Oct. 6-8, 2017

at the Renaissance in DC


= LEARN =

ROUTER EXPLOITATION, CSRF, XSS, AUTH BYPASS

Our contest network lets you get a chance to try your hand at numerous exploits that are commonly found in embedded electronics.

= CTF PRIZES =

Prizes are limited! There will be only one first, second, and third place winner, and other prizes will be given while they last. To qualify for prizes you must score a minimum of 12,000 points.

First Place Second Place Third Place
$100 $50 $25

= 0-DAY TRACK =

This contest only runs during DEF CON

Rules for 0-DAY TRACK

Identify and exploit a vulnerability:

Submit 0-Day overview and proof of responsible disclosure:

Demonstrate your exploit:

Email us if you have any questions or concerns: sohopeless@securityevaluators.com



Devices for 0-DAY TRACK

Device Software/Firmware Version
CUJO Smart Internet Security Firewall
Synology RT2600ac Router v. SRM 1.1.1-6414 Update 1
TrackR
Nokē Padlock - 2nd Gen
FitBark: Activity tracking for your pet
Roost: Smart battery for smoke alarms N/A
Keen Home: Smart vent N/A
August: Smart Keypad 2.22.0
Nest Cam: Outdoor 214-610038
Talkies: A new way to chat with kids N/A
QNAP TS 251A v. 4.2.2 2016/06/07
Amazon Echo Dot 571207720
Google WiFi 9334.41.3
Google OnHub 9334.41.3
Amazon Echo 3077
Canary (Model CAN100USBK) v. 1.4.5
Apple Time Capsule 7.7.8
ZyXel Wireless Router (NBG6716) V1.00(AAKG.9)C0
ASUS RT-AC3200 3.0.0.4.380.7378
FitBit Alta 21.21.38.12
FitBit Blaze 17.8.401.3
FitBit flex 2
FitBit charge 2
Google NestCam 174-600055
WD My Cloud NAS v. WDMyCloud v04.04.03-113 : Core F/W

= PAST WINNERS =