This year's CTF contest will be held by FluxFingers, the CTF Team of Ruhr-Universit├Ąt Bochum (Germany).

FluxFingers have been participating in CTFs since 2007 and are excited to organize their first CTF at The CTF will be challenge-based, similair to e.g. DEFCON Quals, Codegate etc.

Topics include (among others): web security, cryptography, reverse engineering and forensic.

If you have any questions, don't hesitate contacting us at our booth. We might even give you some hints for free beer.


CTF is over, where do I find a mirror?


General Information for the CTF

Ahoy me Landlubbers! The fluxfingers are proud to announce the start of this years' HACK.LU CTF. Some tweet might have already indicated, that it's going to be all about pirates, yarr! We hope that you'll enjoy the CTF and wish you the best luck with looting all the hidden doubloons.

Step 0: Try to remember the SHA1 fingerprint by heart (See [1]) You should be sure that you are connecting to our site and *our site only*. Especially local teams wouldn't want anyone to steal their flags, right?

Step 1: Register You will have to sign up your team manually on the ctf web page. Local teams are highly encouraged to visit us at our booth near the entrance to ensure being flagged as a local team (see Step 3). Also, notice that there is an announcement page which will also be used to give out hints regarding yet unsolved challenges.

Step 2: Solve as many challenges as possible :)

Step 3: Profit! The award ceremony will be held locally, so completely remote teams will not be able to receive a price and will receive a nice t-shirt per mail instead ;). Still you will be having a lot of fun - we promise! Also, have you heard about the prices? Among the prices are an Amazon Kindle, and iPad and so on.. :)

Be sure to visit us on IRC for the latest updates: #ctf /

Reminder: The ctf goes from Wed, 27th Oct 11am (CEST) to Fri, 29th Oct 11am CEST (this is in about 20 minutes from now)

Cheers, team fluxfingers

P.S.: We will highly appreciate constructive criticism and are happy to fix all the fuck-ups you will report :)

CTF Dates and Time Information

- Start of the CTF:   27th October, around 11:00 (CEST)
- End of the CTF:     29th October, around 11:00 (CEST) CTF Registration is Open

This years Capture-The-Flag (CTF) contest of the conference will also be open for remote participants. However there will be only a limited amount of teams accepted for remote participation so don't hesitate to register as early as possible. To do so, please subscribe to the mailing list of the CTF: Please, use your team-name to register, and only one subscription per team. Once accepted, you will be provided with more information.
--Fluxfingers 22:00, 5 October 2010 (UTC)


The registration for the online CTF will start on 5th October at 22:00 UTC. There will be a limited number of slots available. Teams playing from the Conference don't need to register now.

Solution for the Second Challenge

Here you go:

The Second Challenge [Solved by Nibbles] Access Control System v1.0

Here is a hint for the *bonus* challenge:

We're looking for a "golden" key-file that is valid for every name. No BOFs or the like involved.  Though its not just math.


 1P (easy): "d|?-c:e;(RJ+o`ci"?!
 2P (medium): Somebody lost their key. Find any valid name for flux.key and log-in!
 +0.5P for an unsuspicious "forename surname" solution.
 3P (medium): Log-in with a key containing the string "hack.l00"! 
 5P (hard): Write a keygen for this application!
 5P (*bonus*): Rumors have it: Some secret agency backdoored the Access Control System!! 0_0
 Find out the truth!

Can you trick the hACS?
Mail your solutions to and win free access to 2010!

The most points in fastest time submitted will be rewarded with one free entrance to the conference.
You have exactly one (1) week (12th September 00:00) to solve the challenge and send us your solution.

Love-letters, complains, bugs and cookies to please.
Have fun an good luck
--Fluxfingers 22:00, 5 September 2010 (UTC)

Solution for the First Challenge

It was a substitution cipher where every char got replaced with another and the substitution was case-sensitive.

The first challenge has already been solved. (See below)
The second (and last) challenge is now online.
More News regarding this will be announced here and on twitter


The CTF will be open to a limited number of teams. The registration procedure will be published in the beginning of September.


Feel free to join our IRC channel:

 Channel: #ctf

First Challenge [Solved by ENOFLAG]

Break this cipher: