Kostenlos abonnieren

Werden Sie regelmäßig per E-Mail über neue Ausgaben der campuls informiert. Sie können Ihr kostenloses Abo jederzeit einfach online über den Abmeldelink im Newsletter kündigen.

Weitere Infos zu Datenschutz & Widerrufsrecht finden Sie hier.

Students shine in “Capture The Flag” – Unresolved security vulnerability found

In the elective module “Applied IT Security” at Hof University of Applied Sciences, students once again demonstrated their skills in the popular hacking competition “Capture The Flag” this year. The competition was organized by Prof. Dr. Florian Adamsky, who uses it to give aspiring IT security experts practical insights into the mindset of attackers.

 Prof. Dr. Florian Adamsky (left) with his successful students in the Capture the Flag competition (from left): Marija Voloder, Fadhil Fasalu Rahiman, Daniela Hofmann, Taha Faroukh Khapra, and Isabell Anna Pankalla; Image: Hof University of Applied Sciences; 

Capture The Flag involves identifying small security gaps within specified tasks and finding cryptic “flags” (these have names such as “NTA1MzNlZjAyOWIwYzhkNTQxNDRjYTk1”) and submitting them – clever approaches are rewarded just as much as technical know-how.

AI challenges as a highlight

For the first time this year, tasks were integrated in which the teams had to specifically challenge artificial intelligence. By asking clever questions or deliberately misleading the AI, the participants attempted to reveal flags hidden by AI models – an exciting addition to the classic CTF format that promoted both creativity and critical thinking.

Students find security vulnerability

Particularly noteworthy is the performance of the group consisting of Isabell, Anna Pankalla, and Daniela Hofmann, who took third place in the CTF competition. As part of their work, they investigated a previously known security vulnerability in more detail and discovered that, contrary to previous assumptions, it had not been completely fixed. The previously implemented solution proved to be insufficient, meaning that the vulnerability still existed.

“No student group has ever achieved such in-depth findings and results before: for the first time, a new, previously unknown security vulnerability was identified in the course of a student investigation. The students responsibly informed the developers of the affected program about their findings – an approach known as ‘responsible disclosure’.”

Prof. Dr. Florian Adamsky.

The developers have since responded and are working to permanently close the vulnerability.

The final scoreboard of the competition; source: Hof University of Applied Sciences;

The winning teams

After intense rounds of competition, the following students took the top spots on the podium:

1st place: GoofyGooby – 10,151 points

  • Marija Voloder – 10,101 points

2nd place: _sierra – 8,401 points

  • Taha Faroukh Khapra – 5,710 points
  • Fadhil Fasalu Rahiman – 2,691 points

3rd place: hackerwoman – 8,101 points

  • Isabell Anna Pankalla – 7,631 points
  • Daniela Hofmann – 40 points

Hof University of Applied Sciences has been holding Capture the Flag competitions since 2021, which have been met with great enthusiasm. 

Congratulations to all participants for their great commitment and impressive achievements!

Rainer Krauß

Weitere Themen