Contest Results
Here are the results from DEF CON Contests That Have been submitted so far. We're still gathering results so stay tuned for more. Contests marked with an asterisk * were Black Badge contests this year!
Contact [email protected] with updates!
?Cube*
The ?Cube results:
1. megadoomer (53% - 21 flags, last submitted at 18:25:04 GMT)
2. TheMisfits (53% - 21 flags, last submitted at 18:27:46 GMT)
3. megagoobers (35% - 14 flags)
4. redhataugust (10% - 4 flags)
Megadoomer is the reigning champ (2x winner of the ?Cube). Currently undefeated...
5n4ck3y
Notable Things RE Our Contest This Year...
First Place : Lukash with 1469 Points (nice)
CTF Participants Registered - 1067
CTF Participants Verified by 5n4ck3y - 948
CTF Prize - Solve any 5 of the 15 challenges and get an AND!XOR HackBoi badge which plays DooM
Photos of interest...
AND!XOR Network Operations Center - Break Glass LVCC Potato Net Mitigation
Best Dressed CTF Participant -
Adversary Wars CTF
Team 1: Phreaks 2600
Team 2: USF CyberHerd
Team 3: eXcel
Beverage Cooling Contraption Contest
Here are the findings of the 20th BCCC people's politburo annual convention.
1st place Eutectic Point with a time of 59 seconds, a temperature delta of 68.9 degrees and a score of 107
Second place is Ice stomp with a time of 61 seconds, a temperature delta of 73.5 degrees and a score of 88
And third place is Q Bros with a time of 50.7 seconds, a temperature delta of 54.9 for a final score of 83
BIC CTF
Top three teams were:
3. PyramidofPwn
2. Ov3rw4tch
1. StrawHatPirates
Biohacking Village CTF
Numbers of participants and Teams:
Users: 142
Teams: 66
Submissions:
3649 right submissions (32%)
7723 wrong submissions(68%)
27 Support tickets created and handled by the CTF Support
14 People including me and Shadow that have worked as CTF Support during DEFCON32.
TOP 5 Teams:
1 Horsemen of the Medpocolypse 10447 2 Ostrich Lab 10290 3 idontknowwhat 7525 4 do-not-reboot 7129 5 TheMythologist 6309
Out of 13182 total possible points.
Scoreboard: https://ctf.villageb.io/scoreboard
Blue Team Village Contests
+ BTV CTF: https://ctf.blueteamvillage.org/docs/stats
**1st Place**:
Def con dans mison
GhidraGoons
**2nd Place**:
N1t3_Tr@1n
**3rd Place**:
Slept4Day
BTV Venator Aurum Puzzle:
Artemis: 4,350
Sometimes cake: 4,300
capnpwn: 3,950
Capture The Flag *
1ST – MAPLE MALLARD MAGISTRATES (5943)
2ND – BLUE WATER (5090)
3RD – SUPERDICECODE (3720)
Cloud Village CTF
We had a fantastic time this year with our Cloud Village CTF events, which embraced a fantasy and magic theme that perfectly aligned with DEFCON's theme of "Engage." Our goal was to immerse participants in a captivating experience that encouraged active involvement and exploration.
We hosted over 25 exciting challenges across four different cloud service providers, and we're pleased to share the highlights from these contests.
**Cloud-Village CTF**
- Total Registered Players: 374
- Total Registered Teams: 215
- Total Points Achievable: 14690
**Winning Teams:**
1.ierae - 11930
2.die_trying - 8550
3.murphy'sL@w - 7720
Total Submissions - 1789
Total Teams Registered - 215
Total Users Registered - 374
CMD+CTRL
1st - Savage Submarine
2nd - ierae
3rd - Mountain Monk
Crack Me If You Can
Our contest is split into two brackets, Pro category and Street.
In Pro, HashMob had a narrow victory over hashcat, with Cynosure Prime
taking third.
In Street, ThatOnePasswordWas40Passwords dominated.
First time in years that hashcat has been knocked off of the top spot!
We had 35 teams compete, which may be a new record.
This year's data sets included a lot of nested puzzles - user passwords
that once cracked could also open encrypted files or archives, which
then contained hints and other information that would aid in cracking
more, higher-point-value user passwords. We got everything from
encrypted Arj to Zip, and a range of password hash algorithms including
ones made up for the contest that teams had to reverse-engineer or work
off of spotty hints in notes they recovered.
Crash and Compile*
Of the 49 teams that registered we had six***** teams complete all three stages of the qualification round. From there nine teams moved on to the main contest.
1st - 500pts - hakk og spaghetti
2nd - 463pts - Cabbache
3rd - 435pts - Coreys
Darknet-NG
Third Place winner
Nuvious
Second Place winner
Feath3rs
First Place winner
FulcrumFoundry
DEF CON's Next Top Threat Model (DCNTTM)
First: lovely dreamer
Second: Deeze
DEF CON MUD
Feath3rz won and received a human badge Thursday
DEF CON Scavenger Hunt*
bannanrchy, 143 points
regenerate 1, 118 points
deegenaret5, 103 points
Embedded Systems Village CTF*
Winners are: Flowers by Irene
Close runners up are: BYUpwny
Game Hacking CTF
Good game hacker badge winners and top 3 game hacker teams.
1. Cade
2. We made them dot org
3. Py-lingual
It was a close race to the very end. Thanks to everyone who came by to hack some games. GG.
GEOSINT
This tournament-style contest had participants identify locations based on images provided. Beginner friendly. A total of 70 partipants played over 2 days.
Day 1 Top Scores: 19689, 19680
Day 2 Top Scores: 19980, 19960
Winners:
Day 1 Winner: Q and Decline
Day 2 Winner: guy
Hac-Man
Hello! I)ruid here from the Hac-Man Challenge. Here's our Top 10 Winners:
1st CyberMonk3y 4492 2nd Carixo 4475 3rd shirajuki 4463 4th eirik 4462 5th anan 4421 6th Errorgone 4365 7th bittwize 4201 8th 5ud0 4182 9th Claudus 3819 10th Eagal_Eater 3719
You also asked for interesting things that happened, for the first time
in 3 years someone figured out that they can script the UI to do things
like automatically eat the fruit when it re-spawns and maximize their
points collection.
We also got a really cool homemade "Green Book of Green Things"
scavenger hunt item turned in by Claudus. It was very obviously made
with care and love just for us so an extra shout-out for that turn-in.
Hack3r Runw@y
The 4 categories were each awarded $75 Amazon gift card. The People's Choice 1st place got the trophy and flask. 2nd prize was the light up crochet tote with defcon logo. 3rd Prize was a 3d printed clutch
Digital Wearable - Divintrio's Constellation Suit
Smart Wearable - Gabi's Party Jacket
Anesthetics - Melanie's Beaded Hacker Barbie Pin
Functional Wear - S34MSTR3SS's Mad Hacker Hat
People's choice - 1st Place Divintrio's Constellation Suit
PC 2nd Place - Gabi's Party Jacket
PC 3rd Place - Jess's Arc Reactor
Thanks to the audience, the contestants and judges who helped make this a wonderful event. Please continue to spread the word about the contest so we can have more participants next year
HackFortress
reetings contest leads, HackFortress's winners are Team MvM
Players:
bradan
mixy1
Trixter
Ling
vishiswoz
<|°_°|>
kroot
Sanduuz
szymex
pilvar
Ham Radio Exams
328 Applicants tested
143 Exams passed
115 New amateurs !!
Ham Radio Fox Hunt
1st Orion
2nd Jaywalker
3rd TheKGBSpy
Goons were amazing foxes. C&E goons especially had an amazing being stationary foxes, shoutout to HeathenHacker, Secove, and various C&E goons
ICS Village CTF
Hey folks, we had 105 members participate ..
First time for me using Hack The Box instead of CTFd so bare with me...
Top 3
apt install MTSI
Vigilantes DC32
SkinnyRD
#1 was locked in the lead since yesterday but 2nd place was down to the wire at the end -- Vigilantes pulled ahead for second place this morning.
Contestants had to complete virtual challenges hosted by HtB as well as physical challenges in the village such as stopping wind turbines, writing ladder logic configs, restoring hacktopia (compromised water HMI), forensics of a compromised network, navigating a ship with the bridge simulator, and learning to play war games (red v blue ship challenge).
We gave 1st prize the ICS Village badge (Whaletale) as well as the Free WiLI
2nd place prize was the ICS Village badge (Whaletale)
3rd place was a box of Trolli's sour gummy worms (leftovers from the DC NextGen prizes)
Live Recon
Participants engaged in live reconnaissance of selected and pre-registered companies. Despite the targets being well-known for their active bug bounty programs, the findings were impressive. Teams found it extremely difficult and the findings were mind-boggling. Here are some stats:
• Total Teams: 46
• Total Players: 85
• Targets: Prominent orgs with active bug bounty programs
• Assets Discovered: 23k+
• Vulnerabilities Detected: 150
• Breach Leak Data Identified: 15+
1st Prize Winner: Pinja
2nd Prize Winners: NFN
Lonely Hard Drive
For this year's Lonely Hard Drive, we seeded 1000 USB drives in the form of a lost Employee RFID Badge through the LVCC space.
Out of the drives picked up, 96 teams contacted back to us and joined the leaderboard.
The top teams for this year (out of a possible 21 flags and bonus flags):
| | |
|---|---|
| Team Name | Score |
| {DFEND} imateam | 19|
| R0ckSt@rz | 13 |
| CyberChallenged | 11 |
The winning team was able to clear the final challenge and rescue Betty from the lockbox, claiming the top spot for this year.
Out of the drives we hid around the LVCC space, only a few were returned to Lost and Found and LVCC staff.
3 drives were returned due to being suspicious and were destroyed.
We did not know that Malcore Group was also leaving USB Drives that contained malware this year, prompting an alert to be sent to our players.
There were a number of returning teams who played last year that were excited that it was happening again.
MARC I & BOMBE
# MARC I:
Henry Trochlil & Luke Janoschka
https://drive.google.com/file/d/1dktyHjMvHalGGgmZr2oogaOhsYcEqszx/view?usp=sharing
MARC-I_Report_Anubis.pdf
# BOMBE:
Stats:
Total Registered Player: 65
Uploaded Malwares: 25
Uploaded EDR: 18
Winner:
1. cknight
2. Zeze
3. N04$urPr123d
Octopus Game*
Winners:
1. First Place: Greg
2. Second Place: Gillian
3. Third Place: Salty Storm
4. Forth Place: Cameron
Octopus Game engaged participants in a pirate-themed quest to discover DefCon through new eyes. In keeping with Squid Game, but with less violence, players are faced with *****ren's games that unlock a quest, presented through the lost log book of Captain Avalon Corsair. Faced with cyphers, encoding, and riddles, players identify a location to scout (one of the wonderful villages at this event) and report back to attain points. Of the 120 competitors who accepted the challenge, 16 completed all tasks. To break the final tie, players faced their toughest competition of the weekend, Simon Says. With the humble support of BlackGirlsHack and Women's Society of Cyberjutsu, we were able to give away 4 Comptia exam vouchers, 2 Tryhackme vouchers, and one CTA course (Cyberjutsu), as well as hundreds of dollars worth of legos, lockpicks, and swag.
Phreakme CTF*
Winner: Psychoholics - Winner wins two black PhreakMe badges (a red/blue box)
Second Place: Chaz - Wins one black PhreakMe badge
Third Place: Kataze - Wins a blue PhreakMe Badge Kit
Five teams completed the CTF, the other teams were kataze, NIC and sysop.
Sysop completed the contest the fastest, doing everything in 5 hours. We're also going to give him a black badge
Interesting Info:
117 people couldn't figure out how to use the payphones (they put a quarter in and couldn't figure out how to dial a phone number)
We had 81 unique callers in to the challenge,
Total IVR flag attempts over 3 days: 3,356
591 IVR Voicemail Pin Guesses
5 Successful Caller ID Spoofings
Pinball High Score Contest
The winner of the DEFCON HIGH Score contest is EmanWeb! (Manny).
Recon Village Contests
**Live Recon:**
Participants engaged in live reconnaissance of selected and pre-registered companies. Despite the targets being well-known for their active bug bounty programs, the findings were impressive. Teams found it extremely difficult and the findings were mind-boggling. Here are some stats:
• Total Teams: 46
• Total Players: 85
• Targets: Prominent orgs with active bug bounty programs
• Assets Discovered: 23k+
• Vulnerabilities Detected: 150
• Breach Leak Data Identified: 15+
**1st Prize Winner: Pinja
2nd Prize Winners: NFN**
_________________________________________________________________
**GEOSINT:**
This tournament-style contest had participants identify locations based on images provided. Beginner friendly. A total of 70 partipants played over 2 days.
Day 1 Top Scores: 19689, 19680
Day 2 Top Scores: 19980, 19960
**Winners:**
**Day 1 Winner: Q and Decline
Day 2 Winner: guy**
Red Alert ICS CTF*
Rank Team Name Points 1 Tesuji 2600 2 NoobTube 1900 3 coridor_crew 1400 3 $RIP 1400 3 Rupertscape 1400
Total of 62 Teams. Joint 3rd place shared by 3 teams.
Red Team Village CTF
**CTF Scoreboard**
**CTF Metrics
**
**The Winners**
Team **EPT** won the CTF by solving all the challenges first.
Red Team Village RedTeam Rumble
- 4 teams / 24 participants / 33 Prizes awarded
- 2 Separate Battles with distinct winners
Round 1:
- 3600 total points earned - 28 points / min average
- 14512 total checks performed - 5125 successful / 10388 failed
Round 2:
- 5760 total points earned - 38 points / min average
- 57086 total checks performed - 10388 successful / 46698 failed
- 6 re-roll requests DENIED, 1 re-roll request APPROVED
spyVspy
In the end, after two solid days of stiff competition, team CaMeLcAsE
emerged victorious.
Telechallenge
Number of calls to our infoline: 183
Number of hackers who listened to the entire TeleChallenge tutorial: 1
Longest session listening to our PBX numbers station: 17 minutes
Hacker Cooling Contraption Challenge Winners And Stats:
Winner: The Little Guy (age 11)
9.7 / 9.3 / 8.8 (9.26 average)
Strongest for: Efficacy
2nd place: ***** MC
8.1 / 9.2 / 8.8
Strongest for: Creativity
3rd place: Tech wizard
8.5 / 8.3 / 9.1 (8.63 average)
Strongest for: Flair (one spell cast)
Wall of Bribes
First Place: **Kaz**, who among other things, bribed with a T-shirt that read "Bribe me like Epstien's Guards" and resulted in an overwhelming community request wanting to buy it
In exchange for a detailed list of new contest rules that were drafted with legal assistance, and continuing to bribe on others behalf in order to provide Lonely HDs to new attendees, and help with other bribes. He made a huge impact on the community with his hard work, his research into the philosophy of what "value" means, and his dedication.
Second place: **maggiefero**, who bribed us with a collection of Taco Bell condiment packs from four different states that when put in the correct order produces a poem.
In exchange for us to change our scoring rubric for wall of bribes, which ultimately heavily impacted the scoring process and reversed other people's bribed rule changes.
Third place: **Pascal-0x90**, who bribed us with the Gold Bug contest slippers and deck of cards.
In exchange for putting them in last place, but to move up for every new bribe submitted afterwards by other players. It was the first (very clever) rule change and ultimately helped out the Gold Bug contest as well.
Stuff that happened during this chaotic hurricane of a contest:
Notes and observations:
Bribes were accepted from 10AM to 6PM on Friday and Saturday, with at 66 items received and recorded
About 36 people bribed for a Lonely Hard Drive
at least 30% of people bribed to take some other bribe from the wall
Most bribes focused to the Black Badge Raffle TCG (BBRTCG) after we were given a few packs
For 3 BBRTCG cards, we were bribed a PCI 2.2 Killer Network Ethernet card from an estate where a murder had occurred, the card is presumed to be haunted
Ten people bribed to change the rules of the Wall of Bribe contest
A number of people attempted to bribe for information on unrelated contests at DEFCON (Fox Hunt, Scav, etc.)
Roughly 15% of bribes were rejected including but not limited to; a lap dance, THC edibles, a date, emotional "experiences", hugs, and so on
It was clear the community did not fully understand the differences between Bribes, Blackmail, Pawning, and Stealing
Two unrelated players at difference times both bribed with Woodford Reserve Whiskey
Stickers were the most common items given as bribes, with 54 unique stickers taken in
A list of items from the bribery offers:
Wall of Bribes - Bribe Offers:
Marble Puzzle with velvet bag locked inside
Radware power to USB travel adapter
Altered Security Mug
3D printed Peener Whistle
6TB HD with rainbow tables from DDV
Knock off Raspberry pie from 2018
Model Railroader Craftsmen from July 1986 featuring Boston MIT's layout
Set of lockpicks
DEFCON 30 Human Badge
A stressed out stress ball
Textured tension wrench for lockpicking
Instructions on How to Lockpick
D&D Lockpicking Prop
Killer Network card for PCI 2.2
3 Pictures of feet (provided by owner of said feet)
T-Shirt with printed "BRIBE ME LIKE EPSTIEN'S GUARDS" with Epstein misspelled
T-shirt depicting Julius Caesar's murder by a crowd wearing DEFCON shirts
Other T-Shirts of various quality related to bribing
Sunglasses clearly from AliExpress
Can of Arizona Ice Tea
Various rubber ducks
Oreos
Bottle of water
Several 3D printed Cap'n Crunch whistles
Threatened to black mail a fictional character
Omega Mart employee Boop Badge
Attempted black mail of the contest lead, not fictional
Watercolor painting of Alexis Park
Gold Bug Flip Flops
4 Million in Ducky Bucks
Floppy Disk written on with a quote from the movie Hackers, signed
Various Challenge Coins
Various Stickers
2 bottles of Woodford Reserve Whiskey
4 pairs of socks
Hacker and Nerd themed jewelry
Phone Phreak device
Barcode scanner in a Wired "What's Next" game box
Assortment of ancient keys
Raspberry Pi 5 8GB
Dice Set
Roll of anti-tamper tape
Crocheted Dickbutt
Several unassembled SAOs
Various Patches
Hand made leather carry case
Notebook decorated with stickers
DEFCON Black Badge Raffle TCG cards
Inflatable pool toy of a tire
Hand towel supporting breast cancer
Tinfoil hat
Tinfoil flipflop
14 condiment packs from Taco Bell that can assemble into a poem
Counterfeit US currency
Old cardboard box of RFID cards
different USB drives containing various digital material
Coin with *****y dragon
A video of a "magic" trick, and the "magic" card (5 of Hearts)
Lots of chocolates and candy
A lap dance (rejected by a shy judge)
Various pieces of trash
Social Engineering shirt that had "Production Crew" printed on the back
A free demo of shoplifting from the wall of bribes pile, then returning it (its was just a prank, bro)
Mardi Gras beads from a *****, who claimed they the beads had special powers in New Orleans