RULES(2019) RULES(2019)

Name

contest-rules - 2019 Square Capture the Flag rules.

Dates

The event starts on October 10th 2019, at 19:00 UTC and ends on October 16th 2019, at 19:00 UTC.

Puzzles will be available for future download. Points will not be awarded for solving them after the event ends.

All puzzles are solvable without brute forcing the solutions.

Flag format

You know you have successfully solved a puzzle if you find a string which matches the following regular expression:
/flag-[0-9a-f]{8,64}/i.

For instance, flag-27fbe50bf1ccdaf5cfc9a1 or FLAG-E8EFDA46 would be valid flags.

Timed release

Each puzzle will be released at a specific time (spread over one week). Schedule is made available before the event start. The release times are carefully picked to avoid favoring any given timezone.

Puzzles are independent and can be solved in any order.

First solver bonus

The first team to solve a challenge and submit a valid flag will be awarded bonus points.

Reference machine

All puzzles have been verified to be solvable using Ubuntu 18.04 and Chrome 77.0.3865.90. Most puzzles should be solvable on a variety of operating system / browser / virtualization software combinations.

If a puzzle contains binaries for various platforms, only the Linux binary is guaranteed to be correct. Other platforms are provided as a convenience only and are not guaranteed to work.

Prizes

Small prizes will be awarded to the top scoring team or teams. The organizers will contact the winners to organize prize delivery.

If there is a tie, the first team to have scored their last point, based on the organizers' records, wins the tie.

Decision of the organizers will be final and binding with regard to the prizes.

Teams

One-person teams are allowed, but it's more fun with friends! There is no limit on team size. We try our best to provide prizes for all team members, without guarantee for teams larger than ten (10) members.

Terms of Service


Email and data use

Providing an email is optional. The email is only used for account recovery purpose and as a means of contact for prize coordination.

All data related to the event will be deleted shortly after the event ends. Your email will not be associated with any other Square services.

Cookie and tracking

*.squarectf.com does not use any tracking technology. Cookies may be used for the purpose of authentication and content delivery (CloudFlare CDN) purpose.

ctftime.org

Your team name and score will be made available in a public fashion and shared with ctftime.org. Points scored in this event should count towards your global CTF Time leaderboard.

Bugcrowd

This website (and anything hosted under *.squarectf.com) is not included in Square's Bugcrowd bug bounty programs. Please visit the official Bugcrowd site for additional information about Square's bug bounty programs.

CTF Scope

The challenges posted on this site may be hacked using any tools desired. However, hacking of any Square infrastructure, which is separate infrastructure from this site, falls under the terms of Square's Bugcrowd bug bounty program. In addition, Slack has their own terms of service for appropriate use. When in doubt, contact a CTF organizer to determine whether a site or server is within the CTF scope.

The CTF is running on infrastructure hosted by other companies. Please be kind and limit traffic to a reasonable level. All puzzles are solvable without brute forcing the solutions.

Code of Conduct

By participating in this Contest you agree to abide by the Square CTF Code of Conduct. Unacceptable behavior by participants will not be tolerated. Anyone asked to stop unacceptable behavior is expected to comply immediately. If a participant engages in unacceptable behavior, the Square CTF organizers may take any action they deem appropriate at their sole discretion, up to and including expulsion from the Competition and expulsion from the Square CTF Slack.

See also

Work_at_Square(1), Privacy_policy(1), Code_of_conduct(1)

Square, Inc. (c) RULES(2019)