Slide 1

Slide 1 text

CTF 2021/ hi120ki

Slide 2

Slide 2 text

@hi120ki CTF Wani Hackase Web Reversing 2 WaniCTF ( ) SECCON Beginners CTF 2021 ( ) WaniCTF 2020 WaniCTF 21-spring WaniCTF 2021

Slide 3

Slide 3 text

WaniCTF 3 CTF 300

Slide 4

Slide 4 text

CTF CTF ! Q&A 4

Slide 5

Slide 5 text

CTF 5 Jeopardy Attack & Defense King of the Hill 頻

Slide 6

Slide 6 text

CTF 6 & etc...

Slide 7

Slide 7 text

CTF 7 & + ⾒ Discord Twitter

Slide 8

Slide 8 text

8 + OK Docker Docker Compose OSS

Slide 9

Slide 9 text

9 CTF

Slide 10

Slide 10 text

1 • • • • • Writeup • • 10

Slide 11

Slide 11 text

2 • • & • 頻 • • • + & • 0 11

Slide 12

Slide 12 text

12 Styled memo (WaniCTF 2021) Django Web PostgreSQL Redis +

Slide 13

Slide 13 text

13 CTF

Slide 14

Slide 14 text

14 CTF

Slide 15

Slide 15 text

- 15 ( RCE )

Slide 16

Slide 16 text

16 - WaniCTF 2 ( ) ( )

Slide 17

Slide 17 text

- 17 OSS (1) CTFd https://github.com/CTFd/CTFd

Slide 18

Slide 18 text

- 18 OSS (2) rCTF https://github.com/redpwn/rctf CTFd

Slide 19

Slide 19 text

19 - GitHub ⾒ Slack prometheus exporter

Slide 20

Slide 20 text

20 - 1 : ( CTFd )

Slide 21

Slide 21 text

- 21 WaniCTFd k6

Slide 22

Slide 22 text

22

Slide 23

Slide 23 text

23

Slide 24

Slide 24 text

24

Slide 25

Slide 25 text

25 WaniCTF CPU

Slide 26

Slide 26 text

26 WaniCTF CPU

Slide 27

Slide 27 text

27 WaniCTF CPU

Slide 28

Slide 28 text

28 & https://github.com/wani-hackase/wanictf2021-writeup/blob/main/web/traversal/checker/web_traversal.py

Slide 29

Slide 29 text

29 ( )

Slide 30

Slide 30 text

30

Slide 31

Slide 31 text

31 Q&A

Slide 32

Slide 32 text

Q&A ? 32 (2 ) : EC2 t2.small, RDS t2.micro (5 ) : EC2 t2.medium x3 (10 ) : EC2 t2.medium & t2.small + 4

Slide 33

Slide 33 text

Q&A ? 33 2 : ( ) 2~3 : HP Twittrer&Discord 1 : ( 2 ) ~ : :

Slide 34

Slide 34 text

Q&A ( ) 34 HTTPS SSL ( https://crt.sh/) Discord CTF SSL Caddy CTF (e.g. Discord )

Slide 35

Slide 35 text

Q&A 35

Slide 36

Slide 36 text

Q&A 36 CTF + SRE ( )

Slide 37

Slide 37 text

CTF ~ ~ 頻

Slide 38

Slide 38 text

38 WaniCTF 2021 https://hi120ki.github.io/blog/posts/20211109/ WaniCTF https://wanictf.org/