crowdsecurity / ambassadors

Content and collaboration with CrowdSec ambassadors
MIT License
3 stars 0 forks source link

CTF : automation to deliver a flag #10

Open BillyMyIT opened 2 weeks ago

BillyMyIT commented 2 weeks ago

In CTF, normally, we need to find a flag and put it on the platform webinterface like CTFd.

I would like to have help to find a solution.

This idea comes from the alpaca odyssey as well as the ctf that I had set up. The only missing element for this ctf and that I wanted help with is to be able to use a scoring platform like CTFd and allow a flag to be given as soon as the attack is correctly blocked (and not blocked with a command directly blocking the ip or by the firewall, but to check the scenario, check that the parameters are correct and adapted) etc...

Example : Be sure to have a proper scenario to block a slow brute force (that don't match the slow brute force attack). We need to find a solution to check that parameters are the minimum and not so not appropriate that everything can be catch up by the rules.

jonatoni commented 2 weeks ago

@BillyMyIT would you like to add this idea to the event with Cyber Info "12 days of Christmas"?

BillyMyIT commented 1 week ago

@jonatoni It can be for 12 days of Christmas and any ctf based on crowdsec