– Bring yourself and a laptop, everything else you need is provided at the stand.
– The competition runs in rounds of up to 5 players at a time, with a 60-minute time limit per round so sign up to reserve your slot.
– Each player receives their own isolated instance of the target, no attacking other players or shared infrastructure.
– Points are awarded per stage. Hints are available but reduce that stage points.
– Ties are broken by furthest stage reached, then by time, then by fewest hints used.
– Use any tools and scripts you like.
– Scope Definition: The scope of the competition will be explicitly defined and communicated by the organizers prior to the start of the event. Contestants must adhere to the defined scope, which may include network devices, specific targets, systems or applications within the simulated environment. Any attempts to access systems beyond the scope are strictly prohibited.
– Denial of Service (DoS) Prohibition: Participants are strictly prohibited from engaging in any form of Denial of Service (DoS) attacks against the competition environment. This includes but is not limited to flooding, overloading, or otherwise disrupting the availability or functionality of systems.
– Fair Play and Non-Disruption: The spirit of the competition is based on fair play and ethical hacking. Any actions intended to disrupt the competition, such as hiding or tampering the flags once found, engaging in cheating, or sabotaging the progress of other participants, will not be tolerated and may lead to immediate disqualification.
– Compliance with Laws and Regulations: All participants are required to comply with local, national, and international laws and regulations related to computer security and ethical hacking. Any illegal activities or actions that could potentially harm the competition environment, participants, or external systems are strictly prohibited.
– Respect for Privacy: Contestants must respect user privacy and any personal data discovered during the competition must not be disclosed or exploited in any way. Participants are expected to handle sensitive information with the utmost care and ethics.
– Responsible Disclosure: If participants discover unknown vulnerabilities during the competition, they should report them to the organizers. Exploitation of undisclosed vulnerabilities that were not part of the competition’s scope is prohibited.
– Time Limitation: The competition is time-limited, and participants must adhere to the specified start and end times. All activities must cease at the conclusion of the competition.
– Sportsmanship: Participants are expected to maintain a high level of sportsmanship throughout the competition. Any disrespectful or unsportsmanlike behavior towards fellow participants, organizers, or sponsors will not be tolerated.
– Organizer’s Authority: The organizers have the final authority in all matters related to the competition. Their decisions are binding and any disputes or rule violations will be addressed by the organizing committee.
– Consequences of Violations: Violations of these rules may result in penalties, disqualification, or other actions as determined by the organizers, which may include banning participants from future competitions.
– The Ascent is designed to be a challenging but fair cybersecurity competition and adherence to these rules ensures a positive and ethical environment for all participants.