NEONCTFv2.0

Rules of Engagement

Read before you hack. Breaking these gets you banned and your score zeroed.

1. Account & Identity

  • >One account per person. Sharing accounts, multi-accounting or score-pooling is forbidden.
  • >Pick a non-offensive username. Impersonating staff or other players results in an immediate ban.

2. Flag Sharing

  • >Do not share flags, partial flags, hints, screenshots of solutions, or writeups during the event.
  • >Public writeups are allowed only after the event has ended.

3. Attacks

  • >Attack only the targets listed on the challenge page. Never attack the platform itself, the scoreboard, other players, or shared infrastructure.
  • >No DoS, brute-forcing the login, or generating excessive traffic. Rate limits are enforced.
  • >Do not attempt to break out of challenge sandboxes or pivot to the host.

4. Tooling

  • >Automated scanners (sqlmap, dirbuster, nuclei, etc.) are tolerated only against your own challenge instance with sane rate limits.
  • >Use of AI assistants is allowed. The built-in console is provided for your convenience.

5. Fair Play

  • >Found a platform bug? Report it to the admins instead of exploiting it. Confirmed reports earn bonus points.
  • >Admin decisions are final.