Capture the Flag
It's a game. We hid secret codes inside fake emails, fake contracts, a fake code repo, and one truly terrible login page. You dig them out, paste them in, and get points. That's the whole thing. No security background needed. Being nosy helps.
I'm in Show me the challenges Who's winningWait, what's a CTF?
Capture the Flag is how security people practice. Someone takes a real-world screwup, like a password that was way too easy or a document that leaked more than it should have, and builds a puzzle around it. You poke at it until you find the hidden string (the "flag") and submit it. Ours look like PSCI{something_like_this}. If you can open a text file and you're willing to Google things, you're qualified. Most of these don't need any code at all.
Why are we doing this?
Because the annual "don't click suspicious links" training doesn't stick, and everyone knows it. What sticks is the moment you personally crack a vendor's "encrypted" API key in ten seconds and realize they thought it was safe to email around. Every challenge here is based on something that has actually burned a company like ours. Our customers trust us with their bid data. We'd like to keep it that way, and finding the holes yourself beats a slideshow every time.
1Sign up
Use your @procurementsciences.com email. Pick any name for the scoreboard. Yes, it can be a pun.
2Pick a challenge
Each one gives you a file and a short story. Somewhere in there is a flag. Start with the Welcome one, it takes eight seconds and gets you on the board.
3Paste the flag
Points appear. Most challenges pay more to early solvers and less as the crowd catches up, so don't sit on one you've already cracked.
House rules
| Don't share flags | Solving next to a coworker is fine. Dropping flags in Slack is not. The scoreboard timestamps make it very obvious, and we will make fun of you. |
| Only hack this | This site and the files it hands you are the whole target. Nothing else at PSci is in scope. No, not even "just checking" the printer. |
| Hints are for using | They cost a few points. Staring at a file for an hour costs you an hour. Take the hint. |
| Something broken? | Tell us in #ctf. Reporting a busted challenge gets you a shout-out and probably some points. |
| Prizes | Top three at the end of the month, plus a random draw from everyone with three or more solves. So finishing three is worth your time even if you're not going to catch first place. |