SecDim AppSec Village Wargame: Fix the Flag
The SecDim AppSec Village Wargame is a hybrid secure coding competition that blends application security engineering, adversarial thinking, and live head-to-head play. Unlike a traditional CTF, where the goal is usually to exploit a target and capture a flag, this activity asks competitors to first fix vulnerable software correctly, keep intended functionality intact, and then compete in a live attack-and-defence setting. SecDim frames it as an attack-and-defence CTF focused on secure coding challenges inspired by real incidents, where players are expected to remediate vulnerabilities, not just exploit them.
Types of Challenges:
How to submit:
To get started, follow this link to create a GitHub repo containing your future challenge. Accepting the link will automatically create a private repository for you, pre-configured with CI tests via GitHub Actions.
Then fill out the submission form including the vulnerability or technique at its heart, the intended difficulty, and what makes it stand out.
From there, you'll develop your challenge directly in the repository — including the challenge itself, a patch, and tests that confirm everything works as expected. When you're ready, open a pull request to submit for final review. Our team will go through your challenge, patch, and tests, and communicate any feedback directly through the PR.
Once your proposal is reviewed and approved, you shall receive a notification via email and Sessionize.
We look forward to seeing what you build!
PLEASE NOTE: As a non-profit, volunteer-run organization, we are guests at DEF CON and are unable to cover conference fee, travel or accommodation expenses.
If you haven't logged in before, you'll be able to register.
Using social networks to login is faster and simpler, but if you prefer username/password account - use Classic Login.