Rules of Engagement
Last Updated: September 2026 | Version 2.1.0
1. Infrastructure & Scope
1.1. In-Scope Targets: You are ONLY permitted to attack the specific instances, domains, or IP addresses provided within the challenge descriptions. Attacking the main Unfoldd platform, scoreboard, database, or other competitors is strictly prohibited and illegal.
1.2. Denial of Service (DoS): Do not perform DoS or DDoS attacks on any challenge infrastructure. If you suspect a challenge requires a DoS vulnerability, contact the admins first. DoS is never the intended solution.
1.3. Automated Scanners: Do not use automated vulnerability scanners (e.g., Nessus, OpenVAS, Acunetix, SQLmap) against the infrastructure unless the challenge explicitly states it is allowed. These tools generate massive noise and degrade performance for everyone.
2. Flags & Scoring
2.1. Flag Format: Unless specified otherwise in the challenge, flags follow the format: unfoldd{some_random_string}. Submit the entire string including the wrapper.
2.2. Flag Hoarding: Do not hoard flags to submit them all at the end of the competition to manipulate the scoreboard. This disrupts the competitive balance and may lead to manual score review.
2.3. Dynamic Scoring: Many events use dynamic scoring. The point value of a challenge decreases as more users solve it. Early solves are rewarded.
3. Integrity & Cheating
3.1. Flag Sharing: Sharing flags, solutions, or providing overly specific hints to other teams during an active competition is strictly forbidden. This includes posting solutions on Discord, forums, or social media before the event concludes.
3.2. Team Limits: You may only compete on one team per event. Creating multiple fake accounts (smurfing) to access more instances or bypass limits will result in a permanent ban.
3.3. Dynamic Flags: Be aware that flags may be dynamically generated per-user or per-team instance. Submitting a flag assigned to another user's instance will instantly flag your account for cheating.
4. Platform Bugs & Writeups
4.1. Bug Bounty: If you discover a security vulnerability in the Unfoldd CTF platform itself (not a challenge), DO NOT exploit it further. Report it immediately to the admins at team@unfoldd.me. We appreciate responsible disclosure.
4.2. Write-ups: We highly encourage publishing write-ups and solutions on your blogs or GitHub, but ONLY AFTER the event has officially concluded and the scoreboard is frozen.
⚠ VIOLATION CONSEQUENCES
Failure to adhere to these rules will result in immediate disqualification, forfeiture of any prizes or certificates, and potential permanent suspension from the Unfoldd ecosystem.