CTFs as you need them
 
 
 
 
Go to file
Kevin Chung b7a19f74ff
Mark 2.1.1 (#982)
2.1.1 / 2019-05-04
==================

**General**
* Allow admins to hit `/api/v1/challenges` and `/api/v1/challenges/[id]` without having a team to fix challenge previews
* Fix rate-limiting of flag submission when using team mode
* Fixes some modal close buttons not working in the admin panel
* Fixes `populate.py` to assign captains to teams.

**Models**
* Added `Challenges.flags` relationship and moved the `Flags.challenge` relationship to a backref on Challenges
* Added `ondelete='CASCADE'` to most ForeignKeys in models allowing for deletions to remove associated data
    * `Hints` should be deleted when their Challenge is deleted
    * `Tags` should be deleted when their Challenge is deleted
    * `Flags` should be deleted when their Challenge is deleted
    * `ChallengeFiles` should be deleted when their Challenge is deleted
        * Deletion of the file itself is not handled by the model/database
    * `Awards` should be deleted when their user or team is deleted
    * `Unlocks` should be deleted when their user or team is deleted
    * `Tracking` should be deleted when their user or team is deleted
    * `Teams.captain_id` should be set to NULL when the captain user is deleted

**Exports**
* Force `db.create_all()` to happen for imports on `sqlite` or on failure to create missing tables
* Force `ctf_theme` to be set to `core` in imports in case a theme is missing from the import or the instance
* Fix imports/exports to emit and accept JSON properly under MariaDB
    * MariaDB does not properly understand JSON so it must accept strings instead of dicts
    * MariaDB outputs strings instead of JSON for its JSON type so the export serializer will attempt to cast output JSON strings to JSON objects

**Deployment**
* Run as root when using docker-compose
    * This is necessary to be able to write to the volumes mounted from the host
2019-05-04 19:49:39 -04:00
.github Issue template (#455) 2017-11-14 16:40:36 -05:00
CTFd Mark 2.1.1 (#982) 2019-05-04 19:49:39 -04:00
docs 2.1.0 (#957) 2019-04-17 01:36:30 -04:00
migrations Adds ondelete='CASCADE' to some models. (#979) 2019-05-04 02:08:26 -04:00
scripts Add Vagrant with docker support (#285) (#355) 2017-08-20 19:31:32 -04:00
tests Adds ondelete='CASCADE' to some models. (#979) 2019-05-04 02:08:26 -04:00
.codecov.yml Fix admin cannot modify verified status in Edit User (#777) 2018-12-04 00:35:51 -05:00
.dockerignore Adding .dockerignore and making docker-entrypoint consider DATABASE_URL (#312) 2017-07-13 02:43:17 -04:00
.flaskenv 1.2.0 (#627) 2018-05-03 18:04:39 -04:00
.gitignore Add plugin wrappers for plugin related utils functions (#410) 2017-10-14 17:17:06 -04:00
.travis.yml 2.1.0 (#957) 2019-04-17 01:36:30 -04:00
CHANGELOG.md Mark 2.1.1 (#982) 2019-05-04 19:49:39 -04:00
CONTRIBUTING.md Documentation improvements (#963) 2019-04-21 12:00:21 -04:00
Dockerfile Fix logging without root in container (#966) 2019-04-22 22:22:54 -04:00
LICENSE Update LICENSE 2018-07-29 03:16:54 -04:00
Makefile Fix imports/exports and update Flask-SQLAlchemy to reduce warnings (#974) 2019-04-30 20:36:25 -04:00
README.md Reduce default gunicorn worker count to reduce memory usage (#968) 2019-04-25 15:05:20 -04:00
Vagrantfile Vagrant uses mariadb database rather than sqlite - Fixes #648 (#649) 2018-07-29 00:08:05 -07:00
development.txt 2.1.0 (#957) 2019-04-17 01:36:30 -04:00
docker-compose.yml Run as root when using docker-compose to be able to write to the volume (#981) 2019-05-04 17:17:11 -04:00
docker-entrypoint.sh Reduce default gunicorn worker count to reduce memory usage (#968) 2019-04-25 15:05:20 -04:00
export.py 2.0.0 (#741) 2018-11-19 23:16:14 -05:00
import.py 2.0.0 (#741) 2018-11-19 23:16:14 -05:00
manage.py 2.0.0 (#741) 2018-11-19 23:16:14 -05:00
populate.py Adds ondelete='CASCADE' to some models. (#979) 2019-05-04 02:08:26 -04:00
prepare.sh Mark prepare.sh executable 2017-09-27 22:32:01 -04:00
requirements.txt Fix imports/exports and update Flask-SQLAlchemy to reduce warnings (#974) 2019-04-30 20:36:25 -04:00
serve.py 2.1.0 (#957) 2019-04-17 01:36:30 -04:00
setup.cfg Starting to write tests 2017-01-07 02:44:31 -05:00
wsgi.py 2.1.0 (#957) 2019-04-17 01:36:30 -04:00

README.md

Build Status CTFd Slack Documentation Status

What is CTFd?

CTFd is a Capture The Flag framework focusing on ease of use and customizability. It comes with everything you need to run a CTF and it's easy to customize with plugins and themes.

CTFd is a CTF in a can.

Features

  • Create your own challenges, categories, hints, and flags from the Admin Interface
    • Dynamic Scoring Challenges
    • Unlockable challenge support
    • Challenge plugin architecture to create your own custom challenges
    • Static & Regex based flags
      • Custom flag plugins
    • Unlockable hints
    • File uploads to the server or an Amazon S3-compatible backend
    • Limit challenge attempts & hide challenges
    • Automatic bruteforce protection
  • Individual and Team based competitions
    • Have users play on their own or form teams to play together
  • Scoreboard with automatic tie resolution
    • Hide Scores from the public
    • Freeze Scores at a specific time
  • Scoregraphs comparing the top 10 teams and team progress graphs
  • Markdown content management system
  • SMTP + Mailgun email support
    • Email confirmation support
    • Forgot password support
  • Automatic competition starting and ending
  • Team management, hiding, and banning
  • Customize everything using the plugin and theme interfaces
  • Importing and Exporting of CTF data for archival
  • And a lot more...

Install

  1. Install dependencies: pip install -r requirements.txt
    1. You can also use the prepare.sh script to install system dependencies using apt.
  2. Modify CTFd/config.py to your liking.
  3. Use flask run in a terminal to drop into debug mode.

You can use the auto-generated Docker images with the following command:

docker run -p 8000:8000 -it ctfd/ctfd

Or you can use Docker Compose with the following command from the source repository:

docker-compose up

Check out the wiki for deployment options and the Getting Started guide

Live Demo

https://demo.ctfd.io/

Support

To get basic support, you can join the CTFd Slack Community: CTFd Slack

If you prefer commercial support or have a special project, feel free to contact us.

Managed Hosting

Looking to use CTFd but don't want to deal with managing infrastructure? Check out the CTFd website for managed CTFd deployments.

MajorLeagueCyber

CTFd is heavily integrated with MajorLeagueCyber. MajorLeagueCyber (MLC) is a CTF stats tracker that provides event scheduling, team tracking, and single sign on for events.

By registering your CTF event with MajorLeagueCyber users can automatically login, track their individual and team scores, submit writeups, and get notifications of important events.

To integrate with MajorLeagueCyber, simply register an account, create an event, and install the client ID and client secret in the relevant portion in CTFd/config.py or in the admin panel:

OAUTH_CLIENT_ID = None
OAUTH_CLIENT_SECRET = None

Credits