SlideShare a Scribd company logo
1 of 30
PROGRAMANDO E
CAPTURANDO BANDEIRAS
DIFERENCIAIS EM UM TIME DE CTF!
CAPTURETHEFLAG---->
WHEREISMYFLAG---->
GABRIELA FONSECA
FORMADA EM GESTÃO DE TI, UNINOVE.
PÓS GRADUANDO EM CYBER SECURITY.
VOLUNTÁRIA EM EVENTOS DE SEGURANÇA && TECNÓLOGIA.
ANALISTA DE SI, NA CIPHER.
CTF-PLAYER:
WHOAMI
HELP
BEFORESTART---->
O QUE É CFT? OBJETIVO? TIPOS DE CTF ?
FLAG? AONDE ESTA A FLAG?
MATE A SUA PRIMEIRA FLAG!
JOGADORES DE CTF , TIMES DE CTF E SUAS HABILIDADES.
EVENTOS DE CTF E SUAS MODALIDADES.
POSSO JOGAR? COMO FAZ? POR ONDE COMEÇO?
PORQUE JOGAR CTF?
O QUE É CTF?
CAPTURETHEFLAG---->
CAPTURE THE FLAG
CAPTURE THE FLAG
WHATISTHEPOINT?---->FLAG
É UMA COMPETIÇÃO ONDE O OBJETIVO É CAPTURAR A BANDEIRA, A FLAG.
ESTRUTURA DE UM CTF~
WEARELOSINGPOINTS---->FLAG
ORGANIZAÇÃO/EVENTO - ONLINE E PRESENCIAL
CHALLENGES & TASKS - DESAFIOS
TIMES & JOGADORES
SKILLS - HABILIDADES
HINT - DICAS
RANKING/SCOREBOARD
WRITEUP
TIPOS DE CTF [ /}
CAPTURETHEFLAG--->
ATTACK / DEFENSE
É UM AMBIENTE COM SERVÍÇOS VULNERÁVEIS.
CAPTURE A BANDEIRA INIMIGA É PROTEJA O SEU TERRITORIO.
JEOPARDY
SÃO DIVERSOS DESAFIOS COMPOSTO POR DIFERENTES NIVEIS DE
DIFICULDADES DE ACORDO COM A PONTUAÇÃO.
O QUE É FLAG?
WHATISTHEFLAG---->
CAPTURE A BANDEIRA, DIGO A FLAG
A FAMOSA FLAG
QUALÉOOBJETIVO?---->FLAG
HASH=CKDAOSAKSO394404303840KFFFNVNVJN
EU_POSSO_SER_UMA_FLAG
FLAG{VMVUAGEGSM9NYXIGQ1RGIG5VIEDHCM9H}
HEXQUEENS={4S_M3#IN4$_T6M_3N6O#T54M_F!4G}
GS2W{AOS_SABADOS_NOS_REUNIMOS_PARA_JOGAR_CTF_NO_GAROA}
AONDE ESTÁ A FLAG?
CAPTURETHEFLAG--->
SERVIÇOS:
APLICAÇÕES WEB, FTP, DNS E OUTROS SERVIÇOS...
ARQUIVOS CRIPTOGRAFADOS & ESTENOGRAFIA:
IMAGEM, AUDIO, E-MAIL, ARQUIVOS CORROMPIDOS E OUTROS...
ARQUIVOS BINARIOS:
EXECUTÁVEIS, VM , PROGRAMAS E ETC...
INFRA-ESTRUTURA:
LOG'S, SERVIDORES, MAQUINAS, REDE, PCAP'S ENTRE OUTROS...
WHEREISTHEFLAG--->
TIPOS DE DESAFIOS [?]
CAPTURETHEFLAG--->
CRYPTO
CRIPTOGRAFIA
FORENSICS
ANALÍSE FORENSE
NETWORKING
INFRA-ESTRUTURA E REDES
MISCELLANEOUS
DIVERSOS
TIPOS DE DESAFIOS [?]
CAPTURETHEFLAG--->
PWNABLE/EXPLOITATION
EXPLORAÇÃO DE BINÁRIOS
REVERSING
ENGENHARIA REVERSA
TRIVIA
TRIVIAIS
WEB HACKING
DESAFIOS
WELCOMETOTHEFLAG/GAMES--->
MATE A SUA PRIMEIRA FLAG !!!
DESAFIO DE CTF
YOURTEAMITSYOURNEWBFF
--->
HEY 7878787838
A) SERVIÇO
B) SITE
C) IP
D)N/D
DESAFIO DE CTF
YOURTEAMITSYOURNEWBFF
--->
HEY 7878787838
A) SERVIÇO
B) SITE
C) IP
D)N/D
DESAFIO DE CTF
YOURTEAMITSYOURNEWBFF
--->
O QUE PROGRAMAÇÃO TEM
HAVER COM CTF?
CAPTURETHEFLAG---->
DIFERENCIAIS EM UM TIME DE CTF!
HABILIDADES
TRYTOIMPROVENEWSKILLS---->
LÓGICA DE PROGRAMAÇÃO
ESCREVA SCRIPTS E EXPLOITS.
PROGRAMAÇÃO
DESAFIOS DE REDES, ENGENHARIA REVERSA, ANÁLISE FORENSE, PWNABLE ENTRE OUTROS.
TAMBÉM PODE ROUBAR A FLAG DO TIME ADVERSÁRIO.
CODE REVIEW
COMO "AS COISAS FUNCIONAM" OU COMO ARRUMAR AQUELE CÓDIGO ESCRITO POR ALGUÉM.
JOGADOR(A)ES DE CTF
GIRLSJUSTWANTTOHAVEFUN---->
AGATHA SOPHIA
WEB & PROGRAMAÇÃO EM C/C++ , PYTHON
ALLEY
WEB & PROGRAMAÇÃO EM C/C++ , PYTHON
INGRID SPANGLER
CRIPTOGRAFIA , FORENSE & PROGRAMAÇÃO EM PYTHON
CLARA NOBRE
WEB, REDES & PROGRAMAÇÃO EM PYTHON
GABRIELA FONSECA
WEB & STEGO
TIMES DE CTF
TEAM@CTF---->
EVENTOS E MODALIDADES
CAPTURETHEFLAG---->
JOGUE POR HOBBY OU SEJA CAMPEÃO NOS
EVENTOS
PRESENCIAIS/EVENTOS
CAPTURETHEFLAG--->
DISPUTAS/ONLINE ~
CTFTODAY---->
POR ONDE COMEÇAR?
CAPTURETHEFLAG--->
HTTP://CAPTF.COM/PRACTICE-CTF/
LET'S GO AND
SUBMIT THE
FLAG!
WHEREISTHEFLAG--->
#DESAFIO CODAMOS
CAPTURETHEFLAG--->
ACESSE: HTTP://104.233.105.35/NU/CODAMOS.HTML
ENCONTRE A FLAG E TWEET:
'HEY, @GAB__FONSECA' , A FLAG É --->'
PERGUNTAS?
CAPTURETHEFLAG--->
"FAÇA AMIGOS, MONTE UM TIME
E TENHA UMA VIDA SOCIAL."
- ARTHUR PAIXÃO
AND THE MOST IMPORTANT TIP OF ALL...
FLAG{OBRIGADO(A)}
GITHUB.COM/GABRIELAFONSECA
@GAB__FONSECA
AVAILABLEIN--->

More Related Content

Similar to Programando e Capturando Bandeiras: Diferenciais em um Time de CTF!

NFT Marketplace Clone Script
NFT Marketplace Clone ScriptNFT Marketplace Clone Script
NFT Marketplace Clone ScriptNFTwiiz global
 
Trying and evaluating the new features of GlusterFS 3.5
Trying and evaluating the new features of GlusterFS 3.5Trying and evaluating the new features of GlusterFS 3.5
Trying and evaluating the new features of GlusterFS 3.5Keisuke Takahashi
 
Kauli SSPにおけるVyOSの導入事例
Kauli SSPにおけるVyOSの導入事例Kauli SSPにおけるVyOSの導入事例
Kauli SSPにおけるVyOSの導入事例Kazuhito Ohkawa
 
Life of PySpark - A tale of two environments
Life of PySpark - A tale of two environmentsLife of PySpark - A tale of two environments
Life of PySpark - A tale of two environmentsShankar M S
 
DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...
DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...
DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...Felipe Prado
 
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...sonjeku1
 
Playing 44CON CTF for fun and profit
Playing 44CON CTF for fun and profitPlaying 44CON CTF for fun and profit
Playing 44CON CTF for fun and profit44CON
 
Playing CTFs for Fun & Profit
Playing CTFs for Fun & ProfitPlaying CTFs for Fun & Profit
Playing CTFs for Fun & Profitimpdefined
 
ACI Multicast 구성 가이드
ACI Multicast 구성 가이드ACI Multicast 구성 가이드
ACI Multicast 구성 가이드Woo Hyung Choi
 
May2010 hex-core-opt
May2010 hex-core-optMay2010 hex-core-opt
May2010 hex-core-optJeff Larkin
 

Similar to Programando e Capturando Bandeiras: Diferenciais em um Time de CTF! (12)

NFT Marketplace Clone Script
NFT Marketplace Clone ScriptNFT Marketplace Clone Script
NFT Marketplace Clone Script
 
Trying and evaluating the new features of GlusterFS 3.5
Trying and evaluating the new features of GlusterFS 3.5Trying and evaluating the new features of GlusterFS 3.5
Trying and evaluating the new features of GlusterFS 3.5
 
Kauli SSPにおけるVyOSの導入事例
Kauli SSPにおけるVyOSの導入事例Kauli SSPにおけるVyOSの導入事例
Kauli SSPにおけるVyOSの導入事例
 
Life of PySpark - A tale of two environments
Life of PySpark - A tale of two environmentsLife of PySpark - A tale of two environments
Life of PySpark - A tale of two environments
 
Intrusion Techniques
Intrusion TechniquesIntrusion Techniques
Intrusion Techniques
 
DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...
DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...
DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...
 
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
 
Playing 44CON CTF for fun and profit
Playing 44CON CTF for fun and profitPlaying 44CON CTF for fun and profit
Playing 44CON CTF for fun and profit
 
Playing CTFs for Fun & Profit
Playing CTFs for Fun & ProfitPlaying CTFs for Fun & Profit
Playing CTFs for Fun & Profit
 
ACI Multicast 구성 가이드
ACI Multicast 구성 가이드ACI Multicast 구성 가이드
ACI Multicast 구성 가이드
 
Samplab19
Samplab19Samplab19
Samplab19
 
May2010 hex-core-opt
May2010 hex-core-optMay2010 hex-core-opt
May2010 hex-core-opt
 

Recently uploaded

Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024SynarionITSolutions
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 

Recently uploaded (20)

Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 

Programando e Capturando Bandeiras: Diferenciais em um Time de CTF!