Cybersecurity Competition

Investigate clues, decode secrets, analyze digital evidence, and uncover hidden flags in this hands-on cybersecurity challenge.

Point of Contact

Qusai Hasan
Lecturer of Computing Security
Computing Sciences Department

On-Site Competition

This competition requires no advance preparation and will be completed onsite using the materials and instructions provided on the event day.

Competition Overview

Capture the Flag (CTF)

The Capture the Flag (CTF) competition is a beginner-friendly, team-based cybersecurity challenge designed to introduce participants to fundamental concepts in cybersecurity through practical, hands-on activities.

The competition focuses on problem-solving, investigation, logical thinking, and the application of basic cybersecurity techniques in a controlled environment.

Competition Format

Three Cybersecurity Stations

The competition consists of three independent cybersecurity stations hosted on a central competition website.

01

Station 1

Start Your Engine

Participants will work through:

  • Web-based login inspection using browser developer tools and Base64 encoding
  • Image steganography extraction
  • Substitution ciphers
02

Station 2

The Race Is On

Participants will work through:

  • PCAP packet analysis to extract geographic coordinates
  • Location investigation using Google Street View to retrieve a ZIP password
  • Morse code decoding
  • URL parameter navigation
  • Cookie inspection
03

Station 3

A Little Web of Secrets

Participants will use Open Source Intelligence (OSINT) techniques to investigate:

  • A fictional social media account's posts
  • Comments and tagged accounts
  • Links associated with the account
  • Five security questions
  • The final flag

Industry Partner: Collaboration with Uney for industry partner involvement will be investigated.

Competition Rules

Time Limit

90 MIN

Maximum time to solve all three stations

Team Format

3 MAX

Maximum students per team

01
Target Audience

Students in grades 11 and 12 are invited to participate.

02
School & Team Limit

Each school may register only one team, with a maximum of three students per team.

03
Registration & Access

Teams register through the competition platform prior to starting. The team timer begins upon the first login.

04
Time Limit

Teams have a maximum window of 90 minutes to solve all three stations.

05
Flag Submissions

Flags are submitted via the platform. Repeated submissions are allowed without direct penalties.

06
Hints

Using optional hints incurs an automatic time penalty added to the final completion time.

07
Allowed Resources

Public search engines, online decoders such as Base64 and Morse code tools, online steganography tools, Wireshark, and mapping/Street View services may be used.

08   Safety & Conduct

The competition is conducted in a controlled educational environment. Attacks on the CTF server or other teams are strictly prohibited. All OSINT targets are strictly fictional accounts.

Technical Specifications

Competition Setup

Location, Equipment & Infrastructure

01   Location & Equipment

University Computer Laboratory

The competition will be conducted in a university computer laboratory.

3 computers per team

Each computer will be equipped with a keyboard, mouse, and internet/laboratory network connectivity.

02   Software

Tools & Applications

Web Browser
Chrome, Edge, or Firefox with Developer Tools enabled

File Analysis
Utilities such as Wireshark for analyzing .pcap files

03   Infrastructure

Local Competition Server

A local competition server will host the core CTF environment, including:

CTF website & challenge pages
Challenge files
Flag validation engine
Hint system
Automatic timer
Live leaderboard

Evaluation

Scoring Framework

Scoring & Flag Validation

Fully automated scoring. Scoring and flag validation are handled automatically by the competition platform. Teams must successfully complete all three stations to receive a final score.

Criteria
Description
Base Completion
Successful submission of correct flags for Station 1, Station 2, and Station 3.
Adjusted Time Calculation
Adjusted Time = Actual Completion Time + Hint Penalties
Ranking
Teams are ranked on the live leaderboard according to the lowest Adjusted Time.
Tie-Breaking
System-recorded timestamps determine ranking order. If teams remain tied, the earliest timestamp of the final submitted flag is used.

Constrains and Requirements

Station Requirements

Tools & Skills Required

01

Station 1

Start Your Engine

Requires:

  • Browser developer tools
  • Base64 decoder
  • Steganography extraction tool
02

Station 2

The Race Is On

Requires:

  • PCAP packet inspection software, such as Wireshark
  • Google Maps / Street View
  • ZIP password extraction tool
  • Morse code decoder
  • Browser cookie inspection
03

Station 3

A Little Web of Secrets

Requires investigating publicly available information across fictional social media posts, comments, tagged accounts, and linked platforms to answer five security questions.

Safety Constraint

No advanced exploitation techniques or malicious attacks on real systems are required or permitted.

Competition Flow

01

Before the Start

Pre-Competition

  • Team registration
  • Workstation assignment
  • Network and CTF platform functionality check by volunteers
  • Participant briefing covering rules, penalties, the 90-minute limit, and leaderboard
02

90-Minute Challenge

During Competition

  • Simultaneous challenge solving across all three stations
  • Automatic time tracking
  • Automatic flag validation
  • Automatic penalty application
  • Live leaderboard updates
03

Completion

Competition End

The competition terminates after 90 minutes, or earlier if a team solves all challenges.

Teams are automatically ranked on the leaderboard by adjusted completion time.

Registration

Ready to Compete?

Register Your Team

Register your team to participate in the Capture the Flag competition.

Website last updated: October 2, 2026