TERMS & CONDITIONS // RULES OF ENGAGEMENT
Official terms of engagement, team eligibility standards (max 3 members), anti-DDoS mandates, and code of conduct governing all participants of Breach Point II.
THE 6 RULES OF ENGAGEMENT
These 6 core non-negotiable standards must be upheld by all participating teams and individual operatives.
- 1.
Target Sandbox Only — Zero DDoS / Flooding
Only attack designated challenge containers and IP ranges. Any DoS/DDoS, network flooding, brute-forcing the scoring platform/API, or attacking university infrastructure results in an instant permanent ban.
- 2.
No Flag Sharing or Collusion
Flags and solutions must be your team’s independent work. Sharing flags, trading hints, pooling solutions with other teams, or buying answers is strictly prohibited.
- 3.
Team Limit (Max 3 Members) & Authentic Credentials
Teams are strictly limited to a maximum of 3 verified members. No duplicate accounts, burner emails, impersonation, or ghost players are permitted.
- 4.
Competitor Safety & Challenge Isolation
Never target other competitors' machines, personal devices, or VPN traffic. Do not tamper with, delete flags, or break service daemons on shared challenge instances.
- 5.
Responsible Tooling & Rate Limiting
Keep automated tools (gobuster, ffuf, dirsearch) throttled. Challenges never require high-thread directory busting, password guessing, or server resource exhaustion.
- 6.
No Spoilers & Final Marshal Authority
Do not publish write-ups, hints, or solution streams until the scoreboard is officially frozen. CTF Marshals hold full authority to audit logs and issue unappealable disqualifications.
COMPETITION TERMS & CONDITIONS
Detailed contractual and legal provisions governing participation in Breach Point II.
1. Acceptance of Terms & Legal Binding
By registering an account, forming a team, or accessing the Breach Point II arena at ctf.breachpoint.live, all participants agree to be legally bound by these Terms & Conditions, the Rules of Engagement, and the official decisions of the Organizing Committee and CTF Marshals.
2. Eligibility & Team Roster Verification (Max 3 Members)
Participation is open to verified students, researchers, and cybersecurity enthusiasts nationwide. Teams may consist of 1 to 3 registered members (maximum 3 members per team). All team members must provide authentic credentials (full legal name, verifiable institutional email address, phone number). Impersonation, multiple account registrations by the same individual, or submitting false academic affiliation is strictly prohibited and results in immediate disqualification.
3. Scope of Engagement & Prohibited Cyber Attacks (Strict Anti-DDoS)
Participants are strictly permitted to target only designated challenge instances and designated challenge IP ranges. Any Denial of Service (DoS/DDoS), network flooding, unauthorized scanning of campus/university networks, ARP spoofing, router attacks, or brute-forcing scoring engines and portal APIs is strictly illegal and will trigger instant blacklisting and formal reporting to academic deans.
4. Anti-Collusion, Flag Sharing & Leaks
Flags and solutions must be generated solely through your team's independent analysis. Trading flags, purchasing solutions, sharing exploit tokens, or collaborating across distinct teams is prohibited. Publicly posting writeups, hints, or solution videos before the official competition closure and scoreboard freeze is strictly forbidden.
5. Marshal Authority & Disqualification Powers
The CTF Head Marshals retain uninhibited authority to monitor solve timestamps, inspect traffic patterns, review server access logs, and audit submission entropy. The Organizing Committee reserves the right to freeze scores, invalidate solves, disqualify teams, and revoke certificates without appeal in cases of confirmed violations.
6. Limitation of Liability & Educational Charter
Breach Point II is organized strictly for educational, academic, and ethical skill-development purposes. Malla Reddy University and Cyber Fortress Club assume no legal responsibility or liability for any participant's unauthorized actions or misuse of security tools outside the designated CTF sandbox environment.