OPERATION SIGNALFIRE // RULES OF ENGAGEMENT

CTF Rules

Compete hard, keep the event fair, and protect the shared infrastructure.

  1. Stay in scope. Test only the challenges, hosts, and services provided for Operation Signalfire.
  2. Do not attack the platform. Do not target CTFd, the scoreboard, authentication, other teams, or event infrastructure unless a challenge explicitly requires it.
  3. Respect other players. Do not access another player’s account, session, flags, submissions, or private communications.
  4. No denial of service. Avoid traffic or techniques that degrade availability for other players, including brute-force attacks and resource exhaustion.
  5. Do not share active flags. Discuss techniques after a challenge is solved, but do not publish flags, full solutions, or unintended spoilers while the event is live.
  6. Use intended paths. Do not scan the underlying OCI host or probe unrelated ports, services, credentials, cloud metadata, or third-party systems.
  7. One account per player. Keep your account details private. Ask an organizer if you need help recovering access.
  8. Report problems responsibly. If you find an unintended issue, stop using it and contact an organizer with the challenge name and a short description.
  9. Organizer decisions are final. Challenge availability, scoring corrections, and rule interpretations may be adjusted to preserve a fair event.
  10. Leave the Cereberus instance alone. Do not target, scan, probe, exploit, or otherwise test the Cereberus OCI host, CTFd, reverse proxy, or any underlying infrastructure. Interact only with the published challenge endpoints and supplied files.

By participating, you agree to these rules. Good hunting.