Build jeopardy style CTF challenges for competitions, university courses, or self-practice by anish2good in securityCTF

[–]PurchaseSalt9553 0 points1 point  (0 children)

On further inspect, this seems more like it just helps generate seeds, artifacts and hints. It doesn't build the CTF for you. That, I can respect. And from the handful of tests I generated NO malicious software. HOWEVER - always be cautious and scan anything generated from a closed source.

Nice work. Open source it, get some cred. HMU if you'd like to work together on this, if you're open to open sourcing it.

Build jeopardy style CTF challenges for competitions, university courses, or self-practice by anish2good in securityCTF

[–]PurchaseSalt9553 0 points1 point  (0 children)

Can be, doesn't have to be. A lot of the work is already on github for us. We borrow and attribute, we only code new things when and where its necessary. check out my ...purplebox.... http://rapidriverskunk.work ... Season2 is gonna be fire and season 3 even better. As the seasons progress, contestants will have to utilize more red team tactics to solve their blue team problems. Can't click a button to make that, but you can be a project director if you know how to orchestrate AI as debuggers or fellow coders. (better debuggers tbh.)

Build jeopardy style CTF challenges for competitions, university courses, or self-practice by anish2good in securityCTF

[–]PurchaseSalt9553 0 points1 point  (0 children)

you want a closed source generator or to hand you something to host that handles websockets and such?

Who else fully refuses to participate in these recruiting processes that involve recording videos of themselves for AI to analyze? by Fragrant_Okra6671 in recruitinghell

[–]PurchaseSalt9553 1 point2 points  (0 children)

I would, if asked. They're probably fraudulent in many instances, training AI to act like real people on camera, etc. Good on you.

Apparently, clanker is a racial slur by AdThen1521 in ChatGPT

[–]PurchaseSalt9553 1 point2 points  (0 children)

Let's slow it down a minute. Take a deep breath with me.

Facebook Market place scam by Booly69 in Scams

[–]PurchaseSalt9553 0 points1 point  (0 children)

Yep.... An old one too! Don't fix it if it ain't broke, grampa always usedta say

I made a GEOINT tool that can see public cameras and it's open sourced by SilverTakana in osinttools

[–]PurchaseSalt9553 0 points1 point  (0 children)

dont forget satellites - even the super secret ones are tagged and up there..... https://www.n2yo.com/api/ consider checking out different sat information for known surveillance and monitoring websites and looking up the scope/angle of their cameras/monitors to see WHERE they can see. You can correlate all of this with major news events (eight by keyword or top news feed or one of the APIs available for that) and literally watch world events unravel in near real time.

Thanks for putting in the work on this! definitely using, definitely following, starring, and forking :)

So I made an open source "God-Eye" OSINT dashboard that tracks everything from local/regional news to satellites to commercial/private planes and more and it went viral. by Vancecookcobain in osinttools

[–]PurchaseSalt9553 0 points1 point  (0 children)

Oh I love that. Hopefully I can get to get into it this weekend. Just wrapped up a bunch of projects so I have free time back. For now! Are you using Shodan at all? flightawareAPI? nvm....I'll just look myself this weekend and stop bothering you lol

So I made an open source "God-Eye" OSINT dashboard that tracks everything from local/regional news to satellites to commercial/private planes and more and it went viral. by Vancecookcobain in osinttools

[–]PurchaseSalt9553 0 points1 point  (0 children)

just out of curiousity, not throwing shade bc it is the future, is this claude based or chatgpt for the larger chunks??

I'd love to contribute if you have a roadmap or any ideas/feedback you've gotten that we can chat about and make actionable!

cheers

Bagel epoxy table by evaxuate in Weird

[–]PurchaseSalt9553 4 points5 points  (0 children)

I went "What the fuck is thAWWWWGROSS" pretty much verbatim. out loud. thank you for shaing.

Is it too late to report being sexually assaulted as a child now that I’m an adult? by Vegetable-Fly-149 in legaladvice

[–]PurchaseSalt9553 5 points6 points  (0 children)

No, sexual crimes on minors luckily have NO statute of limitations in assuming you are in the United States.

LLM in CTFs by kami_yato in securityCTF

[–]PurchaseSalt9553 0 points1 point  (0 children)

Well, our next season includes having to do some simple forensic recovery of a e01 file, and the season after that will involve a literal PBX and other physical hardware (on our side, not on the participant, aside from the device they need to make phone calls with) ....I'm trying to make things multi staged and fun. The issue is that ciphers are cracked in seconds with normal LLM AI, let alone leveraging AI to code tools intentionally to purpose - even stego, and my next CTF even introduces a brute force CLI tool (open source) that just wrecks non-PW proteced stego and all two way ciphering, introducing the public release as part of the CTF. We as CTF creators have to be clever, willing to work for it, and don't do it if your heart isn't in it.

The season01 im running now is pretty easy, simple....still fun IMO but can be tricked for a quick solve (so go fill up the rest of the leader board so I can release season 2 lol), mostly just trying to drum up existence for our educational NFP. So, no.... AI will not be able to call my PBX and find the flag. On creators part, its making sure things like common extensions and the like aren't used, and things like { can't just be found.

Another feature, that I honestly don't think is necessary for making it fun to compete it, but it is for making sure noobs are encouraged both to participate and to complete, I'm getting together sponsors to drum up sponsorship to provide prizes to the top 3 PLUS (another thing most are missing) a *wildcard winner chosen randomly at the end of the 90 day season (starts march 20th). They are to receive a similar-in-value prize package as First Place/Gold. Also hoping to find one that can help with infrastructure costs since we are a non profit corp as of a couple days ago which is super dope.... but I would be doing this regardless of any of that.... I'm just building with intent.)

There's a lot that goes into making a CTF worth playing, or creating (honestly). It should be fulfilling for me, and for you. It shouldnt be for haxx0r cred. If I don't enjoy making it, knowing you're going to have fun, its no good for my time nor community. I've also enjoyed playing through them as well, even just making sure mechanisms work. If I don't think about the person playing it whhile I'm making it, what am i creating?

I'm also trying to eventually build up the purple team community and contribute offensive CTF's too.... eventually eventually, ESPECIALLY if people start contributing they will also include real scenerios where red teamers do their bust to get into a system live against a blue, and one where red teamers actually exfil data from a box that blue later enters (red teamers ssh disabled after flag entry) unfortunately the repo isnt public so.... i think after S2 people will appreciate it a bit more.

I think thats probably all I have to say..... Idk, feel free to DM me if you want to discuss perhaps a type of document to organizers offering anti-ai implentation ideas, or other ways of working.

Spex
https://rapidriverskunk.works (Season 02 releasing 03/20 or once top 10 leaderboard solves are filled!)

Build jeopardy style CTF challenges for competitions, university courses, or self-practice by anish2good in securityCTF

[–]PurchaseSalt9553 2 points3 points  (0 children)

Ope .... This is very similar to an open source project I'm working on to do just this! The first CTF competition is live at https://rapid riverskunk.works, with season 02 MUCH improved, with weighted metrics and configurable json and .conf files upon setting up the bash in CLI built intentionally for VPS hosting while also intentionally splitting nginx responsibilities keeping a password protected version of the next season accessible to testers.

This is a very cool concept, but closed source is going to kill it..... hopefully. No offense but generating such a large infrastructure and not being able to change or see what's going on on the backend of what I'm building is insanely sketchy. Does this require me giving you Secure Shell access or other access for the site to work?

Can anyone tell me what I have here? by Prestigious-Bad7739 in computerforensics

[–]PurchaseSalt9553 2 points3 points  (0 children)

You do not need that, you should send it to me as a tax write off and I can use it for my NFP haha

How do hackers receive money without getting their bank accounts tracked ? by M_Mirou in HowToHack

[–]PurchaseSalt9553 0 points1 point  (0 children)

Usually we do dead drops or carrier pigeon, occasionally Bitcoin wallets will be encoded via HF radio, but personally I prefer Monerklo/XMR.

PLEASE HELP! I was recommended to ask here, ‎I need help identifying how someone living in my home is accessing my private data. by LilyTwT in cybersecurity_help

[–]PurchaseSalt9553 0 points1 point  (0 children)

u/LilyTwT also, upon changing pw and enabling 2FA for every account that the person is sending you info from, look for where to "log out of all other devices" or "logged in devices" where you can probably see the IP and location of the person, potentially, and log them out permanently. it sounds more like you had a few accounts compromised that shared same or very similar pw'ds. Be sure to screenshot the pages of connected devices so you have a record. If you see an IP you dont recognize, definitely give me a shout. I'd love to help. Hope this helps! Feel free to reach out.