CtrlAltCTF 2.0

Rules of Engagement

Safe. Legal. Controlled. Educational.

These Rules of Engagement define exactly which systems may be tested during CtrlAltCTF 2.0 and which activities are authorised.

⚠ Educational Purposes Only

CtrlAltCTF 2.0 is provided solely for education, awareness, training and professional development.

Cyber-security techniques must only be used against systems you own or systems for which you have explicit permission to test.

All activity during this event must remain within the authorised scope shown on this page.

🌐 Public Web Server

Only scanning, enumeration and challenge-related connections are permitted against the following target:

Authorised targetbsidesctf.ctrlaltcyber.co.uk

💻 Cyber Deck Range

Challenge activity is authorised only against the following local IP addresses:

Authorised IP range192.168.1.100 – 192.168.1.120

1. Authorisation

By participating in CtrlAltCTF 2.0, you agree to follow these Rules of Engagement.

Testing is authorised only against the systems and services explicitly identified as in scope.

Any activity outside the defined scope is unauthorised and may breach event rules, venue policy or applicable law.

🛑
When unsure whether an activity is permitted, stop and ask a CtrlAltCTF organiser before continuing.

2. Public Web Server Scope

Participants may conduct reconnaissance, enumeration and scanning against the public CtrlAltCTF web server.

Authorised public targetbsidesctf.ctrlaltcyber.co.uk

Permitted activities

  • Passive reconnaissance
  • DNS lookups
  • HTTP and HTTPS enumeration
  • Directory and file discovery
  • TCP port scanning
  • Service enumeration
  • Banner grabbing
  • Connecting to deliberately provided challenge services
  • Retrieving challenge flags

Restrictions

Participants must not attempt to compromise, modify, damage, disrupt or gain administrative access to the public web server.

Only scanning, enumeration and interaction with deliberate challenge services are authorised.

3. Cyber Deck Scope

Within the Cyber Deck range, scanning, enumeration and challenge-related exploitation are authorised only against the following IP addresses:

Authorised Cyber Deck range192.168.1.100 – 192.168.1.120

This scope includes every IP address from 192.168.1.100 through to 192.168.1.120.

All other IP addresses are out of scope unless a CtrlAltCTF organiser explicitly confirms otherwise.

🎯
Check the target range before running any automated tool. Broad subnet scans such as 192.168.1.0/24 are not authorised.

4. Out of Scope

The following systems and targets are not authorised:

  • Any Cyber Deck IP address outside 192.168.1.100 – 192.168.1.120
  • Any public website, IP address, domain or Internet host other than the authorised CtrlAltCTF target
  • BSides infrastructure
  • Venue infrastructure
  • Organiser infrastructure
  • CTFd administration and hosting infrastructure
  • Routers, switches and network-management systems
  • Wireless access points unless specifically identified in a challenge
  • Personal laptops, mobile phones, tablets or other attendee devices
  • Organiser devices
  • Third-party services linked from the CtrlAltCTF website
  • Any system that does not clearly form part of a published challenge

5. Prohibited Activities

The following activities are strictly prohibited:

  • Denial-of-Service or Distributed Denial-of-Service attacks
  • Traffic flooding or excessive automated requests
  • Disrupting services used by other participants
  • Attacking the CTF platform, scoreboard or administration panel
  • Attacking another participant's device or account
  • Social engineering or phishing
  • Deploying malware, ransomware or destructive software
  • Creating persistence mechanisms
  • Destroying, deleting or modifying shared challenge data
  • Changing passwords to prevent access by other participants
  • Stealing flags, credentials or answers from another participant
  • Brute-force or password-spraying activity unless explicitly required by a challenge
  • Privilege escalation against event infrastructure unless explicitly required by a published challenge
  • Attempting to bypass, weaken or interfere with these Rules of Engagement

6. Participant Conduct

All participants are expected to:

  • Act responsibly and respectfully
  • Use only the authorised targets
  • Check scan ranges before running automated tools
  • Avoid disrupting another participant's experience
  • Complete challenges using their own skills and tools
  • Report accidental out-of-scope discoveries to an organiser
  • Stop immediately when instructed by event staff
  • Ask an organiser when unsure whether an activity is permitted

7. Accidental Discoveries

If you discover a vulnerability, credential, personal record or sensitive system that does not appear to be part of a CtrlAltCTF challenge:

  • Stop testing immediately
  • Do not access the system further
  • Do not download, copy, modify or share the information
  • Record only the minimum information required to explain the discovery
  • Report the discovery privately to a CtrlAltCTF organiser

8. Educational Purpose

CtrlAltCTF 2.0 exists solely to improve cyber-security awareness, defensive knowledge, ethical-hacking skills and practical technical experience.

The event does not authorise participants to use these techniques against systems outside the stated scope.

Skills learned through this event must only be applied legally, responsibly and with explicit permission.

9. Participant Responsibility

Participants remain responsible for their own actions and for ensuring their tools remain inside the authorised scope.

Activity outside the defined scope is not authorised by CtrlAltCTF, its organisers, BSides, the venue or event partners.

Event staff may ask a participant to stop an activity or leave the CTF environment if these rules are not followed.

By taking part in CtrlAltCTF 2.0, you confirm that you have read, understood and agreed to follow these Rules of Engagement.
Hack the challenge, not the infrastructure.
CtrlAltCTF 2.0  •  Education  •  Authorised Testing  •  Responsible Security