Rules of Engagement
These Rules of Engagement define exactly which systems may be tested during CtrlAltCTF 2.0 and which activities are authorised.
⚠ Educational Purposes Only
CtrlAltCTF 2.0 is provided solely for education, awareness, training and professional development.
Cyber-security techniques must only be used against systems you own or systems for which you have explicit permission to test.
All activity during this event must remain within the authorised scope shown on this page.
🌐 Public Web Server
Only scanning, enumeration and challenge-related connections are permitted against the following target:
💻 Cyber Deck Range
Challenge activity is authorised only against the following local IP addresses:
1. Authorisation
By participating in CtrlAltCTF 2.0, you agree to follow these Rules of Engagement.
Testing is authorised only against the systems and services explicitly identified as in scope.
Any activity outside the defined scope is unauthorised and may breach event rules, venue policy or applicable law.
2. Public Web Server Scope
Participants may conduct reconnaissance, enumeration and scanning against the public CtrlAltCTF web server.
Permitted activities
- Passive reconnaissance
- DNS lookups
- HTTP and HTTPS enumeration
- Directory and file discovery
- TCP port scanning
- Service enumeration
- Banner grabbing
- Connecting to deliberately provided challenge services
- Retrieving challenge flags
Restrictions
Participants must not attempt to compromise, modify, damage, disrupt or gain administrative access to the public web server.
Only scanning, enumeration and interaction with deliberate challenge services are authorised.
3. Cyber Deck Scope
Within the Cyber Deck range, scanning, enumeration and challenge-related exploitation are authorised only against the following IP addresses:
This scope includes every IP address from 192.168.1.100 through to 192.168.1.120.
All other IP addresses are out of scope unless a CtrlAltCTF organiser explicitly confirms otherwise.
192.168.1.0/24 are not authorised.4. Out of Scope
The following systems and targets are not authorised:
- Any Cyber Deck IP address outside
192.168.1.100 – 192.168.1.120 - Any public website, IP address, domain or Internet host other than the authorised CtrlAltCTF target
- BSides infrastructure
- Venue infrastructure
- Organiser infrastructure
- CTFd administration and hosting infrastructure
- Routers, switches and network-management systems
- Wireless access points unless specifically identified in a challenge
- Personal laptops, mobile phones, tablets or other attendee devices
- Organiser devices
- Third-party services linked from the CtrlAltCTF website
- Any system that does not clearly form part of a published challenge
5. Prohibited Activities
The following activities are strictly prohibited:
- Denial-of-Service or Distributed Denial-of-Service attacks
- Traffic flooding or excessive automated requests
- Disrupting services used by other participants
- Attacking the CTF platform, scoreboard or administration panel
- Attacking another participant's device or account
- Social engineering or phishing
- Deploying malware, ransomware or destructive software
- Creating persistence mechanisms
- Destroying, deleting or modifying shared challenge data
- Changing passwords to prevent access by other participants
- Stealing flags, credentials or answers from another participant
- Brute-force or password-spraying activity unless explicitly required by a challenge
- Privilege escalation against event infrastructure unless explicitly required by a published challenge
- Attempting to bypass, weaken or interfere with these Rules of Engagement
6. Participant Conduct
All participants are expected to:
- Act responsibly and respectfully
- Use only the authorised targets
- Check scan ranges before running automated tools
- Avoid disrupting another participant's experience
- Complete challenges using their own skills and tools
- Report accidental out-of-scope discoveries to an organiser
- Stop immediately when instructed by event staff
- Ask an organiser when unsure whether an activity is permitted
7. Accidental Discoveries
If you discover a vulnerability, credential, personal record or sensitive system that does not appear to be part of a CtrlAltCTF challenge:
- Stop testing immediately
- Do not access the system further
- Do not download, copy, modify or share the information
- Record only the minimum information required to explain the discovery
- Report the discovery privately to a CtrlAltCTF organiser
8. Educational Purpose
CtrlAltCTF 2.0 exists solely to improve cyber-security awareness, defensive knowledge, ethical-hacking skills and practical technical experience.
The event does not authorise participants to use these techniques against systems outside the stated scope.
Skills learned through this event must only be applied legally, responsibly and with explicit permission.
9. Participant Responsibility
Participants remain responsible for their own actions and for ensuring their tools remain inside the authorised scope.
Activity outside the defined scope is not authorised by CtrlAltCTF, its organisers, BSides, the venue or event partners.
Event staff may ask a participant to stop an activity or leave the CTF environment if these rules are not followed.