/ctf-vs-the-real-world

Informational Repository tracking times that real world bugs have come out of CTF challenges intentionally or otherwise

Apache License 2.0Apache-2.0

ctf-vs-the-real-world

Informational Repository tracking times that real world bugs have come out of CTF challenges intentionally or otherwise

  1. CVE-2016-5007

  2. CVE-2020-6512 (unconfirmed CTF background)

  3. CVE-2020-27348

  4. CVE-2020-27348

  5. CVE-2012-1823

  6. Bunyan's Revenge

  7. Lollerska8ters FreeBSD 0day

  8. Pirate Danbi

  9. Several from Google CTF 2019:

  10. 35C3 CTF Entire category of 0day challenges (zajebiste).

  11. Many CTF challenges have inspired real-world bug finding:

  12. CVE-2019-2684

  13. https://bugs.chromium.org/p/chromium/issues/detail?id=1077139

  14. CVE-2011-2018

TODO

  • Sortable/better table format
  • Standard tags for different types of interactions (used as legit challenge, found accidentally, used against infra, etc)