Cybersecurity Competition
Investigate clues, decode secrets, analyze digital evidence, and uncover hidden flags in this hands-on cybersecurity challenge.
Point of Contact
On-Site Competition
This competition requires no advance preparation and will be completed onsite using the materials and instructions provided on the event day.
Competition Overview
Capture the Flag (CTF)
The Capture the Flag (CTF) competition is a beginner-friendly, team-based cybersecurity challenge designed to introduce participants to fundamental concepts in cybersecurity through practical, hands-on activities.
The competition focuses on problem-solving, investigation, logical thinking, and the application of basic cybersecurity techniques in a controlled environment.
Competition Format
Three Cybersecurity Stations
The competition consists of three independent cybersecurity stations hosted on a central competition website.
Station 1
Start Your Engine
Participants will work through:
- Web-based login inspection using browser developer tools and Base64 encoding
- Image steganography extraction
- Substitution ciphers
Station 2
The Race Is On
Participants will work through:
- PCAP packet analysis to extract geographic coordinates
- Location investigation using Google Street View to retrieve a ZIP password
- Morse code decoding
- URL parameter navigation
- Cookie inspection
Station 3
A Little Web of Secrets
Participants will use Open Source Intelligence (OSINT) techniques to investigate:
- A fictional social media account's posts
- Comments and tagged accounts
- Links associated with the account
- Five security questions
- The final flag
Industry Partner: Collaboration with Uney for industry partner involvement will be investigated.
Competition Rules
Time Limit
Maximum time to solve all three stations
Team Format
Maximum students per team
Students in grades 11 and 12 are invited to participate.
Each school may register only one team, with a maximum of three students per team.
Teams register through the competition platform prior to starting. The team timer begins upon the first login.
Teams have a maximum window of 90 minutes to solve all three stations.
Flags are submitted via the platform. Repeated submissions are allowed without direct penalties.
Using optional hints incurs an automatic time penalty added to the final completion time.
Public search engines, online decoders such as Base64 and Morse code tools, online steganography tools, Wireshark, and mapping/Street View services may be used.
08 Safety & Conduct
The competition is conducted in a controlled educational environment. Attacks on the CTF server or other teams are strictly prohibited. All OSINT targets are strictly fictional accounts.
Technical Specifications
Competition Setup
Location, Equipment & Infrastructure
01 Location & Equipment
University Computer Laboratory
The competition will be conducted in a university computer laboratory.
Each computer will be equipped with a keyboard, mouse, and internet/laboratory network connectivity.
02 Software
Tools & Applications
Web Browser
Chrome, Edge, or Firefox with Developer Tools enabled
File Analysis
Utilities such as Wireshark for analyzing .pcap files
03 Infrastructure
Local Competition Server
A local competition server will host the core CTF environment, including:
Evaluation
Scoring Framework
Scoring & Flag Validation
Fully automated scoring. Scoring and flag validation are handled automatically by the competition platform. Teams must successfully complete all three stations to receive a final score.
Constrains and Requirements
Station Requirements
Tools & Skills Required
Station 1
Start Your Engine
Requires:
- Browser developer tools
- Base64 decoder
- Steganography extraction tool
Station 2
The Race Is On
Requires:
- PCAP packet inspection software, such as Wireshark
- Google Maps / Street View
- ZIP password extraction tool
- Morse code decoder
- Browser cookie inspection
Station 3
A Little Web of Secrets
Requires investigating publicly available information across fictional social media posts, comments, tagged accounts, and linked platforms to answer five security questions.
Safety Constraint
No advanced exploitation techniques or malicious attacks on real systems are required or permitted.
Competition Flow
Before the Start
Pre-Competition
- Team registration
- Workstation assignment
- Network and CTF platform functionality check by volunteers
- Participant briefing covering rules, penalties, the 90-minute limit, and leaderboard
90-Minute Challenge
During Competition
- Simultaneous challenge solving across all three stations
- Automatic time tracking
- Automatic flag validation
- Automatic penalty application
- Live leaderboard updates
Completion
Competition End
The competition terminates after 90 minutes, or earlier if a team solves all challenges.