CTF Radiooo

CTF Radiooo

By adamd and ZardusTechnology
Download on the App Store

CTF Radiooo episodes

  • 007 - DC 28 CTF Winners: A*0*E with Tianyi, Gengming, Hui Shin, and silver

    Youtube Video of podcast

    Shownotes and Links

    In this extra-special episode of CTF Radiooo, adamd and Zardus host the WINNERS of DC 28 CTF: A*0*E.

    From A*0*E we’re joined by Captain Gengming aka dmxcsnsbh, Vice-Captain Hui Shin aka septyem, Founder Tianyi aka Jackyxty, and DevOps silver!

    We discuss how everyone got into CTFs, the history of A*0*E (the short version is A*0*E = EEE ∪ AAA ∪ 0ops ∪ ******), DC 28 CTF, DC 26 madness (on adamd and Zardus’ side, including social engineering a parking spot), and how to succeed at CTFs.

    Silver’s amazing diagram of their networking setup:

    +---------------------------------------------------------------------------+
    | |
    | >Other players in our team< |
    | |
    +-----------------+----------------------------------+----------------------+
    | |
    | |
    | OpenVPN | OpenVPN
    | | The `dc28-redir-controller`
    +--------+------+ +------+--------+ is deployed here
    | | | |
    | VPN Endpoint | | VPN Endpoint | |
    | for CHN users | | for USA users | |
    | | | | v
    +-------+-------+ +-------+-------+
    | | +---------------------------+ +--------------------+
    | bandwidth and ACL limited! | | | | |
    | save some money ;) | | Jumpbox, config copied +-----+ OOO's WG endpoint |
    | | | +-----+ from OOO's machine | | |
    | | | | | | | |
    +---------------------------------+ | v | | +---------------------------+ +--------------------+
    | | +-----+-----+ +-----+-----+ |
    | CPU-intensive applications | | | QoS Promised | | |
    | since EPYC servers are only +------+ Gateway +------------------------+ Gateway +------+ +------------------------------------+
    | available in CHN available zone | | China | MPLS VPN? not sure. | U.S West | | |
    | | | | 110-130ms, <0.1% loss | +------------+ Latency-aware programs |
    +---------------------------------+ +-----------+ +-----------+ | & |
    | Traffic-heavy programs (like pcap) |
    | Reduce costs under the ocean |
    | |
    +------------------------------------+
    - All connections are using WireGuard unless specified.
    - Netdata is installed on all machines so we can do remote telemetry
    and receive alarms.
    Links
    • A*0*E redirection controller
    • 0CTF/TCTF finals (which was last month, sorry the recording happened before)
    • 1 hr 54 min
    • 006 - Google CTF 2020 with sirdarckcat

      Youtube Video of podcast

      Shownotes and Links

      In this episode of CTF Radiooo adamd and Zardus host a special guest: sirdarckcat a.k.a. Eduardo Vela to discuss Google CTF 2020.

      We discuss how sirdarckcat got into CTFs, the history of Google CTF, how Google CTF 2020 went, what happens behind the scenes of hosting a CTF, how to respond to issues in a CTF, and the need for organizers to share information.

      Links
      • CSAW CTF
      • ESPR (Eat Sleep pwn Repeat)
      • iCTF
      • WCTF: teams write challenges
      • Google CTF 2020 Challenge Source
      • pwnyracing by our friend ZetaTwo
      • c2w2m2, one of the fastest hackers in DC 27 CTF quals speedrun. palli palli!
      • 🍊’s CTF challenges (we are all fans)
      • Google barges
      • All the little things walkthough pt. 1 and pt. 2 by our friend LiveOverflow
      • A CTF Organizer’s nightmare: flag leaks
      • CTF Organizers’ Slack created by our friend psifertex
      • sirdarckcat would like you to save the whales
      • 54 min
      • 005 - ropshipai with anton00b and Jay, Corwin, and Matt from PPP

        Youtube Video of podcast

        In this episode of CTF Radiooo, adamd and Zardus host a special guest: Antonio from the Order of the Overflow to talk about his DC 28 CTF challenge ropshipai!

        In addition, Jay, Corwin, and Matt from PPP join to talk about ropshipai and ropship from a player’s perspective!

        Together adamd, Zardus, Antonio, Jay, Corwin, and Matt discuss how they got into CTFs, Return-Oriented Programming, the ropships, DC 28 CTF, and how PPP prepares and plays in DC 28 CTF.

        Shownotes and Links
        • ropship source
        • ropshipai source
        • Two hours and 42 minutes of all ropshipai rounds
        • Hack this site (mentioned by Jay)
        • Jay’s homepage, cite his papers!
        • Garbage Truck from plaidCTF (written by Corwin)
        • PlaidCTF
        • PicoCTF
        • adamd’s blog post on how to get ready for PicoCTF
        • 1 hr 27 min
        • 004 - Founding of OOO and gameboooy DEF CON 28 CTF Challenge w/ Guest Jeff

          Youtube Video of podcast

          Shownotes and Links

          In this episode of CTF Radiooo, adamd and Zardus host a special guest: Jeff! Together adamd, Zardus, and Jeff founded the Order of the Overflow, and they tell the story here.

          Next, we chat about the DEF CON 28 CTF challenge gameboooy, which Jeff wrote.

          gameboooy is a gameboy emulator with multiple modules, each of which operate one aspect of the emulator.
          Rather than patch the emulator itself, the patch strategy is to write a firewall that inspects (and can block) the communication between each of the modules.

          We also take an honest look at the problems of gameboooy (so that everyone can learn from mistakes), and discuss the challenges of organizing a CTF and writing challenges.

          Links
          • OOO Philosophy, which is 90% of the proposal
          • gameboooy source
          • telooogram writeup
          • What we sent players before DC 27 CTF
          • dooom source
          • CTFd
          • 58 min
          • 003 - nooode DEF CON 28 CTF Challenge w/ Guest kaptain

            Youtube Video of podcast

            Shownotes and Links

            In this episode of CTF Radiooo adamd and Zardus host their first guest: kaptain a.k.a. Alexandros Kapravelos to discuss the DEF CON 28 CTF challenge nooode.

            We discuss a bit about OOO, how kaptain got into CTFs, the design inspiration of nooode, CTF challenge philosophy, attack-defense private instances (and why they are necessary), stealth ports, how nooode went in DEF CON CTF, and lessons learned.

            Links
            • Play nooode on archive.ooo
            • Check out the source of nooode on github
            • kaptain’s work on reducing Node.js attack surface: Mininode
            • Prototype pollution
            • 46 min
            • 002 - How to get into Capture the Flag (CTF)?

              Unfortunately, Zardus’ machine blew up after the first 16 minutes of

              recording (LINUX!), so we lost his good audio, and have to go with
              lower quality audio for the first 16 minutes. Sorry!

              Youtube Video of podcast

              Shownotes and Links

              In this episode of CTF Radiooo, adamd and Zardus answer the question that we get frequently: How to get into Capture the Flag (CTF) cybersecurity competitions?

              We tell our “orgin story” about how we both got into CTFs at UCSB and with Shellphish (Zardus’ is particularly great).

              We also point people to resources where they can get into CTFs.

              The best way into CTFs is to start playing, so do it!

              Links to Explore CTFs:
              • The art of sniffing: dsniff
              • When are CTFs? CTF Time
              • OpenToAll CTF team that is, as the name says, open to all!
              • Proper preparation prevents poor performance: wargames to practice
              • OverTheWire, one of our favorite sets of wargames
              • Hack on some binaries with pwnable.kr, by our friend daehee
              • Go from a white-belt to a yellow-bet on exploitation with pwn.college, by our very own Zardus and kanak
              • 54 min
              • 001 - What is Capture the Flag (CTF)?

                Youtube Video of podcast

                Shownotes and Links

                In this initial episode of CTF Radiooo, adamd and Zardus answer the question: What is Capture the Flag (CTF)?

                And no, we’re not talking about a physical in-person CTF, or a first-person shooter CTF (ala Quake or Unreal).

                We’re talking about the cybersecurity hacking competitions known as Capture the Flag, where hackers from around the world compete to solve security challenges and develop their security skills.

                Interesting Links to Explore:
                • Capture The Flag (Wikipedia)
                • What is Capture the Flag (from CTF Time)
                • CTFd’s What is CTF
                • Why CTFs are Awesome and Why CTFs are Terrible, both from our friend LiveOverflow
                • DEF CON, the birthplace of DEF CON CTF
                • 39 min

                About CTF Radiooo

                From the publisher's feed

                Capture The Flag Radiooo is a cybersecurity podcast focused on CTF competitions. Hosted by adamd and Zardus, founding members of the Order of the Overflow, the organizers of DEF CON CTF from…