Hi everyone! I was tasked to create few challenges for a CTF at my university as part of my bachelor thesis. The last challenge I should create is essentially about crashing a system, while another “monitoring” system is detecting if the other one is running, and if not it gives you a flag. The tasks are meant for 4th year high-school students, so nothing insane, but this one still should be at an “extreme” difficulty in regard to the experience high-school students could have.
Issue is, I have no prior experience in such exploitation, and I don’t necessarily know where to start with this one. My idea was creating a custom vulnerable module/driver in the linux kernel, that the players would be tasked to somehow exploit (some kind of overflow I guess, so that it would trigger kernel panic). I suppose it could be something similar to this: https://nofilqasim.info/Making a Kernel CTF (PUCon’24 pwn CTF)/ , except I believe the author of this CTF made it as a privilege escalation task, which is not exactly what I desire.
I was wondering if anyone could give me some pointers or ideas on where to start with this, and if what I have described above might be too difficult for the students to exploit, and consequently for me to implement.
Thank you for any answers!
Try the magic SysRq crash command
Could it be considered an exploit/vulnerability tho? And if it would, would you say the difficulty of finding it being enabled could be hard enough for the audience I am creating it for?
That sounds like your job :)
You’re right haha. I think I will go with something similar to this. Ran it through others working on this, and it seems like a viable method! Thank you very much
Halt and catch fire 🔥 🤣
Here’s a class assignment from UC Berkeley that is somewhat similar. They provide a VM image of a vulnerable computer and you have to break it. I believe all the (student side) resources are publicly accessible:
if the only task is to make a system crash, what do you do to stop a bash bomb (
:(){ :|:& };:)?it will make the system crash. so if the monitoring system only checks whether system A is alive and gives the flag if not - that defeats the challenge. nerdier high schoolers surely know something like that, bc it is fun to crash your friends computer…
Great point, haven’t thought of that… I’ll see if either, this is a good enough vulnerability for this level of task, or I’ll try setting a ulimit, as at least according to wikipedia, that is a good enough prevention against a simple fork bomb. Thank you very much!


