, EthicalHacker.net (& more) websites Thursday 9 June 2011
  • 33. It’s all here....... Teamwork & Preparedness Constant Improvement Thursday 9 June 2011
  • 35. All done, no more! If you’re still awake..... Thursday 9 June 2011