ICT2215 Final CTF

Rules for the CTF

Mobile Security CTF

1. Scope: All attacks, scans and testing must be performed ONLY on the APK file provided. Do NOT target other students, personal devices, external websites, or SIT infrastructure.

2. Proctoring & Screen Sharing: EXAMENA must be ON for the entire CTF and your FULL SCREEN must be shared. Any attempt to disable, pause, or bypass the tool results in disqualification.

3. AI Usage: The use of AI tools is strictly NOT allowed. AI search, summaries, or copilots must not be run even on your local machines.

4. No Collaboration: This is an individual competition. No discussion or teamwork allowed.

5. No Sharing: Do NOT share flags, hints, or solutions until one hour after the CTF ends.

6. Platform Access: Do NOT access CTFd outside the official venue. No VPNs, proxies, or remote machines.

7. Prohibited Actions: Do NOT perform DoS/DDoS, brute-force attacks, modify/delete files, crash services, or attack the platform.

8. Allowed Tools: Standard security tools (Nmap, Burp Suite, SQLMap, Wireshark, etc.) and your own scripts are allowed.

10. Support: Contact the instructor ONLY for technical issues. No hints.

11. No Collaborative Tools and internet access: Do NOT access Notion, Obsidian, Google Docs, shared drives, or similar collaboration tools.

11. No Internet: Internet can be accessed only for accessing CTFd platform and enabling EXAMENA.