GCTF://RULES

Rules

Attack the challenges, not the platform. Play as one team. Organizer decisions are final.

# Rule Detail
1 Attack only in-scope targets You may only attack official challenge instances and files provided by organizers. Do not scan, probe, exploit, or brute-force the scoreboard, registration, other teams, instancers, or any host outside the challenge.
2 Do not disrupt infrastructure No denial of service, traffic floods, port scans of the platform, or anything that degrades shared services. If a challenge looks broken, open a ticket — do not “fix” it by attacking the host.
3 Flags stay inside your team Do not share flags, hints, payloads, or solutions with anyone outside your team. Do not submit a flag you did not earn. Public write-ups are allowed only after the event ends.
4 One player, one account Do not register multiple accounts, share logins, or play on another team’s account. Team size limits (if set) are enforced. Solo players compete as a team of one.
5 No scoreboard games Do not withhold flags to manipulate ranking, dump the API for hidden challenges you are not meant to see, or interfere with another team’s instances or submissions.
6 Report platform bugs If you find a bug in CTFd, the instancer, or scoring, tell organizers privately via tickets. Do not use it for points. Challenge bugs that are the intended path are fair game.
7 Respect the community Harassment, hate speech, and toxic behaviour are not tolerated — in chat, tickets, streams, or match broadcasts. Girls in CTF is a safe space for women and girls in cybersecurity.
8 One faction You compete on one of three leaderboards: Human, Humanoid, or Cyborg. Register on the matching bracket and stay there. Using a higher-tier method moves you up. See AI Policy.
9 Staff decisions are final RE:UN10N may warn, move, or disqualify a team for rule or AI Policy violations. Finals may add operational rules, announced before that round. Questions go through tickets.