Repository files navigation

CTF Gameserver

This is a Gameserver for attack-defense (IT security) CTFs. It is used for hosting FAUST CTF, but designed to be re-usable for other competitions. It is scalable to large online CTFs, battle-tested in many editions of FAUST CTF, and customizable for other competitions.

For documentation on architecture, installation, etc., head to ctf-gameserver.org.

What's Included

The Gameserver consists of multiple components:

  • Web: A Django-based web application for team registration, scoreboards, and simple hosting of informational pages. It also contains the model files, which define the database structure.
  • Controller: Coordinates the progress of the competition, e.g. the current tick and flags to be placed.
  • Checker: Place and retrieve flags and test the service status on all teams' Vulnboxes. The Checker Master launches Checker Scripts, which are individual to each service.
  • Checkerlib: Libraries to assist in developing Checker Scripts. Currently, Python and Go are supported.
  • Submission: Server to submit captured flags to.
  • VPN Status: Optional helper that collects statistics about network connectivity to teams.

Related Projects

There are several alternatives out there, although none of them could really convince us when we started the project in 2015. Your mileage may vary.

  • ictf-framework from the team behind iCTF, one of the most well-known attack-defense CTFs. In addition to a gameserver, it includes utilities for VM creation and network setup. We had trouble to get it running and documentation is generally rather scarce.
  • HackerDom checksystem is the Gameserver powering RuCTF. The first impression wasn't too bad, but it didn't look quite feature-complete to us. However, we didn't really grasp the Perl code, so we might have overlooked something.
  • saarctf-gameserver from our friends at saarsec is younger than our Gameserver. It contains a nice scoreboard and infrastructure for VPN/network setup.
  • EnoEngine by our other friends at ENOFLAG is also younger than our solution.
  • CTFd is the de-facto standard for jeopardy-based CTFs. It is, however, not suitable for an attack-defense CTF.

Another factor for the creation of our own system was that we didn't want to build a large CTF on top of a system which we don't entirely understand.

Development

For a local development environment, set up a Python venv or use our dev container from .devcontainer.json.

Then, run make dev. Tests can be executed through make test and a development instance of the Web component can be launched with make run_web.

We always aim to keep our Python dependencies compatible with the versions packaged in Debian stable. Debian-based distributions are our primary target, but the Python code should generally be platform-independent.

Docker Compose

A containerized baseline infrastructure is available via docker-compose.yml in this repository. It includes PostgreSQL, Web, Controller, and Submission services, plus optional profiles for Checker and VPN Status. See docker/README.md for setup and usage.

Security

Should you encounter any security vulnerabilities in the Gameserver, please report them to us privately. Use GitHub vulnerability reporting or contact Felix Dreissig or Simon Ruderich directly.

Copyright

The Gameserver was initially created by Christoph Egger and Felix Dreissig. It is currently maintained by Felix Dreissig and Simon Ruderich with contributions from others.

It is released under the ISC License.

About

FAUST Gameserver for attack-defense CTFs

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

CTF Gameserver

This is a Gameserver for attack-defense (IT security) CTFs. It is used for hosting FAUST CTF, but designed to be re-usable for other competitions. It is scalable to large online CTFs, battle-tested in many editions of FAUST CTF, and customizable for other competitions.

For documentation on architecture, installation, etc., head to ctf-gameserver.org.

What's Included

The Gameserver consists of multiple components:

  • Web: A Django-based web application for team registration, scoreboards, and simple hosting of informational pages. It also contains the model files, which define the database structure.
  • Controller: Coordinates the progress of the competition, e.g. the current tick and flags to be placed.
  • Checker: Place and retrieve flags and test the service status on all teams' Vulnboxes. The Checker Master launches Checker Scripts, which are individual to each service.
  • Checkerlib: Libraries to assist in developing Checker Scripts. Currently, Python and Go are supported.
  • Submission: Server to submit captured flags to.
  • VPN Status: Optional helper that collects statistics about network connectivity to teams.

Related Projects

There are several alternatives out there, although none of them could really convince us when we started the project in 2015. Your mileage may vary.

  • ictf-framework from the team behind iCTF, one of the most well-known attack-defense CTFs. In addition to a gameserver, it includes utilities for VM creation and network setup. We had trouble to get it running and documentation is generally rather scarce.
  • HackerDom checksystem is the Gameserver powering RuCTF. The first impression wasn't too bad, but it didn't look quite feature-complete to us. However, we didn't really grasp the Perl code, so we might have overlooked something.
  • saarctf-gameserver from our friends at saarsec is younger than our Gameserver. It contains a nice scoreboard and infrastructure for VPN/network setup.
  • EnoEngine by our other friends at ENOFLAG is also younger than our solution.
  • CTFd is the de-facto standard for jeopardy-based CTFs. It is, however, not suitable for an attack-defense CTF.

Another factor for the creation of our own system was that we didn't want to build a large CTF on top of a system which we don't entirely understand.

Development

For a local development environment, set up a Python venv or use our dev container from .devcontainer.json.

Then, run make dev. Tests can be executed through make test and a development instance of the Web component can be launched with make run_web.

We always aim to keep our Python dependencies compatible with the versions packaged in Debian stable. Debian-based distributions are our primary target, but the Python code should generally be platform-independent.

Docker Compose

A containerized baseline infrastructure is available via docker-compose.yml in this repository. It includes PostgreSQL, Web, Controller, and Submission services, plus optional profiles for Checker and VPN Status. See docker/README.md for setup and usage.

Security

Should you encounter any security vulnerabilities in the Gameserver, please report them to us privately. Use GitHub vulnerability reporting or contact Felix Dreissig or Simon Ruderich directly.

Copyright

The Gameserver was initially created by Christoph Egger and Felix Dreissig. It is currently maintained by Felix Dreissig and Simon Ruderich with contributions from others.

It is released under the ISC License.

About

FAUST Gameserver for attack-defense CTFs

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

CTF Gameserver

This is a Gameserver for attack-defense (IT security) CTFs. It is used for hosting FAUST CTF, but designed to be re-usable for other competitions. It is scalable to large online CTFs, battle-tested in many editions of FAUST CTF, and customizable for other competitions.

For documentation on architecture, installation, etc., head to ctf-gameserver.org.

What's Included

The Gameserver consists of multiple components:

  • Web: A Django-based web application for team registration, scoreboards, and simple hosting of informational pages. It also contains the model files, which define the database structure.
  • Controller: Coordinates the progress of the competition, e.g. the current tick and flags to be placed.
  • Checker: Place and retrieve flags and test the service status on all teams' Vulnboxes. The Checker Master launches Checker Scripts, which are individual to each service.
  • Checkerlib: Libraries to assist in developing Checker Scripts. Currently, Python and Go are supported.
  • Submission: Server to submit captured flags to.
  • VPN Status: Optional helper that collects statistics about network connectivity to teams.

Related Projects

There are several alternatives out there, although none of them could really convince us when we started the project in 2015. Your mileage may vary.

  • ictf-framework from the team behind iCTF, one of the most well-known attack-defense CTFs. In addition to a gameserver, it includes utilities for VM creation and network setup. We had trouble to get it running and documentation is generally rather scarce.
  • HackerDom checksystem is the Gameserver powering RuCTF. The first impression wasn't too bad, but it didn't look quite feature-complete to us. However, we didn't really grasp the Perl code, so we might have overlooked something.
  • saarctf-gameserver from our friends at saarsec is younger than our Gameserver. It contains a nice scoreboard and infrastructure for VPN/network setup.
  • EnoEngine by our other friends at ENOFLAG is also younger than our solution.
  • CTFd is the de-facto standard for jeopardy-based CTFs. It is, however, not suitable for an attack-defense CTF.

Another factor for the creation of our own system was that we didn't want to build a large CTF on top of a system which we don't entirely understand.

Development

For a local development environment, set up a Python venv or use our dev container from .devcontainer.json.

Then, run make dev. Tests can be executed through make test and a development instance of the Web component can be launched with make run_web.

We always aim to keep our Python dependencies compatible with the versions packaged in Debian stable. Debian-based distributions are our primary target, but the Python code should generally be platform-independent.

Docker Compose

A containerized baseline infrastructure is available via docker-compose.yml in this repository. It includes PostgreSQL, Web, Controller, and Submission services, plus optional profiles for Checker and VPN Status. See docker/README.md for setup and usage.

Security

Should you encounter any security vulnerabilities in the Gameserver, please report them to us privately. Use GitHub vulnerability reporting or contact Felix Dreissig or Simon Ruderich directly.

Copyright

The Gameserver was initially created by Christoph Egger and Felix Dreissig. It is currently maintained by Felix Dreissig and Simon Ruderich with contributions from others.

It is released under the ISC License.

About

FAUST Gameserver for attack-defense CTFs

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

CTF Gameserver

This is a Gameserver for attack-defense (IT security) CTFs. It is used for hosting FAUST CTF, but designed to be re-usable for other competitions. It is scalable to large online CTFs, battle-tested in many editions of FAUST CTF, and customizable for other competitions.

For documentation on architecture, installation, etc., head to ctf-gameserver.org.

What's Included

The Gameserver consists of multiple components:

  • Web: A Django-based web application for team registration, scoreboards, and simple hosting of informational pages. It also contains the model files, which define the database structure.
  • Controller: Coordinates the progress of the competition, e.g. the current tick and flags to be placed.
  • Checker: Place and retrieve flags and test the service status on all teams' Vulnboxes. The Checker Master launches Checker Scripts, which are individual to each service.
  • Checkerlib: Libraries to assist in developing Checker Scripts. Currently, Python and Go are supported.
  • Submission: Server to submit captured flags to.
  • VPN Status: Optional helper that collects statistics about network connectivity to teams.

Related Projects

There are several alternatives out there, although none of them could really convince us when we started the project in 2015. Your mileage may vary.

  • ictf-framework from the team behind iCTF, one of the most well-known attack-defense CTFs. In addition to a gameserver, it includes utilities for VM creation and network setup. We had trouble to get it running and documentation is generally rather scarce.
  • HackerDom checksystem is the Gameserver powering RuCTF. The first impression wasn't too bad, but it didn't look quite feature-complete to us. However, we didn't really grasp the Perl code, so we might have overlooked something.
  • saarctf-gameserver from our friends at saarsec is younger than our Gameserver. It contains a nice scoreboard and infrastructure for VPN/network setup.
  • EnoEngine by our other friends at ENOFLAG is also younger than our solution.
  • CTFd is the de-facto standard for jeopardy-based CTFs. It is, however, not suitable for an attack-defense CTF.

Another factor for the creation of our own system was that we didn't want to build a large CTF on top of a system which we don't entirely understand.

Development

For a local development environment, set up a Python venv or use our dev container from .devcontainer.json.

Then, run make dev. Tests can be executed through make test and a development instance of the Web component can be launched with make run_web.

We always aim to keep our Python dependencies compatible with the versions packaged in Debian stable. Debian-based distributions are our primary target, but the Python code should generally be platform-independent.

Docker Compose

A containerized baseline infrastructure is available via docker-compose.yml in this repository. It includes PostgreSQL, Web, Controller, and Submission services, plus optional profiles for Checker and VPN Status. See docker/README.md for setup and usage.

Security

Should you encounter any security vulnerabilities in the Gameserver, please report them to us privately. Use GitHub vulnerability reporting or contact Felix Dreissig or Simon Ruderich directly.

Copyright

The Gameserver was initially created by Christoph Egger and Felix Dreissig. It is currently maintained by Felix Dreissig and Simon Ruderich with contributions from others.

It is released under the ISC License.

About

FAUST Gameserver for attack-defense CTFs

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

CTF Gameserver

This is a Gameserver for attack-defense (IT security) CTFs. It is used for hosting FAUST CTF, but designed to be re-usable for other competitions. It is scalable to large online CTFs, battle-tested in many editions of FAUST CTF, and customizable for other competitions.

For documentation on architecture, installation, etc., head to ctf-gameserver.org.

What's Included

The Gameserver consists of multiple components:

  • Web: A Django-based web application for team registration, scoreboards, and simple hosting of informational pages. It also contains the model files, which define the database structure.
  • Controller: Coordinates the progress of the competition, e.g. the current tick and flags to be placed.
  • Checker: Place and retrieve flags and test the service status on all teams' Vulnboxes. The Checker Master launches Checker Scripts, which are individual to each service.
  • Checkerlib: Libraries to assist in developing Checker Scripts. Currently, Python and Go are supported.
  • Submission: Server to submit captured flags to.
  • VPN Status: Optional helper that collects statistics about network connectivity to teams.

Related Projects

There are several alternatives out there, although none of them could really convince us when we started the project in 2015. Your mileage may vary.

  • ictf-framework from the team behind iCTF, one of the most well-known attack-defense CTFs. In addition to a gameserver, it includes utilities for VM creation and network setup. We had trouble to get it running and documentation is generally rather scarce.
  • HackerDom checksystem is the Gameserver powering RuCTF. The first impression wasn't too bad, but it didn't look quite feature-complete to us. However, we didn't really grasp the Perl code, so we might have overlooked something.
  • saarctf-gameserver from our friends at saarsec is younger than our Gameserver. It contains a nice scoreboard and infrastructure for VPN/network setup.
  • EnoEngine by our other friends at ENOFLAG is also younger than our solution.
  • CTFd is the de-facto standard for jeopardy-based CTFs. It is, however, not suitable for an attack-defense CTF.

Another factor for the creation of our own system was that we didn't want to build a large CTF on top of a system which we don't entirely understand.

Development

For a local development environment, set up a Python venv or use our dev container from .devcontainer.json.

Then, run make dev. Tests can be executed through make test and a development instance of the Web component can be launched with make run_web.

We always aim to keep our Python dependencies compatible with the versions packaged in Debian stable. Debian-based distributions are our primary target, but the Python code should generally be platform-independent.

Docker Compose

A containerized baseline infrastructure is available via docker-compose.yml in this repository. It includes PostgreSQL, Web, Controller, and Submission services, plus optional profiles for Checker and VPN Status. See docker/README.md for setup and usage.

Security

Should you encounter any security vulnerabilities in the Gameserver, please report them to us privately. Use GitHub vulnerability reporting or contact Felix Dreissig or Simon Ruderich directly.

Copyright

The Gameserver was initially created by Christoph Egger and Felix Dreissig. It is currently maintained by Felix Dreissig and Simon Ruderich with contributions from others.

It is released under the ISC License.

About

FAUST Gameserver for attack-defense CTFs

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

CTF Gameserver

This is a Gameserver for attack-defense (IT security) CTFs. It is used for hosting FAUST CTF, but designed to be re-usable for other competitions. It is scalable to large online CTFs, battle-tested in many editions of FAUST CTF, and customizable for other competitions.

For documentation on architecture, installation, etc., head to ctf-gameserver.org.

What's Included

The Gameserver consists of multiple components:

  • Web: A Django-based web application for team registration, scoreboards, and simple hosting of informational pages. It also contains the model files, which define the database structure.
  • Controller: Coordinates the progress of the competition, e.g. the current tick and flags to be placed.
  • Checker: Place and retrieve flags and test the service status on all teams' Vulnboxes. The Checker Master launches Checker Scripts, which are individual to each service.
  • Checkerlib: Libraries to assist in developing Checker Scripts. Currently, Python and Go are supported.
  • Submission: Server to submit captured flags to.
  • VPN Status: Optional helper that collects statistics about network connectivity to teams.

Related Projects

There are several alternatives out there, although none of them could really convince us when we started the project in 2015. Your mileage may vary.

  • ictf-framework from the team behind iCTF, one of the most well-known attack-defense CTFs. In addition to a gameserver, it includes utilities for VM creation and network setup. We had trouble to get it running and documentation is generally rather scarce.
  • HackerDom checksystem is the Gameserver powering RuCTF. The first impression wasn't too bad, but it didn't look quite feature-complete to us. However, we didn't really grasp the Perl code, so we might have overlooked something.
  • saarctf-gameserver from our friends at saarsec is younger than our Gameserver. It contains a nice scoreboard and infrastructure for VPN/network setup.
  • EnoEngine by our other friends at ENOFLAG is also younger than our solution.
  • CTFd is the de-facto standard for jeopardy-based CTFs. It is, however, not suitable for an attack-defense CTF.

Another factor for the creation of our own system was that we didn't want to build a large CTF on top of a system which we don't entirely understand.

Development

For a local development environment, set up a Python venv or use our dev container from .devcontainer.json.

Then, run make dev. Tests can be executed through make test and a development instance of the Web component can be launched with make run_web.

We always aim to keep our Python dependencies compatible with the versions packaged in Debian stable. Debian-based distributions are our primary target, but the Python code should generally be platform-independent.

Docker Compose

A containerized baseline infrastructure is available via docker-compose.yml in this repository. It includes PostgreSQL, Web, Controller, and Submission services, plus optional profiles for Checker and VPN Status. See docker/README.md for setup and usage.

Security

Should you encounter any security vulnerabilities in the Gameserver, please report them to us privately. Use GitHub vulnerability reporting or contact Felix Dreissig or Simon Ruderich directly.

Copyright

The Gameserver was initially created by Christoph Egger and Felix Dreissig. It is currently maintained by Felix Dreissig and Simon Ruderich with contributions from others.

It is released under the ISC License.

About

FAUST Gameserver for attack-defense CTFs

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

CTF Gameserver

This is a Gameserver for attack-defense (IT security) CTFs. It is used for hosting FAUST CTF, but designed to be re-usable for other competitions. It is scalable to large online CTFs, battle-tested in many editions of FAUST CTF, and customizable for other competitions.

For documentation on architecture, installation, etc., head to ctf-gameserver.org.

What's Included

The Gameserver consists of multiple components:

  • Web: A Django-based web application for team registration, scoreboards, and simple hosting of informational pages. It also contains the model files, which define the database structure.
  • Controller: Coordinates the progress of the competition, e.g. the current tick and flags to be placed.
  • Checker: Place and retrieve flags and test the service status on all teams' Vulnboxes. The Checker Master launches Checker Scripts, which are individual to each service.
  • Checkerlib: Libraries to assist in developing Checker Scripts. Currently, Python and Go are supported.
  • Submission: Server to submit captured flags to.
  • VPN Status: Optional helper that collects statistics about network connectivity to teams.

Related Projects

There are several alternatives out there, although none of them could really convince us when we started the project in 2015. Your mileage may vary.

  • ictf-framework from the team behind iCTF, one of the most well-known attack-defense CTFs. In addition to a gameserver, it includes utilities for VM creation and network setup. We had trouble to get it running and documentation is generally rather scarce.
  • HackerDom checksystem is the Gameserver powering RuCTF. The first impression wasn't too bad, but it didn't look quite feature-complete to us. However, we didn't really grasp the Perl code, so we might have overlooked something.
  • saarctf-gameserver from our friends at saarsec is younger than our Gameserver. It contains a nice scoreboard and infrastructure for VPN/network setup.
  • EnoEngine by our other friends at ENOFLAG is also younger than our solution.
  • CTFd is the de-facto standard for jeopardy-based CTFs. It is, however, not suitable for an attack-defense CTF.

Another factor for the creation of our own system was that we didn't want to build a large CTF on top of a system which we don't entirely understand.

Development

For a local development environment, set up a Python venv or use our dev container from .devcontainer.json.

Then, run make dev. Tests can be executed through make test and a development instance of the Web component can be launched with make run_web.

We always aim to keep our Python dependencies compatible with the versions packaged in Debian stable. Debian-based distributions are our primary target, but the Python code should generally be platform-independent.

Docker Compose

A containerized baseline infrastructure is available via docker-compose.yml in this repository. It includes PostgreSQL, Web, Controller, and Submission services, plus optional profiles for Checker and VPN Status. See docker/README.md for setup and usage.

Security

Should you encounter any security vulnerabilities in the Gameserver, please report them to us privately. Use GitHub vulnerability reporting or contact Felix Dreissig or Simon Ruderich directly.

Copyright

The Gameserver was initially created by Christoph Egger and Felix Dreissig. It is currently maintained by Felix Dreissig and Simon Ruderich with contributions from others.

It is released under the ISC License.

About

FAUST Gameserver for attack-defense CTFs

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

CTF Gameserver

This is a Gameserver for attack-defense (IT security) CTFs. It is used for hosting FAUST CTF, but designed to be re-usable for other competitions. It is scalable to large online CTFs, battle-tested in many editions of FAUST CTF, and customizable for other competitions.

For documentation on architecture, installation, etc., head to ctf-gameserver.org.

What's Included

The Gameserver consists of multiple components:

  • Web: A Django-based web application for team registration, scoreboards, and simple hosting of informational pages. It also contains the model files, which define the database structure.
  • Controller: Coordinates the progress of the competition, e.g. the current tick and flags to be placed.
  • Checker: Place and retrieve flags and test the service status on all teams' Vulnboxes. The Checker Master launches Checker Scripts, which are individual to each service.
  • Checkerlib: Libraries to assist in developing Checker Scripts. Currently, Python and Go are supported.
  • Submission: Server to submit captured flags to.
  • VPN Status: Optional helper that collects statistics about network connectivity to teams.

Related Projects

There are several alternatives out there, although none of them could really convince us when we started the project in 2015. Your mileage may vary.

  • ictf-framework from the team behind iCTF, one of the most well-known attack-defense CTFs. In addition to a gameserver, it includes utilities for VM creation and network setup. We had trouble to get it running and documentation is generally rather scarce.
  • HackerDom checksystem is the Gameserver powering RuCTF. The first impression wasn't too bad, but it didn't look quite feature-complete to us. However, we didn't really grasp the Perl code, so we might have overlooked something.
  • saarctf-gameserver from our friends at saarsec is younger than our Gameserver. It contains a nice scoreboard and infrastructure for VPN/network setup.
  • EnoEngine by our other friends at ENOFLAG is also younger than our solution.
  • CTFd is the de-facto standard for jeopardy-based CTFs. It is, however, not suitable for an attack-defense CTF.

Another factor for the creation of our own system was that we didn't want to build a large CTF on top of a system which we don't entirely understand.

Development

For a local development environment, set up a Python venv or use our dev container from .devcontainer.json.

Then, run make dev. Tests can be executed through make test and a development instance of the Web component can be launched with make run_web.

We always aim to keep our Python dependencies compatible with the versions packaged in Debian stable. Debian-based distributions are our primary target, but the Python code should generally be platform-independent.

Docker Compose

A containerized baseline infrastructure is available via docker-compose.yml in this repository. It includes PostgreSQL, Web, Controller, and Submission services, plus optional profiles for Checker and VPN Status. See docker/README.md for setup and usage.

Security

Should you encounter any security vulnerabilities in the Gameserver, please report them to us privately. Use GitHub vulnerability reporting or contact Felix Dreissig or Simon Ruderich directly.

Copyright

The Gameserver was initially created by Christoph Egger and Felix Dreissig. It is currently maintained by Felix Dreissig and Simon Ruderich with contributions from others.

It is released under the ISC License.

About

FAUST Gameserver for attack-defense CTFs

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages