24 hours. One board.

A jeopardy capture the flag, run online and onsite on a college campus in Roorkee, Uttarakhand.

  • 400+ hackers
  • 25+ countries
  • 28 challenges
  • 9 categories
  • 20.17 ctftime weight

scroll to descend into the night

The rule / 25 Nov 2022 / 04:30 UTC

NECTF{find_the_string}

Every challenge hides one string. A website, a binary, a photograph, a packet of ciphertext. Find it, paste it, take the points.

That is the whole game.

The board / all 28

Open one.

points
opened
0 / 0

Overnight / the letter

One PDF ate the night.

White text on white paper, hiding an MD5. Two decoy strings planted in the metadata, which worked far better than we intended.

It closed as the most expensive challenge on the board.

383

final value, from a flat 30

Final hour / the correction

We shipped a fix with sixty minutes left.

Knock Knock was authored with XOR where the puzzle called for XNOR. Everyone holding the near miss answer was right about the method and wrong about one gate.

Our authors were not consistently reachable on Discord before that.

Both of those are on us.

Now / what is left

The domain did not survive. Some challenges did.

noescape.live stopped resolving. So did the box that served the pwn and crypto sockets. Heroku killed its free dynos weeks after we closed.

But 4 of the original targets still answer. The Firebase challenges are live right now, robots.txt and all. You can go solve them tonight.

    Next / not scheduled

    v1 was the on-ramp. v2 is the building.

    The first one was easy to low-medium by design, so nobody would bounce. It worked, and it is not what we want to run next.

    v2 is a full hacking suite. Multi-stage chains, real infrastructure to move through, challenges that assume you already own a methodology.

    It is not on the calendar. The waitlist decides whether it gets built.

    26 Nov 2022 / 04:30 UTC / board closed

    NECTF{see_you_in_v2}