Exploit › Module 7 › Lesson 3
Rules of CTF
CTF rules literacy — scope, time box, no infra attack, team ethics; pwn awareness on platforms you enroll in.
Visual · t24_rules_of_ctf
CTF rules = platform RoE. Original Cyberlium.
Opening
CTF rules exist so learning stays legal — breaking them turns practice into incident response for the organizers.
CTF rules of engagement: compete only on assigned challenge infra, respect time windows, no attacking scoreboard or other teams, no sharing live flags when forbidden, no DoS on challenge servers, no using skills on non-CTF targets afterward as excuse. Pwn-specific: use provided VPN/bastion, do not port-scan campus outside scope, report accidental out-of-scope touch to organizers. Cyberlium teaches rules literacy before any advanced authorized pwn track — YOUR $PWN_LAB mirrors rules with instructor brief as RoE. Refused: 'CTF practice' on employer network, cheating by flag paste, attacking CTF platform to steal flags. Document rules acknowledgment in chmod 600 notes before team events.
1. Core CTF rules
Stay in scope: challenge IPs/hostnames only. No lateral movement to organizer corp net.
Collaborate per team rules; cite sources; no plagiarism in writeups.
Command guide
Try these commands — Core CTF rules
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
pwn.college rules — https://pwn.college/ (authorization + scope) CWE responsible use — https://cwe.mitre.org/ (classification, not attack) Microsoft SDL — https://learn.microsoft.com/en-us/security/sdl/ (ethical boundary)
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
export LAB_PWN=${LAB_PWN:-$HOME/cyberlium-lab/t24-pwn}
cat > "$LAB_PWN/notes/ctf-rules.txt" <<'EOF'
CTF pwn rules (literacy):
- only authorized platforms (pwn.college / your CTF scope)
- never aim techniques at strangers/production
- this cyberlium lab: YOUR gcc toys + docs — no live exploit chains
EOFCommand — copy this
grep -E 'authorized|never|YOUR' "$LAB_PWN/notes/ctf-rules.txt" curl -sS https://pwn.college/ | head -5 grep never "$LAB_PWN/roe.txt"
Primary tools to practice this lesson: grep, curl. Reference sites: pwn.college rules (https://pwn.college/); CWE responsible use (https://cwe.mitre.org/); Microsoft SDL (https://learn.microsoft.com/en-us/security/sdl/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Pwn-specific etiquette
Do not crash shared challenge infra intentionally beyond brief — report unstable service.
Local $PWN_LAB practice before firing scripts at remote — even in CTF, be deliberate.
3. After CTF
Skills feed defensive reporting and secure coding — not unauthorized prod pwn.
Writeups after deadline per policy; redact infra details.
4. What you ship: CTF rules checklist
Eight rules + pwn etiquette trio + post-CTF ethics line.
5. What you record before the next lesson
CTF rules checklist path.
6. Wrong vs right: weaponized exploits vs memory-safety literacy
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Port-scan entire university during pwn CTF 'for recon.'
Right
CTF rules checklist signed. Next: CTF Lab.
Mission: CTF rules checklist
1) List eight CTF scope rules. 2) Write three pwn etiquette items. 3) Draft rules acknowledgment for team. 4) Post-CTF unauthorized-use refuse line.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “Accidental out-of-scope touch — report how?”
Knowledge Check
APPLY: CTF rules require:
Multiple choice
Knowledge Check
APPLY: True or False: CTF skills justify prod pwn without authorization.
True or False
Knowledge Check
APPLY: Pwn CTF etiquette includes:
Multiple choice