Fri, 10 May 2024, 23:59 UTC — Sun, 12 May 2024, 23:59 UTC
On-line
A San Diego CTF event.
Format: Jeopardy
Official URL: https://sdc.tf/
This event's future weight is subject of public voting!
Event organizersSan Diego CTF (SDCTF) is an annual Capture the Flag competition hosted by undergraduates at the University of California, San Diego (UCSD). Challenges vary across the disciplines of Open Source Intelligence, Cryptography, Web Hacking, Reverse Engineering, Binary Exploitation, Forensic Analysis, and others!
Signups are open at https://ctf.sdc.tf
More information can be found at https://sdc.tf
$1500 prize pool!
1st - $512
2nd - $256
3rd - $128
$150 in writeup prizes
We also have prizes for top UCSD Student teams in addition to the above general prizes:
1st - $256
2nd - $128
3rd - $64
214 teams total
Place | Team | CTF points | Rating points | |
---|---|---|---|---|
1 | thehackerscrew | 4123.000 | 49.340 | |
2 | World Wide Flags | 3781.000 | 34.959 | |
3 | Maple Bacon | 3517.000 | 29.267 | |
4 | Orange Orchard Orioles | 3207.000 | 25.357 | |
5 | b01lers | 2467.000 | 19.695 | |
6 | BYU Cyberia | 2219.000 | 17.389 | |
7 | KUICS | 2110.000 | 16.149 | |
8 | t1nyB0vineArmag3ddon | 1997.000 | 15.033 | |
9 | st0p_cyb3rbu11ying | 1957.000 | 14.451 | |
10 | S1uM4i | 1908.000 | 13.884 | |
11 | welovepython<3 | 1821.000 | 13.139 | |
12 | IrisSec | 1772.000 | 12.659 | |
13 | CyberAthletes | 1752.000 | 12.381 | |
14 | ResetSec | 1710.000 | 11.994 | |
15 | FlagMotori | 1643.000 | 11.476 | |
16 | CyberSpace | 1604.000 | 11.139 | |
17 | sahuang | 1574.000 | 10.869 | |
18 | Black0ut Bu5ters | 1346.000 | 9.424 | |
19 | ECSCTeamGreece | 1300.000 | 9.077 | |
20 | pre-quantum crypto | 1239.000 | 8.647 | |
21 | DarkNebulaTron | 1215.000 | 8.445 | |
22 | Stfu | 1190.000 | 8.242 | |
23 | CLPWN | 1116.000 | 7.750 | |
24 | Wani Hackase | 1072.000 | 7.442 | |
25 | wiredin_iitk | 1067.000 | 7.371 | |
26 | Dombu$ter$ | 1053.000 | 7.249 | |
27 | NYUSEC | 1045.000 | 7.166 | |
28 | reCAPTCHA the Flag | 1042.000 | 7.116 | |
29 | /dev/stp | 1034.000 | 7.038 | |
30 | IITBreachers | 1024.000 | 6.949 | |
31 | FiramexTeam | 994.000 | 6.743 | |
32 | Hellbound | 992.000 | 6.707 | |
33 | pwnagaukar | 988.000 | 6.659 | |
34 | PBR | UCLA | 952.000 | 6.422 | |
35 | KerKerYuan | 932.000 | 6.281 | |
36 | Me | 922.000 | 6.202 | |
37 | TheRomanXpl0it | 906.000 | 6.088 | |
38 | xls team | 887.000 | 5.957 | |
39 | A.Team | 869.000 | 5.832 | |
40 | krauq | 854.000 | 5.727 | |
41 | Random_Seed_43 | 850.000 | 5.688 | |
42 | Plaid Parliament of Pwning | 832.000 | 5.566 | |
43 | Tuning Machine | 820.000 | 5.480 | |
44 | Arya | 780.000 | 5.228 | |
45 | ʕ •ᴥ•ʔ | 780.000 | 5.215 | |
46 | Rubi di Cubrik | 748.000 | 5.012 | |
47 | SNI | 728.000 | 4.881 | |
48 | HLG | 728.000 | 4.870 | |
49 | IITK_Team2 | 725.000 | 4.842 | |
50 | Slt3brgr | 708.000 | 4.730 | |
51 | 000 | 700.000 | 4.672 | |
52 | DoNotTheCat | 696.000 | 4.639 | |
53 | seikatsukowareru | 680.000 | 4.534 | |
54 | signin | 586.000 | 3.963 | |
55 | TPC | 562.000 | 3.811 | |
56 | Concerned Capybaras | 559.000 | 3.785 | |
57 | Cipher Blitz | 553.000 | 3.742 | |
58 | 0xE0F | 550.000 | 3.716 | |
59 | x | 550.000 | 3.709 | |
60 | ARESx | 550.000 | 3.702 | |
61 | Singapore Students Merger | 550.000 | 3.695 | |
62 | pspspsps | 550.000 | 3.689 | |
63 | scampia2 | 532.000 | 3.575 | |
64 | InfoSecIITR | 525.000 | 3.527 | |
65 | dcua | 496.000 | 3.347 | |
66 | mimicats | 484.000 | 3.270 | |
67 | Blu3 T3am | 461.000 | 3.127 | |
68 | CyberStrike | 458.000 | 3.103 | |
69 | patches | 458.000 | 3.098 | |
70 | ꒰ᐢ. .ᐢ꒱₊˚⊹ | 458.000 | 3.093 | |
71 | little eep sea | 450.000 | 3.040 | |
72 | SirawitTH | 450.000 | 3.035 | |
73 | HackChurch | 450.000 | 3.031 | |
74 | JSoyke | 450.000 | 3.026 | |
75 | Vexation | 450.000 | 3.022 | |
76 | g00fy_ahh | 450.000 | 3.017 | |
77 | My4nM4r | 450.000 | 3.013 | |
78 | PwnSec | 450.000 | 3.009 | |
79 | singnoob | 434.000 | 2.909 | |
80 | Del0n1x | 425.000 | 2.851 | |
81 | IITK_Team1 | 425.000 | 2.848 | |
82 | ConfUSI | 425.000 | 2.844 | |
83 | TeamSerbia | 425.000 | 2.840 | |
84 | BankarKodFörGifflar | 425.000 | 2.837 | |
85 | JapaneseFrenchToast | 425.000 | 2.833 | |
86 | Hash Dogs | 425.000 | 2.830 | |
87 | 0rd3rs | 419.000 | 2.791 | |
88 | C3E3C6 | 416.000 | 2.769 | |
89 | BOMBOCLATTT | 350.000 | 2.371 | |
90 | FB | 350.000 | 2.368 | |
91 | Red Cadets | 350.000 | 2.365 | |
92 | UTY Undercover | 350.000 | 2.362 | |
93 | _a] | 350.000 | 2.359 | |
94 | jkck | 350.000 | 2.357 | |
95 | zomry1 | 350.000 | 2.354 | |
96 | BroncoSec | 350.000 | 2.351 | |
97 | .;,;. | 336.000 | 2.265 | |
98 | A.k.a.t.s.u.k.i | 325.000 | 2.196 | |
99 | physical-lab | 325.000 | 2.194 | |
100 | TCP1P | 325.000 | 2.191 | |
101 | 734m_N4M3_h3r3 | 325.000 | 2.189 | |
102 | tvt | 325.000 | 2.187 | |
103 | wezpwnz | 325.000 | 2.184 | |
104 | s3cure_sh3ll | 325.000 | 2.182 | |
105 | Hacklabor | 325.000 | 2.180 | |
106 | 4e5cc9bbfb87ddf | 325.000 | 2.177 | |
107 | spook | 325.000 | 2.175 | |
108 | SWT | 325.000 | 2.173 | |
109 | Cyberclowns | 325.000 | 2.171 | |
110 | spyd3rs | 312.000 | 2.091 | |
111 | HCS | 300.000 | 2.017 | |
112 | what | 270.000 | 1.836 | |
113 | __zEm0__ | 261.000 | 1.780 | |
114 | RoyalRoppers | 236.000 | 1.629 | |
115 | haxxers | 234.000 | 1.615 | |
116 | Frazza | 234.000 | 1.613 | |
117 | !Time_For_418 | 233.000 | 1.605 | |
118 | G5Victory | 225.000 | 1.555 | |
119 | ch3cke | 225.000 | 1.554 | |
120 | AP Linux BC | 225.000 | 1.552 | |
121 | slefforge | 225.000 | 1.550 | |
122 | noraneco | 225.000 | 1.549 | |
123 | 299 | 225.000 | 1.547 | |
124 | Waldbaur | 225.000 | 1.545 | |
126 | UofTCTF | 225.000 | 1.542 | |
127 | codacker | 225.000 | 1.541 | |
128 | uCC | 225.000 | 1.539 | |
129 | fufu | 225.000 | 1.538 | |
130 | Ng00m4lDhuhr | 225.000 | 1.536 | |
131 | ac1d | 225.000 | 1.535 | |
132 | HitMen | 225.000 | 1.533 | |
133 | taaaaaau | 225.000 | 1.532 | |
134 | 0bug | 225.000 | 1.530 | |
135 | f34rl3ss | 225.000 | 1.529 | |
136 | C4RR07 | 225.000 | 1.528 | |
137 | Club Penguin Reloaded | 225.000 | 1.526 | |
138 | HavocCTF | 212.000 | 1.447 | |
139 | YellowFrogs | 200.000 | 1.374 | |
140 | freshwater | 200.000 | 1.373 | |
141 | f4n_n3r0 | 200.000 | 1.372 | |
142 | RooterX | 200.000 | 1.370 | |
143 | lars | 200.000 | 1.369 | |
144 | CYBER & CHILL | 162.000 | 1.141 | |
145 | qqq | 162.000 | 1.139 | |
146 | noiceing | 136.000 | 0.983 | |
147 | OkOkOk | 136.000 | 0.982 | |
148 | mixy1 | 136.000 | 0.980 | |
149 | kanon | 130.000 | 0.943 | |
150 | WaterWipes | 125.000 | 0.912 | |
151 | Animal Farm | 125.000 | 0.911 | |
152 | kludge | 125.000 | 0.910 | |
153 | K1nz | 125.000 | 0.909 | |
154 | vyhatesgrass | 125.000 | 0.908 | |
155 | 3xh4ck5 | 125.000 | 0.907 | |
156 | Davidpb | 125.000 | 0.906 | |
157 | acdwas | 125.000 | 0.905 | |
158 | w4nd3r | 125.000 | 0.904 | |
159 | Kinabler | 125.000 | 0.903 | |
160 | tr00ps | 125.000 | 0.902 | |
161 | kupacup | 125.000 | 0.901 | |
162 | noobmannn | 125.000 | 0.900 | |
163 | N3WBEES | 125.000 | 0.899 | |
164 | LITF | 125.000 | 0.898 | |
165 | Rippers | 125.000 | 0.897 | |
166 | namdt | 125.000 | 0.897 | |
167 | ang | 125.000 | 0.896 | |
168 | albedugi | 125.000 | 0.895 | |
169 | N30Z30N | 100.000 | 0.744 | |
170 | ElectronStar | 100.000 | 0.743 | |
171 | aloevera | 100.000 | 0.743 | |
172 | taco | 100.000 | 0.742 | |
173 | Equivalent XCHG | 100.000 | 0.741 | |
174 | SII | 100.000 | 0.740 | |
175 | N.O.X.U.S | 100.000 | 0.739 | |
176 | BOLUSAIBO | 100.000 | 0.739 | |
177 | Cryptonite | 100.000 | 0.738 | |
178 | 0xT3H | 100.000 | 0.737 | |
179 | Martial_Law_Enforcer | 100.000 | 0.736 | |
180 | L4k$h | 100.000 | 0.735 | |
181 | B1naryREbublik | 100.000 | 0.735 | |
182 | Hor1zon | 100.000 | 0.734 | |
183 | whtvr | 100.000 | 0.733 | |
184 | Olympus OverWatch | 100.000 | 0.732 | |
185 | ctfrrteam | 100.000 | 0.732 | |
186 | SBF | 100.000 | 0.731 | |
187 | 寄寄 | 100.000 | 0.730 | |
188 | Gentowo | 100.000 | 0.730 | |
189 | 16j | 100.000 | 0.729 | |
190 | fuzziesfuzzin | 100.000 | 0.728 | |
191 | ssongk | 100.000 | 0.728 | |
192 | Moxifloxacin | 100.000 | 0.727 | |
193 | TEAM | 100.000 | 0.726 | |
194 | INDIA | 100.000 | 0.726 | |
195 | NMB unit 6l | 100.000 | 0.725 | |
196 | Blind_Virus | 100.000 | 0.724 | |
197 | followUheart | 100.000 | 0.724 | |
198 | EvilBunnyWrote | 100.000 | 0.723 | |
199 | Agents of Pwn | 100.000 | 0.722 | |
201 | H7Tex | 100.000 | 0.721 | |
202 | Do_I_Know_You? | 100.000 | 0.720 | |
203 | kafka | 100.000 | 0.720 | |
204 | Clubbing Baby Seals | 100.000 | 0.719 | |
205 | HawkSec | 100.000 | 0.719 | |
206 | meow | 100.000 | 0.718 | |
207 | Utaha | 100.000 | 0.718 | |
208 | definit | 100.000 | 0.717 | |
209 | NDMHacks | 100.000 | 0.716 | |
210 | Steelers_Suck | 100.000 | 0.716 | |
211 | Yesh | 100.000 | 0.715 | |
212 | puroclan | 100.000 | 0.715 | |
213 | stsei | 100.000 | 0.714 | |
214 | wh1te_r0s3s | 100.000 | 0.357 | |
215 | securityfirst22222 | 100.000 | 0.357 | |
216 | iaccep | 100.000 | 0.356 |
Not working. 404 error
discord invite invalid, plz update
how to register
Several squares on bad CTF bingo were achieved (admins were even keeping track of the bad CTF bingo squares!):
- Released hints for already-blooded challenges (some with several solves)
- Competition start was delayed by 2 hours because infra broke last minute and it took them forever to get back up. When I say "infra broke", you couldn't even access the CTF platform and sign up/create a team/etc just got a 404.
- They announced CTF would be delayed by 2 hours, but then started it 1.5 hours later
- Challenges were never playtested (and acknowledged by admins) because they were mostly created the day of the CTF.
- They used a custom fork of the GZCTF platform which has lots of pros but had lots of bugs (mostly introduced by their fork). Per-team instances would constantly shut down early, if a teammate opened the challenge description your instance would break, you'd often randomly see thousands of error notifications on the page. Teams were locked after starting the CTF (they're changing that I think).
- To connect to remote challenges, you had to install a rust proxy client which would make the challenge accessible on your own localhost. It is not the most intuitive thing to install, several people had issues initially, and I just don't like the idea of having to use a proxy client to connect to challenges.
- Each challenge had a difficulty assigned to it which was very much off. Normally this wouldn't be a big deal, except the decay rate was based on difficulty. This led to some easy challenges being worth significantly more than harder challenges with a lot less solves.
- While some challenges were good, there were also guessy and painful challenges. A rev challenge was simply a cipher (you copy the "ciphertext" into dcode.fr's cipher detection and immediately got the flag), the only forensics challenges were guessy wav2png conversions using a custom scheme that you were just supposed to guess (otherwise it made it EXTREMELY noisy and very difficult to accurately make out characters).
Overall, I think the CTF would have been much more enjoyable if they:
1) Had planned for the CTF more than a day in advance, playtesting challenges + infrastructure, and
2) Changed some parts of their (custom fork of the) GZCTF platform so it wasn't buggy and didn't require a proxy.