Blog from October, 2012

FAQ page created

We now have an FAQ page that contains some logistical details about the CTF.  More information forthcoming - please feel free to get in touch with us if you have specific questions (see Contact Us page).

Code for binary services lecture posted

Code for the binary services lecture has been posted on Lecture Slides page.

A final reminder - this evening is the 4th and final lecture in the MIT/LL CTF seminar series, focusing on defense and monitoring techniques for Linux servers.  Given last year's experience, these concepts and tools will prove to be very useful.

Defending and Monitoring LAMP Servers - Wed, 7-9pm, 32-141

Please join us for the 4th (and final!) lecture in the MIT/LL seminar series.  This lecture will cover protection and monitoring mechanisms for Linux systems, including how to sandbox code, understand what processes are doing, monitor network connections, etc.  You'll need all this (and more!) to defend your server during the competition.  This lecture will be co-presented by Prof. Nickolai Zeldovich and your's truly.

In addition, we'll be making announcements about changes to scoring algorithm, CTF schedule and logistics, and a couple other things that you may be interested in.  So if you can make this seminar, please do!  Otherwise, we'll see you on Nov 3rd. 

Binary service lecture slides posted

Lecture slides for the binary service exploitation and patching seminar have been posted on the Lecture Slides page for those who could not make it in person.

Binary Service Reversing and Patching - Wed, 7-9pm, 32-141

The third in our seminar series will cover binary service reversing and patching.  We will present some advice on how to discover vulnerabilities, how to exploit these vulnerabilities and how to defend these services.

Prof. Wil Robertson (Northeastern University) and Joe Werther (MIT Lincoln Laboratory) will be co-presenting this seminar.

Web Application Vulnerabilities - Wed, 7-9pm, 32-141

The second in our seminar series will cover Web application basics (HTTP, Cookies, HTML, JavaScript, etc) and server-side web-related issues (SQL Injection, XSS, XSRF, etc).  We will present some advice on how to discover vulnerabilities in applications built on these technologies, how to exploit these vulnerabilities and how to defend web applications.

Prof. Engin Kirda (Northeastern University) and Joe Werther (MIT Lincoln Laboratory) will be co-presenting this seminar. 

VM information posted

CTF VM image is now available for download (in both VMX and OVA formats).  Instructions on how to get it and set things up are available at VM Information page.

Intro to MITLL CTF - Wed, 7-9pm, 32-141

Team registration is now officially closed.  We have 20+ teams playing in this CTF - head on over to Team Information page and check out your competition!  If you've requested to be put on a team and haven't heard from us yet, don't dispair - we're working our way through the survey responses and will make team assignments before the 1st CTF seminar on Wednesday.

Which brings me to the next topic - our first seminar introducing you to the 2012 MIT/LL CTF will be this Wednesday, 7-9pm at MIT Stata center (the funky building at 32 Vassar St, you can't miss it) in room 32-141.  This forum is the best opportunity to learn about game setup, scoring, logistics, etc and get your questions answered (we've allocated plenty of time for Q&A).

We will also have for you (barring any last minute technical glitches) a copy of the competition VM that you can take home and start exploring, fortifying, etc.  So if you'd like help getting setup, bring your laptop with VMWare installed.