Poster: To Play or Not to Play: Insights and Lessons Learned from 20 Years of CTFs with ENOFLAG
Jörg Schneider, Sebastian Neef, Sebastian Koch
cs.CR
Submitted: 2026-07-15
Comments: Preprint; To be published at DIMVA 2026 ( https://www.dimva.org/dimva2026/ )
Code: https://github.com/CTFd/CTFd
License: http://creativecommons.org/licenses/by/4.0/
The gist: Security contests in the form of CTF (Capture The Flag) exercises are nowadays a common way to learn cyber security.
Terminology
Abstract
Security contests in the form of CTF (Capture The Flag) exercises are nowadays a common way to learn cyber security. 20 years ago at DIMVA 2006 the on-site CTF CIPHER II was one of the conference highlights and led to the foundation of the team ENOFLAG. In this poster, we reflect on the changes in the CTF gameplay and report on lessons learned while running an academic CTF team for 20 years.
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs