Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 37 guests and 1 member online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Capture The Flag in High Schools
EH-Net
May 18, 2013, 08:42:47 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Capture The Flag in High Schools
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Capture The Flag in High Schools (Read 10136 times)
0 Members and 1 Guest are viewing this topic.
H1t M0nk3y
Hero Member
Offline
Posts: 864
Capture The Flag in High Schools
«
on:
May 11, 2010, 07:26:05 AM »
Hey,
I would really like to start a competition in the high schools around where I live. I have been a teacher years ago and I also did some volunteer work in on high school, etc.
I think teenagers interested in InfoSec are often left learning tools by themselves and if not guided properly, can start hacking networks everywhere without permissions...
Finally, I am a French Canadian and there is close to no resource in French in this field.
So, I would like to create some kind of a club among different high schools in my city where we could meet once a month or something like that and organize a CTF among them. I really, really want to focus on the legal aspect of it. I want them to be White Hats, not the opposite...
Do you guys think it would be a good idea? Have anyone done that before?
Thanks for your advice!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
hayabusa
Hero Member
Offline
Posts: 1630
Re: Capture The Flag in High Schools
«
Reply #1 on:
May 11, 2010, 07:58:08 AM »
I think it's a very interesting idea. I'd considered something similar around here at one point, and had even thought of using it to prep some of the local 'infosec-interested' students towards the US Cyber Security challenge, etc. I think giving them something to start with would be an excellent thing to help them decide if they wanted to truly stick with this field, or move to something else. It would also encourage them to play / practice on legitimate servers and lab machines, and not ones that they shouldn't be touching.
In any event, I think it'd be a good initiative. I also think you could combine it into a local program, with meetings / presentations on internet safety for kids / parents, etc, and really grow the club into something worthwhile.
Please continue to provide feedback as you move forward (assuming you do) and I'd do the same.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Capture The Flag in High Schools
«
Reply #2 on:
May 11, 2010, 08:10:47 AM »
Thanks Hayabusa,
I will keep you posted for sure. Meanwhile, I am just starting...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Equix3n-
Sr. Member
Offline
Posts: 386
Re: Capture The Flag in High Schools
«
Reply #3 on:
May 11, 2010, 08:17:16 AM »
We don't have such kind of competitions for schools in our country. But colleges and universities routinely organize techfests and conduct various competitions. Besides regular tech events some of them do organize CTFs. However, it is not very difficult (not evry college student is a hacker geek) and is often preceded by 1-2 day optional security workshop. The idea is, if you don't know hacking take the workshop where you'll be taught some basic stuff like
ethics
, recon, malware etc. But if you have some hacking skills then jump right onto the CTF. What I like about it is that students are taught about the importance of ethics in hacking.
You can also do something similar. Either organize some workshop or provide students with articles about infosec as a career and the importance of ethics. Add little tips/trics to make the article more interesting.
Logged
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Capture The Flag in High Schools
«
Reply #4 on:
May 11, 2010, 08:50:32 AM »
I was going to start by visiting high schools and try to talk to IT teachers and try to get some ideas from them to. They know their students after all...
Then I could do a little presentation to push the interest. I will probably have to write a letter to parents, school directors, etc.
Then we can start a web site, find a place to gather, do a few presentations and demos to really get the interest going. Then as you said Equix3n, have a workshop and organize a competition.
And you are right ETHICAL would be the keyword here...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
chrisj
Hero Member
Offline
Posts: 1163
Re: Capture The Flag in High Schools
«
Reply #5 on:
May 11, 2010, 10:21:32 AM »
H1t M0nk3y,
Good luck. some things you'll have to remember (since you've been a teacher), you're responsible for them until they get picked up / home.
Had a friend (Tang Soo Do master) try to start an after school program, and the expectations of the administration were way out there.
Also, I don't know how things are in your area, but around here extracurricular has been taking cuts left and right. If someone were to try this here, they'd have to supply all the equipment themselves.
Logged
OSWP, Sec+
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Capture The Flag in High Schools
«
Reply #6 on:
May 11, 2010, 10:43:20 AM »
Thanks chrisj,
I agree with you, I will be responsible of this kids until they are picked up. Also, I will start with one school, talk to the teachers and the director before I "see too big"!
My expectation is that any school will be afraid of us using their network. So I though of supplying the server, the switches, the cables, etc and the students bring their laptops. And since I wanted to put them in teams anyway, if one doesn't have a laptop, it should be alright.
But what about the CTF part. I don't want it to be too tough, but I want them to have a good challenge nevertheless. So what about this:
1) We meet twice a month and I give them a lecture on a single topic. Fro example, scanning with nmap using 4 or 5 switches.
2) The same day, they practice against the lab's server. Again for example, they use nmap to discover ports and enumerate services.
3) Every month or so, there is a bigger challenge where they will apply the knowledge they have learned recently. Ex: Reconnaissance, scanning, and an easy hack.
I also really, really want to put a big emphasis on ethic and defense!
It is a vast field and my biggest challenge will probably be to choose among many, many subjects...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
chrisj
Hero Member
Offline
Posts: 1163
Re: Capture The Flag in High Schools
«
Reply #7 on:
May 11, 2010, 11:14:12 AM »
Does the school or the home supply the laptop. Will they have the ability to boot BackTrack or something else on the laptop?
How are you going to keep them from using the skills you're teaching them from attacking the school network? What if someone else attacks the network, how are you going to prove it wasn't one of yours?
Not trying to discourage you, just playing devil advocate.
I really do think this is a great idea, and once I get more experience might approach a school about this (I love teaching, but would hate working as a teacher in a public school).
Logged
OSWP, Sec+
Equix3n-
Sr. Member
Offline
Posts: 386
Re: Capture The Flag in High Schools
«
Reply #8 on:
May 11, 2010, 11:46:59 AM »
@chrisj I was going to post the same thing, but you worded it more clearly
@H1t M0nk3y
Will you provide any study guide to the students or just refer some books? Don't hesitate to ask if you need any help with tutorials. I might help you out with some articles if you want.
Logged
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Capture The Flag in High Schools
«
Reply #9 on:
May 11, 2010, 12:16:24 PM »
Thanks guys!
It's good to see that I am not the only one thinking about this. I will try to meet the school director soon and see if I have too many road blocks.
If I do, I may look at the College level instead!
@Equix3n Thanks for offering your help!!!
I will keep you guys posted.
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Capture The Flag in High Schools
«
Reply #10 on:
May 11, 2010, 12:49:20 PM »
Humm...
I also wonder if this teenager would understand enough about computers to even start such a project. They probably wouldn't know about even a router, what really is a firewall, yet alone TCP/IP, UDP, ports, NAT, etc.
Would anyone know about a 15 year old superuser who could even slowly start learning about these subjects?
I may be too optimistic...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
chrisj
Hero Member
Offline
Posts: 1163
Re: Capture The Flag in High Schools
«
Reply #11 on:
May 11, 2010, 01:18:16 PM »
Quote from: H1t M0nk3y on May 11, 2010, 12:49:20 PM
Humm...
I also wonder if this teenager would understand enough about computers to even start such a project. They probably wouldn't know about even a router, what really is a firewall, yet alone TCP/IP, UDP, ports, NAT, etc.
Would anyone know about a 15 year old superuser who could even slowly start learning about these subjects?
I may be too optimistic...
I don't think so. Tech is popular now (was going to say chique, but not sure if that's the word I wante). Back in the day (when I was 15) we had bbses, and dial-up internet was new. While I didn't mind playing around on the bbses, I wasn't as interested in computers back then. However with edbuntu and the increase of Linux, and networking to the house, I'm sure you'll find students.
If not, arrange for a couple of copies of Little Brother by Cory Doctorow to become available at the school.
Logged
OSWP, Sec+
Equix3n-
Sr. Member
Offline
Posts: 386
Re: Capture The Flag in High Schools
«
Reply #12 on:
May 11, 2010, 01:21:42 PM »
15 yr. olds are more intelligent than you think. I've seen some 13 year old kids hacking stuff like professionals (random sites). What level of stuff do you want to teach these kids? From your above post it seems to me that you're going too deep into the syllabus. Teaching the above basics won't take more than a day or two. At this stage, however, I think you should just give an overview of each of the phase-- Whois, Zone Transfer, bit of Google hacking & web based searching in Recon, 3-way handshake, ports, 2-3 nmap scans, what's a vuln. scanner with bit of nessus intro in scanning etc (Are you getting my point?)
Conducting a full fledged hacking class will be too much. Flow gently through each of the phase and let them explore the advanced stuff themselves.
Logged
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Capture The Flag in High Schools
«
Reply #13 on:
May 11, 2010, 01:35:14 PM »
Ok, let's say I can gather 20 teenagers.
After about 10 hours of training, demonstrations and exercises, what kind of challenge should I give them?
I guess I will know their level once I can evaluate them, but with CTF in mind, what kind of vulnerabilities should I expect them to compromise? I just can't throw a reverse engineering problem at them...
So password cracking, ARP cache poisoning, maybe some basic SQL injection?!?
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Equix3n-
Sr. Member
Offline
Posts: 386
Re: Capture The Flag in High Schools
«
Reply #14 on:
May 11, 2010, 01:48:54 PM »
Could you please provide a basic overview of what you want to cover-- any table of contents you've prepared?
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Ethical Hacktivism
: lulzsec in it for the money
(7) by
Georgydfea
News Items and General Discussion About EH-Net
: [Article]-Holiday 2012 Free Giveaway Sponsor - Rapid7
(20) by
Georgydfea
News Items and General Discussion About EH-Net
: Наконец то ра
(4) by
Georgydfea
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.