The 1st Pentesting Competition in Cyprus (a personal experience, Q/A, photos, video)
Here follows a /* brief */ review as well as my personal experience regarding the 1st penetration testing competition that was organized by UCLan, the University of Cyprus and the company Circles on Saturday, September 19, 2015.
From the first day it was announced that a pen-test competition would be organized in Cyprus, I decided that it would be something I wanted to support both professionally and personally, which is why this extensive (and perhaps excessive) reference.

I participated in several online competitions and some abroad, it is a way to challenge yourself, to push yourself, to evaluate your knowledge, resulting in improvement, to train, to learn from the challenges of others.
I heard from many people that you are organizing such a competition in order for the co-organizing company to find employees, for UCLan to gather students, and so on. Maybe! I agree in part, but on the other hand, such a competition needed to be organized in Cyprus.
Those of us who consider ourselves “experts” need to, in this digital age we live in, provide proper Security Awareness, promote the field of information security and penetration testing, and correct the half‑knowledge regarding the term hacker.
I went to UCLan from 9 a.m. as a representative of the Cypriot Chapter of (ISC)² to inform attendees about the activities of (ISC)² in Cyprus as well as the CISSP certifications, etc. In addition I took on helping as the videographer of the whole event, since I thought the whole symposium should be recorded in a video. It should be noted that it was filmed with my personal camera without special care and professionalism, which is why there are many awkward distant shots and sometimes you lose the sound. Nevertheless there is documentation of the whole event.
From the morning there were quite a few people in the reception area and good organization during registration. It gave you the feeling of a well-organized event.
As announced in the agenda, the conference began with presentations related to information security.
Presentation by Andreas Loutsios on the Cyprus Computer Society.
The presentations clearly indicated some tips regarding the challenges and questions that the participants of the competition would face, which made them particularly interesting.
The competition started around 2:00pm, after lunch was provided. We don't see many free events offering food to participants, so kudos to the organizers!
Followed an opening speech for the competition, instructions to the contestants and here we go!! There were 3 rooms with computers equipped with virtual installation of Kali Linux.
The competition was controlled by “Mobby”, an automatic chat bot, which posed the questions and received the answers. For each correct answer it gave “100” points while for wrong ones it deducted “10”.
We should of course give credit to the organizers for the imaginative scenario of the competition questions. The overall idea was to prevent the criminal activity of the family “DeCavalcante”!!
The video wall at the entrance to the university was also quite impressive, displaying the score in real time.
UCLan Video wall (picture is not showing the final result)
I think it is important to mention that people with various experiences participated. Students, employees in IT companies, experienced security workers, experienced pen-testers, IT auditors, programmers and many others participated.
Congratulations to everyone who participated, and of course those who won the awards!
In conclusion, I would like to say a big thumbs up to the organizers for the
“1st Cyprus Pen-Test Competition”
As mentioned earlier, there is the related video of the event:
The bad things..
and suggestions for improvement:
At the end and after the awarding of the winners, the organizers had answered all the questions of the competition, and also gave the floor to the attendees to express their opinions.
Some of the suggestions that were made and some of my own:
Many people got stuck on one question and couldn't move on. You should be able to choose any question you want instead of getting stuck on the same one for a long time.
Each question should earn points based on its difficulty level. For example, someone could start with the question that is considered the most difficult and from there get 500 points, then the rest will make it harder for them. It requires a bit of thought and programming, but overall that is the idea.
Someone can take part with their own laptop, of course they should arrive earlier to connect to the network.
There should be fewer questions about cryptography and more that concern scanning, network attacks, web app attacks, exploitation, fuzzing, etc. All stages of penetration testing should be covered.
There should be an official event hashtag for us to send tweets, and to promote during the presentations 😉
We thank Andreas Konstantinidis for the timely and accurate information.
blog: https://medium.com/@acmegahz
twitter: @acmegahz




