CardHaxHeader800.png

Submitting Flags

All flags must be submitted in the following format:

flag{flagtext here}

As an example:

Challenge: Can you make one word from new door?

Flag submission: flag{oneword}

Challenge: What is 1+1?

Flag submission: flag{2}

Failure to submit your flag with flag{} means that it will be scored as incorrect!

CardHax 2021 Official Rules

NO PURCHASE NECESSARY TO ENTER OR WIN. VOID WHERE PROHIBITED. CONTEST IS OPEN TO RESIDENTS OF THE 50 UNITED STATES, US TERRITORIES AND THE DISTRICT OF COLUMBIA.

This Contest consists of two events: the first is a distributed, wide-area security exercise, whose goal is to test the security skills of the participants.

The competition will consist of a set of challenges for participants to solve. Participants can achieve rewards based on solving these challenges by submitting their results and earning points for solving challenges within the Contest time period—as described further below, teams earning the most points will qualify for cash awards are possible.

Timing: CardHax will take place between 9AM and 8PM Eastern Standard Time on February 20th, 2021. ENTRANTS ARE RESPONSIBLE FOR DETERMINING THE CORRESPONDING TIME ZONE IN THEIR RESPECTIVE JURISDICTIONS.

Sponsors: The University of Louisville and/or ULRF, the Kentucky Cabinet for Military Affairs, and Tenable Inc.

Eligibility: The Contest is open to individuals who are (1) over the age of thirteen (13) at the time of entry; (2) not a resident of Quebec, Cuba, Iran, Syria, North Korea, Sudan, or Crimea; (3) an individual who is not restricted by applicable export controls and sanctions programs; and (4) people who have registered at ctf.cecsresearch.org. VOID WHERE PROHIBITED. All federal, state and local laws and regulations apply. U of L and ULRF reserves the right to verify eligibility and to adjudicate on any dispute at any time.

How to Enter: Eligible participants may enter by registering at ctf.cecsresearch.org and completing the tasks as detailed on the site. Participants may enter only once. Participants may work in teams; the prize money will be awarded to the team listed on the team registration. It is the sole responsibility of the registrants to distribute any potential winnings. U of L and ULRF takes no liability for the distribution of payment to other group members.

Any entries, points or flags are void if they are in whole or in part illegible, incomplete, damaged, irregular, altered, counterfeit, produced in error, forged or obtained through fraud or theft. By entering you agree to be bound by these Official Rules and that all decisions of U of L and/or ULRF are final. If you are entering on behalf of your employer, these rules are binding on you, individually, and your company, and your company has consented to your entry and potential receipt of the Prize.

Rewards for Points Accumulated: There will be a scoreboard where points will be assigned at the end of the competition based on the challenges that were completed. Each challenge will have an amount of points based on the number of teams that solved it. Winners will be selected based on the greatest number of points earned. In case of a tie, the team with the earlier submission of the last flag will be the winner. Note that write-up rewards do not give any points for the qualification stage.

At the conclusion of the competition, the U of L CardHax team will select those teams that have earned the three highest points scores. Finalists will be notified and revealed at 8PM following the end of the competition. If a potential finalist does not respond to the notification attempt within 3 days from the first notification attempt, then such potential finalist will be disqualified and an alternate potential finalist will be selected from among all eligible entries received based on the judging criteria described herein up until the 25th place team is reached

If no entries are received, no prize will be awarded. Determinations of the judges are final and binding.

Privacy: UofL will be collecting personal data about participants when they register and enter the Contest. UofL will treat this data in accordance with its privacy policy, located at https://louisville.edu/privacy-statement

Prizes: First place winner will receive 1500 US dollars. Second place winner will receive 1000 US dollars. Third place winner will receive 500 US dollars. Prizes may be subject to terms, restrictions and conditions imposed by U of L and/or ULRF. Further, all prize winners will need to provide all requested personal (and if applicable, company) information to prove residence eligibility and that they are not restricted by applicable export controls and sanctions programs.

Prizes will be awarded in the form of pre-paid credit card (Swift Prepaid Card) funded in the name of each winner (Teams will receive one cash card in the name of the individual who is the representative of the team; team representative cannot be changed after card is issued). Prize cards will be mailed to winners within 5 business days after the event. Prize cards are not redeemable in cash. UofL is not responsible for loss of card(s) after receipt. Winners/prize card recipients are responsible for all applicable taxes; Please note that UofL reports all prizes awarded to the IRS. UofL student prize winners may be subject to possible financial aid implications and will need to check with the office of financial aid for more information.

U of L and/or ULRF and its affiliates, subsidiaries and related companies, or their respective officers, directors, employees, representatives and agents will not be liable for unsuccessful efforts to notify a winner. The prize will be delivered within 60 days after the conclusion of the contest. No prize transfer, assignment or substitution by winner permitted except at Sponsor’s sole discretion. If the prize becomes unavailable, Sponsor reserves the right to substitute a prize of equal or greater value. All federal, state and local taxes, fees and surcharges on prizes are the sole responsibility of the winner.

If a potential winner declines the prize, does not respond to the prize notification, fails to claim the prize, is unavailable for prize fulfillment, fails to abide by the Official Rules, or is ineligible, ULRF may select the next highest scoring team as the winner.

Publicity: By entering, entrant agrees and consents to permit UofL and its associate entities to use his or her name, photographs and/or likeness, write-ups,code and any provided or recorded/streamed video for advertising and promotional purposes without additional compensation.

Intellectual Property Rights: By submitting a code in this Contest, the entrant warrants and represents that the code, including the programming and related material, is open source and is released subject to the Apache License 2.0 or any suitable BSD (Berkeley Software Distribution) license and not subject to the proprietary rights of any person or entity.

Warranty, Indemnity and Release: Entrants warrant that their codes are their own original work and, as such, they are the sole and exclusive owner and rights holder of the submitted code and that they have the right to submit the code in the Contest and grant all required licenses. Each entrant agrees not to submit any code that (1) infringes any third party proprietary rights, intellectual property rights, industrial property rights, personal or moral rights or any other rights, including without limitation, copyright, trademark, patent, trade secret, privacy, publicity or confidentiality obligations; or (2) otherwise violates the applicable state or federal law.

To the maximum extent permitted by law, each entrant indemnifies and agrees to keep indemnified UofL and/or ULRF at all times from and against any liability, claims, demands, losses, damages, costs and expenses resulting from any act, default or omission of the entrant and/or a breach of any warranty set forth herein. To the maximum extent permitted by law, each entrant agrees to defend, indemnify and hold harmless UofL and/or ULRF from and against any and all claims, actions, suits or proceedings, as well as any and all losses, liabilities, damages, costs and expenses (including reasonable attorneys fees) arising out of or accruing from (a) any code or other material uploaded or otherwise provided by the entrant that infringes any copyright, trademark, trade secret, trade dress, patent or other intellectual property right of any person or defames any person or violates their rights of publicity or privacy, (b) any misrepresentation made by the entrant in connection with the Contest; (c) any

non-compliance by the entrant with these Rules; (d) claims brought by persons or entities other than the parties to these Rules arising from or related to the entrant’s involvement with the Contest; and (e) acceptance, possession, misuse or use of any prize or participation in any Contest-related activity or participation in this Contest.

Entrant releases U of L and/or ULRF from any liability associated with: (a) any malfunction or other problem with the Contest Site; (b) any error in the collection, processing, or retention of entry information; or (c) any typographical or other error in the printing, offering or announcement of any prize or winners.

Right to Cancel: If for any reason the Contest is not capable of running as planned, including tampering, unauthorized intervention, fraud, technical failures, printing errors, or any other causes which corrupt or affect the administration, security, fairness, integrity, or proper conduct of the Contest, UofL reserves the right at its sole discretion to cancel, terminate, modify or suspend the Contest. UofL further reserves the right to disqualify any entrant who tampers with the submission process or contest, cheats, deceives, abuses, annoys, threatens any other entrants or Judges, or otherwise violates any law or behaves in an unfit manner as determined by UofL.

Limitation of Liability & Disclaimer of Warranties: IN NO EVENT WILL UofL OR ITS AFFILIATES, SUBSIDIARIES AND RELATED ENTITIES, OR THEIR RESPECTIVE OFFICERS, DIRECTORS, EMPLOYEES, REPRESENTATIVES AND AGENTS, BE RESPONSIBLE OR LIABLE FOR ANY DAMAGES OR LOSSES OF ANY KIND, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL OR PUNITIVE DAMAGES ARISING OUT OF YOUR PARTICIPATION IN THE CONTEST OR FOR ANY ACTION OR OMISSION MADE IN CONNECTION WITH THE CONTEST. WITHOUT LIMITING THE FOREGOING, EVERYTHING IN THESE RULES AND IN THIS CONTEST, INCLUDING THE PRIZES AWARDED, IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT. SOME JURISDICTIONS MAY NOT ALLOW THE LIMITATIONS OR EXCLUSION OF LIABILITY FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES OR EXCLUSION OF IMPLIED WARRANTIES SO SOME OF THE ABOVE LIMITATIONS OR

EXCLUSIONS MAY NOT APPLY TO YOU. CHECK YOUR LOCAL LAWS FOR ANY RESTRICTIONS OR LIMITATIONS REGARDING THESE LIMITATIONS OR EXCLUSIONS.

Governing Law. This Contest is governed by the laws of Commonwealth of Kentucky without regard to the conflict of laws provision.