SlideShare une entreprise Scribd logo
1  sur  30
PROGRAMANDO E
CAPTURANDO BANDEIRAS
DIFERENCIAIS EM UM TIME DE CTF!
CAPTURETHEFLAG---->
WHEREISMYFLAG---->
GABRIELA FONSECA
FORMADA EM GESTÃO DE TI, UNINOVE.
PÓS GRADUANDO EM CYBER SECURITY.
VOLUNTÁRIA EM EVENTOS DE SEGURANÇA && TECNÓLOGIA.
ANALISTA DE SI, NA CIPHER.
CTF-PLAYER:
WHOAMI
HELP
BEFORESTART---->
O QUE É CFT? OBJETIVO? TIPOS DE CTF ?
FLAG? AONDE ESTA A FLAG?
MATE A SUA PRIMEIRA FLAG!
JOGADORES DE CTF , TIMES DE CTF E SUAS HABILIDADES.
EVENTOS DE CTF E SUAS MODALIDADES.
POSSO JOGAR? COMO FAZ? POR ONDE COMEÇO?
PORQUE JOGAR CTF?
O QUE É CTF?
CAPTURETHEFLAG---->
CAPTURE THE FLAG
CAPTURE THE FLAG
WHATISTHEPOINT?---->FLAG
É UMA COMPETIÇÃO ONDE O OBJETIVO É CAPTURAR A BANDEIRA, A FLAG.
ESTRUTURA DE UM CTF~
WEARELOSINGPOINTS---->FLAG
ORGANIZAÇÃO/EVENTO - ONLINE E PRESENCIAL
CHALLENGES & TASKS - DESAFIOS
TIMES & JOGADORES
SKILLS - HABILIDADES
HINT - DICAS
RANKING/SCOREBOARD
WRITEUP
TIPOS DE CTF [ /}
CAPTURETHEFLAG--->
ATTACK / DEFENSE
É UM AMBIENTE COM SERVÍÇOS VULNERÁVEIS.
CAPTURE A BANDEIRA INIMIGA É PROTEJA O SEU TERRITORIO.
JEOPARDY
SÃO DIVERSOS DESAFIOS COMPOSTO POR DIFERENTES NIVEIS DE
DIFICULDADES DE ACORDO COM A PONTUAÇÃO.
O QUE É FLAG?
WHATISTHEFLAG---->
CAPTURE A BANDEIRA, DIGO A FLAG
A FAMOSA FLAG
QUALÉOOBJETIVO?---->FLAG
HASH=CKDAOSAKSO394404303840KFFFNVNVJN
EU_POSSO_SER_UMA_FLAG
FLAG{VMVUAGEGSM9NYXIGQ1RGIG5VIEDHCM9H}
HEXQUEENS={4S_M3#IN4$_T6M_3N6O#T54M_F!4G}
GS2W{AOS_SABADOS_NOS_REUNIMOS_PARA_JOGAR_CTF_NO_GAROA}
AONDE ESTÁ A FLAG?
CAPTURETHEFLAG--->
SERVIÇOS:
APLICAÇÕES WEB, FTP, DNS E OUTROS SERVIÇOS...
ARQUIVOS CRIPTOGRAFADOS & ESTENOGRAFIA:
IMAGEM, AUDIO, E-MAIL, ARQUIVOS CORROMPIDOS E OUTROS...
ARQUIVOS BINARIOS:
EXECUTÁVEIS, VM , PROGRAMAS E ETC...
INFRA-ESTRUTURA:
LOG'S, SERVIDORES, MAQUINAS, REDE, PCAP'S ENTRE OUTROS...
WHEREISTHEFLAG--->
TIPOS DE DESAFIOS [?]
CAPTURETHEFLAG--->
CRYPTO
CRIPTOGRAFIA
FORENSICS
ANALÍSE FORENSE
NETWORKING
INFRA-ESTRUTURA E REDES
MISCELLANEOUS
DIVERSOS
TIPOS DE DESAFIOS [?]
CAPTURETHEFLAG--->
PWNABLE/EXPLOITATION
EXPLORAÇÃO DE BINÁRIOS
REVERSING
ENGENHARIA REVERSA
TRIVIA
TRIVIAIS
WEB HACKING
DESAFIOS
WELCOMETOTHEFLAG/GAMES--->
MATE A SUA PRIMEIRA FLAG !!!
DESAFIO DE CTF
YOURTEAMITSYOURNEWBFF
--->
HEY 7878787838
A) SERVIÇO
B) SITE
C) IP
D)N/D
DESAFIO DE CTF
YOURTEAMITSYOURNEWBFF
--->
HEY 7878787838
A) SERVIÇO
B) SITE
C) IP
D)N/D
DESAFIO DE CTF
YOURTEAMITSYOURNEWBFF
--->
O QUE PROGRAMAÇÃO TEM
HAVER COM CTF?
CAPTURETHEFLAG---->
DIFERENCIAIS EM UM TIME DE CTF!
HABILIDADES
TRYTOIMPROVENEWSKILLS---->
LÓGICA DE PROGRAMAÇÃO
ESCREVA SCRIPTS E EXPLOITS.
PROGRAMAÇÃO
DESAFIOS DE REDES, ENGENHARIA REVERSA, ANÁLISE FORENSE, PWNABLE ENTRE OUTROS.
TAMBÉM PODE ROUBAR A FLAG DO TIME ADVERSÁRIO.
CODE REVIEW
COMO "AS COISAS FUNCIONAM" OU COMO ARRUMAR AQUELE CÓDIGO ESCRITO POR ALGUÉM.
JOGADOR(A)ES DE CTF
GIRLSJUSTWANTTOHAVEFUN---->
AGATHA SOPHIA
WEB & PROGRAMAÇÃO EM C/C++ , PYTHON
ALLEY
WEB & PROGRAMAÇÃO EM C/C++ , PYTHON
INGRID SPANGLER
CRIPTOGRAFIA , FORENSE & PROGRAMAÇÃO EM PYTHON
CLARA NOBRE
WEB, REDES & PROGRAMAÇÃO EM PYTHON
GABRIELA FONSECA
WEB & STEGO
TIMES DE CTF
TEAM@CTF---->
EVENTOS E MODALIDADES
CAPTURETHEFLAG---->
JOGUE POR HOBBY OU SEJA CAMPEÃO NOS
EVENTOS
PRESENCIAIS/EVENTOS
CAPTURETHEFLAG--->
DISPUTAS/ONLINE ~
CTFTODAY---->
POR ONDE COMEÇAR?
CAPTURETHEFLAG--->
HTTP://CAPTF.COM/PRACTICE-CTF/
LET'S GO AND
SUBMIT THE
FLAG!
WHEREISTHEFLAG--->
#DESAFIO CODAMOS
CAPTURETHEFLAG--->
ACESSE: HTTP://104.233.105.35/NU/CODAMOS.HTML
ENCONTRE A FLAG E TWEET:
'HEY, @GAB__FONSECA' , A FLAG É --->'
PERGUNTAS?
CAPTURETHEFLAG--->
"FAÇA AMIGOS, MONTE UM TIME
E TENHA UMA VIDA SOCIAL."
- ARTHUR PAIXÃO
AND THE MOST IMPORTANT TIP OF ALL...
FLAG{OBRIGADO(A)}
GITHUB.COM/GABRIELAFONSECA
@GAB__FONSECA
AVAILABLEIN--->

Contenu connexe

Similaire à Programando e Capturando Bandeiras: Diferenciais em um Time de CTF!

NFT Marketplace Clone Script
NFT Marketplace Clone ScriptNFT Marketplace Clone Script
NFT Marketplace Clone ScriptNFTwiiz global
 
Trying and evaluating the new features of GlusterFS 3.5
Trying and evaluating the new features of GlusterFS 3.5Trying and evaluating the new features of GlusterFS 3.5
Trying and evaluating the new features of GlusterFS 3.5Keisuke Takahashi
 
Kauli SSPにおけるVyOSの導入事例
Kauli SSPにおけるVyOSの導入事例Kauli SSPにおけるVyOSの導入事例
Kauli SSPにおけるVyOSの導入事例Kazuhito Ohkawa
 
Life of PySpark - A tale of two environments
Life of PySpark - A tale of two environmentsLife of PySpark - A tale of two environments
Life of PySpark - A tale of two environmentsShankar M S
 
DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...
DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...
DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...Felipe Prado
 
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...sonjeku1
 
Playing 44CON CTF for fun and profit
Playing 44CON CTF for fun and profitPlaying 44CON CTF for fun and profit
Playing 44CON CTF for fun and profit44CON
 
Playing CTFs for Fun & Profit
Playing CTFs for Fun & ProfitPlaying CTFs for Fun & Profit
Playing CTFs for Fun & Profitimpdefined
 
ACI Multicast 구성 가이드
ACI Multicast 구성 가이드ACI Multicast 구성 가이드
ACI Multicast 구성 가이드Woo Hyung Choi
 
May2010 hex-core-opt
May2010 hex-core-optMay2010 hex-core-opt
May2010 hex-core-optJeff Larkin
 

Similaire à Programando e Capturando Bandeiras: Diferenciais em um Time de CTF! (12)

NFT Marketplace Clone Script
NFT Marketplace Clone ScriptNFT Marketplace Clone Script
NFT Marketplace Clone Script
 
Trying and evaluating the new features of GlusterFS 3.5
Trying and evaluating the new features of GlusterFS 3.5Trying and evaluating the new features of GlusterFS 3.5
Trying and evaluating the new features of GlusterFS 3.5
 
Kauli SSPにおけるVyOSの導入事例
Kauli SSPにおけるVyOSの導入事例Kauli SSPにおけるVyOSの導入事例
Kauli SSPにおけるVyOSの導入事例
 
Life of PySpark - A tale of two environments
Life of PySpark - A tale of two environmentsLife of PySpark - A tale of two environments
Life of PySpark - A tale of two environments
 
Intrusion Techniques
Intrusion TechniquesIntrusion Techniques
Intrusion Techniques
 
DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...
DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...
DEF CON 27 - GRICHTER - reverse engineering 4g hotspots for fun bugs net fina...
 
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
 
Playing 44CON CTF for fun and profit
Playing 44CON CTF for fun and profitPlaying 44CON CTF for fun and profit
Playing 44CON CTF for fun and profit
 
Playing CTFs for Fun & Profit
Playing CTFs for Fun & ProfitPlaying CTFs for Fun & Profit
Playing CTFs for Fun & Profit
 
ACI Multicast 구성 가이드
ACI Multicast 구성 가이드ACI Multicast 구성 가이드
ACI Multicast 구성 가이드
 
Samplab19
Samplab19Samplab19
Samplab19
 
May2010 hex-core-opt
May2010 hex-core-optMay2010 hex-core-opt
May2010 hex-core-opt
 

Dernier

How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...Wes McKinney
 
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxGenerative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxfnnc6jmgwh
 
Potential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsPotential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsRavi Sanghani
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Generative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfGenerative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfIngrid Airi González
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality AssuranceInflectra
 
Testing tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesTesting tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesKari Kakkonen
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Hiroshi SHIBATA
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch TuesdayIvanti
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentPim van der Noll
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
QCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesQCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesBernd Ruecker
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersNicole Novielli
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observabilityitnewsafrica
 

Dernier (20)

How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
 
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxGenerative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
 
Potential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsPotential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and Insights
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Generative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfGenerative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdf
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
 
Testing tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesTesting tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examples
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch Tuesday
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
QCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesQCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architectures
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software Developers
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
 

Programando e Capturando Bandeiras: Diferenciais em um Time de CTF!