Procurement Sciences · October is Cybersecurity Month

Capture the Flag

It's a game. We hid secret codes inside fake emails, fake contracts, a fake code repo, and one truly terrible login page. You dig them out, paste them in, and get points. That's the whole thing. No security background needed. Being nosy helps.

I'm in Show me the challenges Who's winning
All of OctoberPlay whenever. Lunch, a slow Friday, 2am, we don't judge.
Work comes first, this is a side quest.
SoloEveryone plays for themselves. Trash talk encouraged.
PrizesReal ones. Details in the kickoff email.

Wait, what's a CTF?

Capture the Flag is how security people practice. Someone takes a real-world screwup, like a password that was way too easy or a document that leaked more than it should have, and builds a puzzle around it. You poke at it until you find the hidden string (the "flag") and submit it. Ours look like PSCI{something_like_this}. If you can open a text file and you're willing to Google things, you're qualified. Most of these don't need any code at all.

Why are we doing this?

Because the annual "don't click suspicious links" training doesn't stick, and everyone knows it. What sticks is the moment you personally crack a vendor's "encrypted" API key in ten seconds and realize they thought it was safe to email around. Every challenge here is based on something that has actually burned a company like ours. Our customers trust us with their bid data. We'd like to keep it that way, and finding the holes yourself beats a slideshow every time.

1Sign up

Use your @procurementsciences.com email. Pick any name for the scoreboard. Yes, it can be a pun.

2Pick a challenge

Each one gives you a file and a short story. Somewhere in there is a flag. Start with the Welcome one, it takes eight seconds and gets you on the board.

3Paste the flag

Points appear. Most challenges pay more to early solvers and less as the crowd catches up, so don't sit on one you've already cracked.

Everything here is made up. The emails, the documents, the repo, the "leaked" passwords. No real customer, employee, or system is involved. And please, do not type a real password into anything you download from this site. That is, in fact, the lesson of one of the challenges.

House rules

Don't share flagsSolving next to a coworker is fine. Dropping flags in Slack is not. The scoreboard timestamps make it very obvious, and we will make fun of you.
Only hack thisThis site and the files it hands you are the whole target. Nothing else at PSci is in scope. No, not even "just checking" the printer.
Hints are for usingThey cost a few points. Staring at a file for an hour costs you an hour. Take the hint.
Something broken?Tell us in #ctf. Reporting a busted challenge gets you a shout-out and probably some points.
PrizesTop three at the end of the month, plus a random draw from everyone with three or more solves. So finishing three is worth your time even if you're not going to catch first place.