I mentioned the Game Hacking Village CTF at DEF CON 34 in passing in a previous blog post. I want to dive in a bit deeper because I feel the CTF turned out awesome and you should play it. If you’d like to experience it yourself without spoilers beyond the hint about the CTF involving decades-old games, pause now and head over to gamehacking.gg – when registering, use that as the password. The CTF portions I led were the games NetHack and Zork which is what I’ll be waxing poetic about below.
Backing up a bit (in part to put some filler in for those who need a bit of buffer from the CTF explanations), I had previously set up a Capture The Flag environment thanks to copious aid from my TASBot Discord community as well as direct assistance from famed Binary Ninja / Vector 35 coding grand master Rusty Wagner. For that CTF, we set up PwnAdventure Z inside RemoteNES, a web-based Nintendo Entertainment System emulator that prevented users from accessing the ROM directly to extract flags from it. I was thankful for such awesome volunteers for that process as I’m the first to admit my skillset (impostor syndrome notwithstanding) has generally focused more on creatively breaking things than properly coding.
When Zetier opted to sponsor the Game Hacking Village (GHV) again this year, I hopped into the GHV Discord and saw they were looking for CTF content to place on a fake game store site they set up to act as the flag management platform. I proposed a few ideas and we tested several open-source games (like Spelunky) we could distribute, but what really got me excited as much as Dr. Stone was the idea of including the game NetHack. If you’ve never heard of NetHack, you may have heard the word it’s most known for; NetHack was essentially the first-ever roguelike game, initially released over four decades ago. (I was admittedly biased toward picking NetHack as I have been working on a Tool-Assisted Speedrun (TAS) of the game for more than a decade.)
Actually working out what flags to include in a game like NetHack proved challenging, as was the process of modifying the code in such an old game. I advocated for ensuring the flags could only be achieved when playing on a server, and we ultimately settled on deploying NetHack on a server with SSH access using dgamelaunch. Similar to the last time I organized a CTF, I still relied on colleagues and volunteers to help with some of the more onerous coding tasks, but this time around I was thankful for opportunities to get more involved in the code.
My colleague John put together code to allow flags in NetHack to be scored using the GHV CTF API, and my colleague Isam and I started adding flags. We realized we needed more help to have any hope of landing some of my notoriously ambitious ideas, so I pulled in actual NetHack devs, including ais523 and AntiGulp, as well as folks from the TASBot community like Ilari to lend a hand. We ultimately added over a dozen flags to NetHack itself and even managed to achieve my stretch goal of adding Zork to the CTF as well – more on that below. I found ways to tie the two games together with a couple of interrelated vulnerabilities along with a fun method Ilari put together in dgamelaunch itself.
On the ground, everything immediately fell apart as the DEF CON network essentially collapsed a few hours after the CTF started. We opted to pivot the whole dgamelaunch server to TASBot server infrastructure as an emergency measure. CTF participants started finding flags despite the challenges, and I was rather surprised to see some of the methods employed even early on.
Now is a good time to mention that every participant was warned on every dgamelaunch screen, both before and after logging in, that games were being recorded and could be watched by others:

One of the flags was to find a way to change that, but more than 90% of participants didn’t manage to disable the recording feature (see if you can poke around the CTF environment and figure it out; it’s a fun puzzle with some Easter eggs thrown in). The dgamelaunch watch menu allowed participants to observe other games in progress and spy on each other, and I’m able to share some of the techniques participants used thanks to the games being recorded as ttyrec terminal movie files. Looking at some of the methods used after the fact was quite enlightening and entertaining.
One of the moderately difficult NetHack flags involved creating antigold, as in a negative quantity of gold caused by overflowing the 32-bit signed integer used to store the player’s gold in inventory. I left several hints in the README file included with the NetHack source code distributed when selecting the games on the GHV CTF server, including links to the TASVideos NetHack game resources page and a TASVideos NetHack submission. The solution I used when creating the flag (and by extension my intended solution) was for participants to find some way to play back the TAS, which goes through an incredibly complex and absolutely hilarious-to-read series of steps involving repeatedly stoning a pet nymph to duplicate gold.
Instead of my intended solution, one of the teams worked out that the flag didn’t check to see if the game was in “wizard” debug mode, unlike some of the other flags we added. Talented NetHack dev AntiGulp herself aided in tweaking the game logic to prevent participants from just wishing for large sums of gold so in theory it shouldn’t have been possible to abuse, but never tell a dedicated CTF team what they can’t do. After entering wizard mode, they wished for “300000000 uncursed tallow candles” which seemed innocuous at first glance:

However, they were able to drop the candles inside a shop, resulting in the shopkeeper buying all of them and returning -647482480 gold (antigold):

We hadn’t considered participants bypassing the “wishing for gold” limit simply by wishing for an absurdly large number of something else suitably valuable and convincing a shopkeeper to buy it. (If finding fun exploits in NetHack intrigues you, we’d love help finishing up the TAS!)
There are several other flags for you to discover in NetHack, but I should also mention Zork, which gave us a couple of fun challenges to work with. If you’re not familiar with Zork, it is rooted in the tradition of text interactive fiction games from the 1970s, including Colossal Cave Adventure. It was ultimately carved up into multiple games as a commercial release, but I wanted to incorporate the original and complete 1970s mainframe version.
This had a notable effect – most guides online are for the commercial Zork 1, Zork 2, and Zork 3 releases. Isam found AI agents became tripped up when trying to play the game while we were testing, in part because the original release was named Dungeon. We opted to add some clues throughout the dgamelaunch environment to help guide participants in the right direction; I feel the challenge of a CTF should be the difficulty of working through the logic rather than searching for obscure references. We found a good balance as every Zork flag was achieved at least once. Ironically, the solution I expected to see used in the aforementioned NetHack antigold flag was used by a couple of enterprising CTF participants for Zork, pasting in sequences of keystrokes to complete portions of the game rapidly.
At the end of the event, the GHV CTF was selected by DEF CON organizers for a notable prize: out of 80 official competitions, only 10 won black badges for DEF CON 34, and one of those picked was the GHV CTF. Just to say it, a huge amount of that credit goes to the GHV folks who put the store page together and worked tirelessly to incorporate a flag server. I also couldn’t have done this without so many volunteers from my TASBot community as well as NetHack devs themselves. For my part, I’m thankful I was able to contribute, even if some of the CTF participants bypassed some of my carefully laid intended solutions.
If you’re the type of person who loves to find non-standard approaches to doing something, you might enjoy talking with a few of my Zetier colleagues. Check out Zetier.com/careers or drop us a note at hello@zetier.com. Zetier is always on the lookout for vulnerability researchers.