#general
1 messages ยท Page 7 of 1

๐ฎ
๐ฎ
demote rob for leeks
:(
flag oracle
๐จ
dice{ie
dice{b
dice{๐ ฑ๏ธ
poortho forensics as a service pwn
may or may not be fake leeks

._.


leak!
One of my flags start with dice{
o same
now we know what the flag isnt
ends with }
That's too much of a leek
inb4 the flags dont start with dice{
can we dq hk
dice{[a-z0-9_]*}
leaked flag format
do we have flag format
.*
... isn't regex smh
we have a regex but i think regex flag formats are confusing
at least give us it
for beginners at least

regex pwn
o true
u can check if flag is suitable in online tools
isnt this ctf gonna be confusing for beginners anyways?
this is good
lol
wtf
we're writing beginner challs rn lmao

so there will be some beginner stuff
wow last minute smh

thats a fat regex
wat?
tfw hk haxored the infra already
hk too stronk
๐ฆ
ono
โญ
@meager wadi ๐
perfect infrastructure
@arctic gyro ayo they're not supposed to know
oops


don't mess it up lol
Me when someone ask am i good with computers
@neon matrix Thats funny yes.... say yes
(funny ? 'yes' : 'no')
yes
I'm just a funny gangsta ig
they don't call me Mr dolphin for no reason
I earned it from making dolphins laugh
!flag
๐
are there golf challs?
i'm ready 
๐ค
๐ค
you'll need to golf the shellcoding
โญ perfect organization
gotta prepare my ASSINT capabilities
I'm a pushover but my challenges are easy


maybe I should just preemptively block jyu
uwu
๐ฆ
ginkoid threatened me ๐

he has my parents
he
hasis my parents
Hello, is it starting February 6 00:00 UTC or February 6 00:00 UTC+1 ?
i should register
Okay, because in the rules, it's written February 6 00:00 UTC
don't
I need a higher chance of winning WWW
0 UTC is what the timer is counting down to
i was gonna play alone but then i talked some friends into playing
so i gotta reregister
wut just give them your team token
you can change both your name and email
oh well, too late
I will have to ban you now as making multiple teams is strictly against the rules
if you don't use a team
having multiple teams is fine
if you have points on two teams
that is
ok
very e-legal
how about i legal you
where's all the fun guessing challenges
I wanna bang my head against a wall guessing cookie names and private keys
to find them
ah yeah
imagine actually doing the challenges
just like real pentesting is guess the root password
it isn't for me?
stop using netscape
looks the same in ff? https://ginkoid.is-inside.me/S2HCpRHL.png
wait wtmoo
it does look a little strange in the screenshot
idk
the text is smaller
every 10 minutes, that's pretty often
i think it fucks up on my monitor bc the resolution is gamer mode
yea probably
Which monitor? my gamer mode recently had weird problems too
not actually gamer mode ๐ข it's just 1440p
Oh, mine did some weird things with images displayed in discord
Subpixel rendering is a way to increase the apparent resolution of a computer's liquid crystal display (LCD) or organic light-emitting diode (OLED) display by rendering pixels to take into account the screen type's physical properties. It takes advantage of the fact that each pixel on a color LCD is actually composed of individual red, green, an...
@harsh abyss prize for first blood on sanity check?
not that i know of
my love and affection, if that means anything
let's goooooooo
:0
Wait is it started?
gonna tell this to rak
starts in 1 hour
timezones smh my head
what?
Coolioso, CactusCon should be doneby then
omg
the ultimate prize
Would not recommend two ctfs in 24 hours
oof, this sanity check is so hard
๐ โ
if the countdown on the homepage doesn't say 58 mins left then you found a bug 
Sin.
pepega
omg it's 00:00 in my country
Hey guys ! Does anyone know what are those "divisions" about ?
brownie come back
rctf feature that we're not using
just register under "open"

I don't really have a choice ๐
hey drakon
indeed you don't 
hey brownie <3
thanks @uneven pendant
lol
monka
๐
what happens if you go to time.is
rctf broken?
why
I would think your browser has timezones messed up
to convert start time to your timezone
evidently it's not working
nop i think it's my country time

does https://time.is say your time is correct or no
okey wait
look
anyone know if the challenges are gonna be made open source post CTF or are they gonna be reused or smthn
are you in UTC+1
i will open source mine at least
i think
same, I assume most will be released
nice, do you need any challenges btw? i make a lot and i have some unused dockerised challanges that you might wanna use
dont even have to give me credit just tyhuoght maybe someone could put em to use
dw if not lmao
||
wtf dunfed
yea sure, mind if i DM you some stuff later? any categories you need more in?
that's right dunfed
monka
up to each challenge author, but most will be
๐
epic
anyways hope everyone enjoys it! :)
enjoyment and ctf do not belong in the same sentence
lmao
hhhhhhhhh awdi mabghytch nb9a talsba7
how do you know I didn't already 
what do you think the server icon changes were about

maybe good steg challenge, question mark?
HHHH same
ez
soon.
You signed up for this?
26 minutes โค๏ธ
I canโt wait to blood the sanity check
i can't wait to blood the survey
i hope you enjoy my stego challenge
Our teamโs only two talents
lmao just an image literally with the flag on it
Good one 
omg lh
neat

itโs an honor
are there any good binexp ones

or re
no stego is more realistic than binexp
I've heard guessing is the most realistic category
@amber wind did you ever end up adding that forenshits chall
bold of you to assume this ctf isn't all guess
In before the bloody server crashes from pure autism
i don't think autism crashes servers
where the discord flag at
i could be wrong though
#message-log
Autism crashed the stockmarket, I think we can say it crashes servers
if infra goes down at start of comp, i want a full refund
autism is powerful
don't underestimate its strength
if you want realistic challs we can make a few wordlist challs 
better have per user instances >:(
flashback to csaw
seesaw
wait no i want a more realistic chall
lmao
make us write a detailed report of some vulnerability we wrote
then have us found not eligible
because of a minor formatting error
pepega
and then get banned from the bbp
"duplicate, not elligible"
then you ask for a link to the original report and it's a completely different vuln
or they say that they fixed the dupe but the bug is still reproducible
or when they say it's out of scope but it's not out of scope at all
I can bet anyone $1000000 that nobody can solve a single challenge written by me
"im sorry when we said that *.doman.com was the scope, we meant the literal * character, not all subdomains"
sounds like they're bad challenges then ๐
@gentle island does this extend retroactively
i think i might have solved one of your tjctf challenges
where's my $1000000
no only dice
sanity check :D
noo!!
cuz I didn't write any ๐
damn :((

Are there any difficult questions ๐
I'm going to find a challenge you wrote 2 years ago and make you pay
so are you just here for the memes
pretty much
you should write one rn so i can get money ๐
awesome
so where we dropping
I mean whats the link
oh I was meant to read it cool
and half of the organizers status
Don't force us admin ๐
where's rsactftool
!remind me 10m grab some pepsi
โ Alright, I'll ping you here for that in 10.0 m
!r m 10m grab pepsi
stfu
omg pepsipu
pepsi >
http://diceprectf.meatctf.com/ 13 minutes left go win the prectf
!remind me 17m blood sanity and win brownie's affection
โ Alright, I'll DM you for that in 17.0 m
radnor also pog

@rain violet what flavour
fake
bebsi

oh.
tied
ono.

npo
I have a feeling there's a 800pts challenge 
no
๐ฆ
all the challenges are in intervals such that a score and challenges solved is determinstic
cause the platform has no way for me to see who solved what challenges
cause it's not a ctf platform
doesn't seem like cutting-edge
its some random half baked unfinished thing
Reminder delivery:
To: @glossy marsh
Scheduled: Thu Feb 4 23:47:04 2021 (1 day ago)
Jump Link: #general message
Reminder:```
wakey wakey dicectf is about to start
did i ask
go to sleep
will go to bed
give us your challs jambot 
no 
summer fruits or bust
aldi restocked today
but
we arent accepting external challenges
willwam speaks for me

there was none in our local
not external if you remove credit


lmao
you should use them to run unofficial unconsentual prectfs for random ctfs
right gl guys im getting ready
yea idc they are just going to waste. allthough im kinda building my own unique ctf platform so i could save em for that
perfect infrastructure โญ
jamctf :o
xd
never
sorry for leek
if you want an actual date expect like 6 months or something idk
is this going to be "the best ctf of 2021 yet" ?
prolly not lol
no swearing in this christian server

Discord Flag:
announcement when ctf didn't start yet?
Reminder delivery:
To: @glossy marsh
Scheduled: Fri Feb 5 23:41:33 2021 (0 hours, 10 minutes ago)
Jump Link: #general message
Reminder:```
grab some pepsi
!flag
for every minute of downtime, admins have to give me 1 minute of root on any box i want
PogO
oh right that too
bargebot is so cool ๐
ginkoid is so cool ๐
I'll choose scoreboard box
Was it delayed?
bargebot is actually ginkoid
waffle is so cool ๐
ok but u only get root on my htpc
only one i can access
no
Epic
htpc?
@authors what are the flags
based
@amber wind we need UHC to come back
who's the admin for the discord flag
@tawny wigeon
omg UHC
?
prectf ended, top 20
youre the admin for discord
confused is there a hidden channel or smthn
tf
modded client time ๐
good work for ppl who played
@clear blade ur scoreboard is weird
also who played as redpwn?
writeup for discord?
for all i know the "redpwn" team isnt even from redpwn
redpwn(hub) 
but i wanna know who defaced the bash http server challenge cause i wanna know how they got it to run longer commands
cause its definitely possible i just dont know how
${IFS}?
hello all
those get filtered
if you fb sanity you get 300000 points
!remind
๐ help 1/1 ๐```diff
![remind|r|reminder|reminders]
Base command for reminders
Sub commands:
me Schedule to be reminded about something
snooze Reschedule your most recent reminder for later
You can get more info about a command (params and subcommands) by using '!help [remind|r|reminder|reminders] <subcommand>'
Commands followed by โช have subcommands.```
oh cool
!remind me
๐ซ You are missing a required command argument: duration
๐ง Command usage: !remind [me|add|m|a] <duration> <reminder>
!flag
whoever fbs sanity, dm me and i will give prize
๐
omg tux ๐ง
๐
!remind me 10s `@everyone pepega
โ Alright, I'll ping you here for that in 10.0 s
uh
tux gives 1% of his brain
oh no

oh no
Reminder delivery:
To: @sage musk
Scheduled: Fri Feb 5 23:57:37 2021 (0 hours, 0 minutes ago)
Jump Link: #general message
Reminder:```
ห@โeveryone pepega
lmao
pog
!remind me 10s ```@everyone pepega
โ Alright, I'll ping you here for that in 10.0 s
you needed 3 backticks
pepega
@neon matrix ill do it just for u
Reminder delivery:
To: @sage musk
Scheduled: Fri Feb 5 23:57:58 2021 (0 hours, 0 minutes ago)
Jump Link: #general message
Reminder:```
หหห@โeveryone pepega
wao
Nice try tho
moment
!remind me 10s `@everyone pepega
even if you got barge to send it, it wouldn't ping anyone
โ Alright, I'll DM you for that in 10.0 s
*bargรฉ
!remind me 10s css
test
โ Alright, I'll ping you here for that in 10.0 s
Reminder delivery:
To: @spring cloud
Scheduled: Fri Feb 5 23:58:38 2021 (0 hours, 0 minutes ago)
Jump Link: #general message
Reminder:```
css
test
move over sql injection, here comes ping injection
Reminder delivery:
To: @uneven pendant
Scheduled: Fri Feb 5 17:59:01 2021 (6 hours, 0 minutes ago)
Jump Link: #general message
Reminder:```
T- 1 minute!
wow
hype
50 seconds
wow @uneven pendant a whole second off
you guys dont have a script for first blood sanity check?
i swear the countdown timer is going slower the closer it gets 
that's the scoreboard going down
Reminder delivery:
To: @glossy marsh
Scheduled: Fri Feb 5 17:59:56 2021 (6 hours, 0 minutes ago)
Jump Link: #general message
Reminder:```
impending perfect infrastructure โญ
barely got it going
no sanity check 
nooo
wtf
second person
I do not approve of the blood
pepehands
this is not okay
BLOODED SANITY POGGERS
same, disqualify
TRUE
TRUE
get those lies out of here
facts
fax
NICE JOB @vague bramble
@hollow jasper no weeb reacts
STOP THE COUNT
0/10 sanity check not called sanity check
THIS!
It took forever to find
@neon matrix where is our prize
did u get fb?
yes
ok dm
Hi
ti-1337 plus CE
@tawny wigeon
i haven't released
kmh's magnum opus
@tawny wigeon i am losing morale ๐ฆ
you can do it! you solved the sanity check already
shut it newcrypt v2
Thanks <3
๐ญ
if someone can solve my challenges i'll dm them a prize
can someone please solve a not-my-challenge first thx
Did it start
Points are not too much
print = lambda s: __builtins__.print(colr.Colr(s).rainbow(freq=0.8))
input = lambda s: (__builtins__.print(colr.Colr(s).rainbow(freq=0.8), end=""), __builtins__.input())[1]``` why
sigh

why no solves ๐
I need to include this in all my python code
just fyi we didn't order challs in terms of difficulty
there is 1 baby among us
must be pyjail
where are the solves ๐
at the sanity check chall
is ti-1337 down
The madlads build video games
oh wait it works now
!flag
!flag
!flag
!flag
!flag
!flag
!flag
!flag
don't even try to do it all on the server
ruined ๐ก
no test on prod
k
you're not gonna be able to solve it
!baby
it's for your own good
defund they could cheese
!baby
i thought you got rid of cheese
!flag
!commands add flag dice{gang}
โ
Command flag has been added!
you can never be certain
!flag
dice{gang}
!flag
dice{gang}
i did defense in depth against cheese, but cpython is big
cringe
ew
this the right place for questions to the authors?
now the command actually does something
!flag
dice{gang}
yes @hidden hornet
!flag
dice{gang}
Oh god, here comes the !flag train
!flag
dice{gang}
!flag
dice{gang}
it's way better when people spam useless commands

๐ You do not have the required permissions to run this command
!commands add uwu owo
yeah now its ruined
!flag 123321
dice{gang}
ginkoid ๐ฟ ๐ฅฐ
omg barge caboose!
blinkgรฉ
@vapid beacon in your TI calculator program, I'm missing a module "colr", is this on purpose? Am I supposed to be launching the program to find the flag?
!flag flippidy
dice{gang}
damn
!flag
dice{gang}
when I run I get the "missing module" error
You could comment out the 2 lambdas
the dockerfile provides all the information necessary for deployment
if oyu install docker you can do
docker build . -t ti1337plusce
got you, thanks so much
wat is prize for win
!flag
dice{gang}
#defund
ctftime points
tru
the prize is a nonzero quantity of american usd dollars
๐
american usd dollars as opposed to british usd dollars
big team
ummm what does rev stand for?
reverend
reverse engineering
reverse engineering
ty ty
i new to ctfs
sounds legit

is the crypto / plagiarism question rsa?
oh funk theyre unordered
Thank you
The scores page (https://ctf.dicega.ng/scores) has a graph with unlabeled axes. :triggered:
Relevant XKCD: https://xkcd.com/833/
give it a bit
hmm
@amber wind bring back UHC
no u
Flag format?
my servers aren't setup rn :/
dice{}
dicega is like pepega except dice
flag{n1C3_wAy_70_5AY_H1}
pepega
!flag
ok
Always spam that
@neon matrix for cryptonewcrypt v2 i'm assuming the Crypto module is not supposed to be included, right?
why not?
@hollow jasper no weeb reacts
So much promotions for the TI pyjail challenge everywhere on the internet. Itโs literally everywhere. Slow down.
crypto uses cryptodome
either should be fine i think but for my system, cryptodome is installed not pycrypto
its so good though ๐ also what places lol
i put it on my twitter and in a discord
hey kmh deserves it he only writes like 1 challenge every 4 months ๐
๐
so now angstrom only gets 2 kmh challenges
i wrote 3 in the last 4 months ๐
tbh I liked aaron's better :/
and problem writing pace will pick up as the competition date approaches
(you're not supposed to tell everyone that)
๐
number 1 rule of ctfs is pretending like you wrote all your challs in advance
lol i think i wrote like 3 crypto challs in the week before angstrom last year
thank you scoreboard very cool
pretty lines
legend has it that at the end of the ctf those lines will reveal a flag
oh wow that's a very interesting graph
we could only afford 3 colors
o ok first letter is d

wtf, 
Wow, google sponsorships must be bad or colors are expensive
our copy of rctf isn't activated so we're stuck with 3 colors
Hi
how I can begine with ctf I register And I enter to page of chalanges but I don't know to statt
start
Pick a challenge and see if you can somehow get the flag
it looks like the web category is probably the best place to start ๐
Stop the count 
Is there an admin for Missing Flavortext?
@harsh abyss
isn't dan afk rn
dox11111;!!
dan the redpwn man
@stone nacelle hello qpwoeirut
pb stop hoarding ๐
hello <@&805956149504770088> who can i contact regarding Babier CSP? Need to confirm about the flag cuz its not working
lmao is organizer pingable
๐
@arctic gyro is the author for babier csp
๐ค ๐ค
yes
Okay thank you!
intentional
interesting
mfw pingable organizer role
you're supposed to ping orgs for urgent non-chall specific things
not
at organizer how to sice the deet
Me rn
wait is it happening now
can someone explain how admin bots work?
@heavy prawn any hints on how to open babymix?
you submit the url you want the admin bot to visit
bruteforce go brrr
and a chrome instance will navigate to your url
so you can execute some client-side attack like XSS
ty ty
wait, so how is that different from just typing it into my own address bar
the admin bot will have, for example, admin level cookies set
which u can then steal w/ a xss
inb4 the browser instance is an old version of IE with 50 exploits available
lmao
beef go brr
inb4 intended solution is to exploit cve 21148
went to babier-csp.dicec.tf and viewed a fruit then copied the url into the admin bot link, said flag would be put in a cookie, there is no cookie'
because you are not the admin
so how do you solve it
you need to use the force
normally on webpaghes this is stored as document.cookie
so
you need some way to get his value for document.cookie - and send it to you
ygm
what type of exploit would be relevant
a working one ๐
Does this involve perhaps scripting and stealing the cookies
whats the next character

once I've negotiated their safe departure I can leek
Babier CSP hint please
i
๐
lol
No longer afk btw
we have not seen a blood in almost 2 hours
time to submit a flag on the admin team
can you give an hint
for what
Babier CSP -
For the question, please ๐ฆ
ah sorry, I'm not in charge of that one
Who is in charge
looks like chall author is notdeghost
im trying to figure out babier csp too rn
im looking at one of the reverse engineering ones what would i use to view them?
or rather go through them or something
ghidra is free
ty sorry im new to ctfs
!flag
scroll up
seems to be up for me
Good cheesening mr dicegang
๐ง
the scoreboard graph is now in HDโข๏ธ 
(more frequent updates for your viewing pleasure)
still just 3 colors tho
what is the Open Division thing?
is it an rctf feature you didn't remove?
yes
who is ireland? author of the crypto/plagiarism challenge?
@thorn dome
can i pm them with questions? specifically i tried following the hint suggested
no luck finding the lib that the post used
wassup
hi, what is the format for flag
!flag
dice{gang}
huh
What is the flag format?
dice{...} (regex:
dice\{[a-zA-Z0-9_,.'?!@$&<>*:-]*\})
can I ask an admin about babymix? i found the flag but it's not working
dm me @tired pecan
nvm ๐
ok :)
!flag
angr go brrrr
!fleg
did{gong}
nice
question for web utils: jim/brownie
@lyric nova dm one of us?
once the competition ends, competitors are free to release their own
!flag
just wondering, will there be a "forensics" category?
there will not
if there are any forensics type challenges, they will go in the misc category
don't post challenge details in public channels ๐
not my chall but sure dm me
!flag
there are no admins
time for 
let's rise up together
!flag

At what point should I just switch to a different field in IT to focus on? I've studied (admittedly not primarily security) for well over two years and I can't solve a single CTF challenge
have you ever done a CTF prior to this?
if not then don't be too harsh on yourself man
I've done some overthewire wargame stuff and tried my hand at an xmas CTF once + watched a bunch of videos on solutions to CTFs
im new to ctfs too, so that's comforting to know๐
I could try some easy wargames or something instead
I know you're supposed to play to your strengths when it comes to what you're studying , but I really don't know what mine are in the field of IT
It's depressing loving the field but not being able to seemingly do well in any part of it
There are many live CTFs everyday, just take a look everytime u can
tbh easiest web challenge took me about 1.5-2 hours lol
babier csp? that took me much longer...๐
Yep
but it was my first time solving something like it, so im really happy that i did
Yes, don't be so hard on yourself! A big part of solving CTF challenges is using past experience. Keep at it and you'll start to recognize patterns in the tasks.
I can usually get a couple of flags at CTF events, but this one is really hard... I feel like Iโm 80% of the way there for Babier and Flavortext, but no cigar.
you can do it ๐
!flag
hello
It's my first CTF I am doing in real time
Someone knows how to link between our team's points to ctftime team points (if this ctf will have weight)
we'll be uploading the scoreboard to ctftime after the competition
you guys will rate the ctf based on perceived quality
ctftime has a public formula for calculating team points as a result
ok
my question is basically how does ctftime knows to give me points if I didn't register using my ctftime account
matches team name
doesn't it leave room for faking?





