Getting Started in CTF: PicoCTF 2017 | Tutorial #1 (CTRL+F)
Key Takeaways
Introduces PicoCTF 2017, a beginner-friendly capture the flag competition for learning cybersecurity and hacking
Full Transcript
hey everyone so I get a lot of questions and comments asking me like hey John how can I get into the capture the flag scene how can I get started how can I learn how to hack or how to be more of a cyber security professional so my usual answer to them is like well just jump in just take a look at over the wire some of those wargames try practicing like capture the flag competitions and normally the first thing that I suggest to them is tried to play Piko CTF and pìkô CTF is what I would say is one of the best jumping-off points to really learn more capture the flag style like challenges and the content topics things that you would you see in some of the scene so what I want to do in this video series is try and attack this like as if you were an absolute beginner so I'll explain as much as I can everything in detail and try and be as hand-holding and as friendly as I can be and that's why I'm doing this right now on Windows so let's say your absolute beginner you don't know Linux you don't know a whole lot of programming stuff just yet but we're gonna jump in and we're gonna do it for real so I am on a vanilla Windows 10 image like literally not even I'm just doing a virtual machine right here so I'm just even on Microsoft edge I don't have anything so if I were to go to Google like as a noob just googled Pico CTF and our first result is where we're gonna head so Pico CTF is a cybersecurity competition put on by Carnegie Mellon University let's make this stupid windows nag go away and it's originally designed for middle and high school students right so to get that introductory phase for people trying to get into the scene and learn cybersecurity computer science stuff around participants must reverse engineer break hack decrypt or do whatever it takes to solve a challenge they're set up with the intent of being hacked so it's like purposefully vulnerable and for you to learn so it's done by the Carnegie Mellon University the guys that do scilab their eye and eye and plaid Parliament up owning so the got a lot of guys that like our hardcore like top of the world for capture flag security teams at least United States wise and this is their game so let's jump in we're still waiting on picot CTF 2018 to be released should come this September but the 2017 game is phenomenal and that's where I want us to start so if you haven't already go ahead and create an account I'm gonna do this as well the URL right now is just 2017 dot picot CTF comm if we want to register you would just go to like forward slash register you can check out the get started page right here but it will link you to ok officially register for picot CTF you will need an email address to be able to do this I'm just probably going to use a quick and easy ten-minute mail thing if we google 10-minute mail we can get temporary email Wow being is the default here dang alright so let's go back over to our Pico 2017 tab I'll pick you username I'm gonna do underscore underscore John Hammond because I've been trying this a few times paste in that email address that we just got for our temporary email address let's give it a password we don't need to have a school in this case I'm from the United States so I'll agree to the Terms of Service tell them I'm not a robot and I'm probably gonna have to go through this stuff sorry guys bus bus bus more buses verify so we I did it I am NOT a robot perfect alright so they just sent a verification email let's go ahead and check it since we're in the ten minute mail slot let's go over there and okay cool it just popped up welcome to POC GF confirm your email scroll down here there's a big blue button to activate our account cool so now we are in and it looks like it's trying to load something okay cool I'm gonna zoom out here a little bit so we can see here but what this section is is the tutorial like you can see up in the URL cut for cutscene and then tutorial one entry so this is a tutorial and it's trying to go through a little bit of scenario storyline to offer some call tax for what we're trying to do here but I think it's pretty silly you don't have to watch through all of it down to the bottom right you've got some skip or skip all options and right now which is trying to set the scene for a lot of the material that we're gonna see in the game I don't care too much about that storyline stuff I care more about the actual technical ability and competence that we're gonna learn how to do here so I'm actually gonna go ahead and skip all on these and it'll jump us right to the first challenge here but it looks like we're presented with kind of like a desktop looking screen so daedalus I think is the company or corporation that we're trying to either get stuff out of again I didn't pay attention the storyline but I just want to give you context of what this thing is so on the left here you've got a file called Oh the name but the icon says open me so if we click on that we get this dialog box that pops up and this is what we're gonna see as a challenge that like that's presented to us and that's that's it's just that it's that small self-contained encapsulated thing this box right here so the challenge title in this case is just tutorial one and our challenge prompt is how can you figure out Robin Morris's middle name thankfully you have a list you can check and list looks to be in blue so that's got to be a link we've got hints down here and we can expand those the hints here says please don't search by hand okay benefit of using a computer we have automation we have power we have speed numbers and computing so let's click on that list and nice okay this looks like a giant text file contractors dot text in some static directory I don't care but we've got Daedalus contractor to list number a thousand four hundred ninety eight so we can scroll through this right but like it said please don't look by hand so let's try and control F let's use that Find and Replace or search functionality that our browser gives us and hit ctrl + F at the same time on the keyboard and we can look for whatever it is we're trying to find Robin Morris's middle name well since we can only look for text in that text file let's try like Morris as the last name see if we could track it down we could also look for Robin but that has 23 results as you can see and Morris I think only has 12 okay so last name Morris that's Anthony Robin Morrison not right not right first names that's Jennifer Morris not Robin Morris Ava Morris Morrison Sophie Morris still wrong Robert Morris etc etc okay so after we fit enter a few times looks like we found it on the tenth entry Robin almay Morris you can see it right there here I'll highlight this that's his name Robin first name Morris last name so his middle name must be L May cool so right now obviously this doesn't look like a cool lead hacker thing that we're doing right now it's just a tutorial it's just trying to get us in the zone in the mindset of finding a flag or a token or something that we're trying to reach as our goal as the objective and find out a way to get there and it's just going through these silly cutscenes and all but let's go ahead and move on from this I want to hit skip all and okay now we're back to the desktop and the next level of tutorial tutorial - looks like the thing is called ambition tutorial - Robin handed me this the other day maybe will help me find the answer okay well that's enough for now because I want us to just get our feet wet I want us to register for picot CTF I wanted to jump and showcase the first tutorial but that's right now the bare basics that we're doing cuz you're right that wasn't super cool that wasn't super leet flashy hacky sexy stuff on the keyboard but we're gonna get into it you're gonna learn to be an awesome cyber security professional gonna learn to be a hacker and you're gonna be loving the cybersecurity capture-the-flag competition that CTF scene and I think picot CTF is a great way to jump in I'm on Windows right now because I want to be holding your hand I want to be with you as a beginner I want to be walking this road with you like side by side so thanks for watching guys hope you like this hey I have to shout out to my supporters people that are giving me some love so far in patreon so big shout out - I'm gonna say big I'm gonna make it like a huge font 4072 let's go 48-72 a little much cool Spencer Clark gal Horowitz is okay Attila I'm sorry Windows notepad remove the accent so I know you have an accent in your name and I'm really sorry that it loses but the next one is my favorite to say or go off the unruly destroyer of worlds bastion of terror thank you guys so much for supporting me $1 a month on patreon will give you a shout-out just like this at the end of every video $5 a month or more will give you early access quote-unquote early actress access the best I can do for the videos that I create because I record a lot of things in bulk and in mass and then I release them to YouTube and a schedule daily like gradual upload if you don't want to wait you want the content immediately as it's ready $5 a month you get early access so thank you guys for watching if you did like this video please press that like button please pries + please press that like button hey maybe comment maybe subscribe if you're willing to support me on patreon thanks so much see you soon
Original Description
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: https://patreon.com/johnhammond010
E-mail: johnhammond010@gmail.com
PayPal: http://paypal.me/johnhammond010
GitHub: https://github.com/JohnHammond
Site: http://www.johnhammond.org
Twitter: https://twitter.com/_johnhammond
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from John Hammond · John Hammond · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
More on: Network Security
View skill →Related Reads
📰
📰
📰
📰
Ferramentas de IA gratuitas para opções em Portugal (2026)
Dev.to AI
Free AI APIs you can use right now without a credit card
Dev.to · David García
Automated Property Tax Appeal Letters for Homeowners: Earn $500–$2,000/Month with Manus AI
Dev.to AI
I Let AI Write Every SQL Migration for a Year. One Rollback Nearly Took Down Production.
Medium · AI
🎓
Tutor Explanation
DeepCamp AI