Mason Competitive Cyber / en Cybersecurity students prepare for inaugural DistrictCon Hacker Conference /news/2025-01/cybersecurity-students-prepare-inaugural-districtcon-hacker-conference <span>Cybersecurity students prepare for inaugural DistrictCon Hacker Conference </span> <span><span>Shayla Brown</span></span> <span>Mon, 01/27/2025 - 12:21</span> <div class="layout layout--gmu layout--twocol-section layout--twocol-section--70-30"> <div class="layout__region region-first"> <div data-block-plugin-id="field_block:node:news_release:body" class="block block-layout-builder block-field-blocknodenews-releasebody"> <div class="field field--name-body field--type-text-with-summary field--label-visually_hidden"> <div class="field__label visually-hidden">Body</div> <div class="field__item"><p><span class="intro-text">Students from ŃÇÖȚAV’s <a href="https://competitivecyber.club/" target="_blank">Competitive Cybersecurity </a>(MCC) club have dominated in multiple national competitions. The team got 1st place in the 2024 VMI CyberFusion and 2nd place in the 2024 Spring National Cyber League. </span></p> <p><span class="intro-text">Next, the students will be competing in the inaugural <a href="https://www.districtcon.org/" target="_blank">DistrictCon Hacker Conference on February 21-22.</a> </span></p> <figure role="group"><div> <div class="field field--name-image field--type-image field--label-hidden field__item"> <img src="/sites/g/files/yyqcgq291/files/styles/medium/public/2025-01/danny_dylan.jpg?itok=CDMez0x4" width="560" height="382" alt="Club president Dylan Knoff working on routers. Photo provided." loading="lazy" /></div> </div> <figcaption>Club president Dylan Knoff working on routers. Photo provided.</figcaption></figure><p>“We'll be presenting live demos with our exploits in front of a judge and audience. So, we'll basically go from not having access to a certain device to showing that we can get access in the eight different attack vectors that we discovered,” said club president Dylan Knoff, a junior <a href="https://cs.gmu.edu/" target="_blank">computer science</a> major. </p> <p>This demonstration is known as the <a href="https://www.districtcon.org/" target="_blank">junkyard competition</a>, and the device they’re hacking is a router. In preparation for the demo, the team is conducting multiple analyses and rehearsing talking points for verification of their research. </p> <p>“We basically ripped the firmware off of it, which is the code that runs on embedded devices like this one,” said Knoff, who participated in the <a href="https://icc.ecsc.eu/" target="_blank">International Cybersecurity Championship</a> in Chile with the U.S. Cyber Team. </p> <p>“We utilized hardware debugging interfaces on the device to both find potential bugs by analyzing our own local copy of the firmware and confirm their existence and exploitability by trying to trigger them on the live device and utilizing the debug interface exposed,” he said. </p> <p>In addition to Knoff, his teammates Danyaal Shaozab and <a href="https://www.linkedin.com/in/ryan-murphy-a37435293/">Ryan Murphy</a> will also participate in the junkyard competition and other cybersecurity challenges including “capture the flag,” also called CTF, where the teams receive challenges, such as web app exploitation, binary exploitation, cryptography, reverse engineering, forensics, and a description that they must solve and then get a flag that is redeemed for points. </p> <p>In September 2023, MCC hosted its own international CTF event, attracting more than 3,000 participants and 1,600 teams as well as hosted PatriotCTF 2024 attracting over 5400 participants and 2200 teams. The club practices are offensive cybersecurity, which is a type of ethical hacking used to evaluate and determine a system’s security, Murphy explained. </p> <figure role="group" class="align-right"><div> <div class="field field--name-image field--type-image field--label-hidden field__item"> <img src="/sites/g/files/yyqcgq291/files/styles/medium/public/2025-01/ryan.jpg?itok=uGweKVy2" width="315" height="560" alt="Club member Ryan Murphy working on routers. Photo provided." loading="lazy" /></div> </div> <figcaption>Club member Ryan Murphy working on routers. Photo provided.</figcaption></figure><p>Murphy, who transferred to George Mason from Virginia Peninsula Community College as a part of the Mason Virginia Promise, has been passionate about cybersecurity since middle school and participated in CyberPatriot, a national youth cyber education program. </p> <p>“I'm still pretty new at George Mason, but it's been a really good experience so far,” said Murphy, a junior <a href="https://cybersecurity.gmu.edu/" target="_blank">cyber security engineering</a> major. “I got involved with the club from the get- go because they're a bunch of like-minded people and I’m really grateful for the opportunities the club and the university have offered me.”</p> <p>The team will have two time slots and two presentations. They plan to do a dry run the day before the conference, as well as more analysis to solidify the information, said Murphy. </p> <p>Shaozab is currently working as an associate vulnerability researcher at TFP0 Labs, a Reston-based security research firm. Shaozab’s role entails finding and exploiting vulnerabilities of various security systems and he compares his professional responsibilities to that of his club and school assignments.  </p> <p>“Working with Dylan and Ryan is great. We all have similar career goals, and it makes projects and assignments a lot easier,” said Shaozab, who is a senior cyber security engineering major. </p> <p>Shaozab credits his courses, including CYSE 465 Transportation Systems Design, for helping him prepare for the upcoming competition.  </p> <p>“<a href="https://cybersecurity.gmu.edu/profiles/marafin" target="_blank">Dr. [Tanvir] Arafi</a> is a very smart professor and a very talented individual in this field. His course really helped me hone my cyber techniques,” he said.  </p> <p>Shaozab explained that the team is focused on exploiting the [Control Area Network] bus, which is like the nervous system of a vehicle, allowing different components like the engine, brakes, and doors to communicate with each other. “Exploiting it involves sending malicious messages in the CAN bus to manipulate the car's function, such as unlocking doors or starting the engine,” he said. </p> <p>“What made this particularly interesting to me is that I'm a huge car enthusiast, so being able to merge my passion for cars and cybersecurity was a unique experience. Getting hands-on with that in a classroom setting made it even more engaging. It’s rare to get that kind of knowledge taught in schools,” he said. </p> </div> </div> </div> </div> <div class="layout__region region-second"> <div data-block-plugin-id="inline_block:text" data-inline-block-uuid="df38375b-4533-4bfd-a9d3-27a129cc934a" class="block block-layout-builder block-inline-blocktext"> </div> <div data-block-plugin-id="inline_block:call_to_action" data-inline-block-uuid="2b035e8b-3645-45b5-8dda-6d1307989667"> <div class="cta"> <a class="cta__link" href="https://cec.gmu.edu/"> <h4 class="cta__title">Learn more about George Mason's College of Engineering and Computing <i class="fas fa-arrow-circle-right"></i> </h4> <span class="cta__icon"></span> </a> </div> </div> <div data-block-plugin-id="inline_block:text" data-inline-block-uuid="addaca1f-0277-41cf-87f4-c32db70bfdaa" class="block block-layout-builder block-inline-blocktext"> <div class="field field--name-body field--type-text-with-summary field--label-hidden field__item"><p> </p> <p> </p> </div> </div> <div data-block-plugin-id="inline_block:news_list" data-inline-block-uuid="d7972315-0a34-4ca2-9cbe-f35d15c10356" class="block block-layout-builder block-inline-blocknews-list"> <h2>Related Stories</h2> <div class="views-element-container"><div class="view view-news view-id-news view-display-id-block_1 js-view-dom-id-a4f93ca9002caa6a61097ff11ba2220cb0e3a510ca36e23de934d869ab9e6b17"> <div class="view-content"> <div class="news-list-wrapper"> <ul class="news-list"><li class="news-item"><div class="views-field views-field-title"><span class="field-content"><a href="/news/2025-02/keeping-data-safe-keeping-it-separate" hreflang="en">Keeping data safe by keeping it separate </a></span></div><div class="views-field views-field-field-publish-date"><div class="field-content">February 25, 2025</div></div></li> <li class="news-item"><div class="views-field views-field-title"><span class="field-content"><a href="/news/2025-01/unlocking-privacy-encrypted-ingenuity-security-expert-receives-nsf-career-award" hreflang="en">Unlocking privacy with encrypted ingenuity: Security expert receives NSF CAREER award </a></span></div><div class="views-field views-field-field-publish-date"><div class="field-content">January 27, 2025</div></div></li> <li class="news-item"><div class="views-field views-field-title"><span class="field-content"><a href="/news/2025-01/cybersecurity-students-prepare-inaugural-districtcon-hacker-conference" hreflang="en">Cybersecurity students prepare for inaugural DistrictCon Hacker Conference </a></span></div><div class="views-field views-field-field-publish-date"><div class="field-content">January 27, 2025</div></div></li> <li class="news-item"><div class="views-field views-field-title"><span class="field-content"><a href="/news/2025-01/podcast-ep-64-navigating-ais-risks-and-rewards" hreflang="en"> Podcast — EP 64: Navigating AI’s risks and rewards</a></span></div><div class="views-field views-field-field-publish-date"><div class="field-content">January 21, 2025</div></div></li> <li class="news-item"><div class="views-field views-field-title"><span class="field-content"><a href="/news/2025-01/using-ai-uncover-human-smuggling-networks" hreflang="en">Using AI to uncover human smuggling networks </a></span></div><div class="views-field views-field-field-publish-date"><div class="field-content">January 16, 2025</div></div></li> </ul></div> </div> </div> </div> </div> <div data-block-plugin-id="inline_block:text" data-inline-block-uuid="4f2aa54e-4966-41b0-894e-917da46cd74c" class="block block-layout-builder block-inline-blocktext"> <div class="field field--name-body field--type-text-with-summary field--label-hidden field__item"><p> </p> <p> </p> </div> </div> <div data-block-plugin-id="field_block:node:news_release:field_content_topics" class="block block-layout-builder block-field-blocknodenews-releasefield-content-topics"> <h2>Topics</h2> <div class="field field--name-field-content-topics field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">Topics</div> <div class="field__items"> <div class="field__item"><a href="/taxonomy/term/3071" hreflang="en">College of Engineering and Computing</a></div> <div class="field__item"><a href="/taxonomy/term/3056" hreflang="en">Cybersecurity</a></div> <div class="field__item"><a href="/taxonomy/term/10431" hreflang="en">Mason Competitive Cyber</a></div> <div class="field__item"><a href="/taxonomy/term/15796" hreflang="en">Mason Virginia Promise</a></div> <div class="field__item"><a href="/taxonomy/term/336" hreflang="en">Students</a></div> <div class="field__item"><a href="/taxonomy/term/4066" hreflang="en">Tech Talent Investment Program (TTIP)</a></div> </div> </div> </div> </div> </div> <div class="layout layout--gmu layout--twocol-section layout--twocol-section--30-70"> <div> </div> <div> </div> </div> Mon, 27 Jan 2025 17:21:53 +0000 Shayla Brown 115461 at Cyber savant hacks his way onto international team /news/2024-12/cyber-savant-hacks-his-way-international-team <span>Cyber savant hacks his way onto international team</span> <span><span>Nathan Kahl</span></span> <span>Tue, 12/03/2024 - 11:48</span> <div class="layout layout--gmu layout--twocol-section layout--twocol-section--30-70"> <div class="layout__region region-first"> </div> <div class="layout__region region-second"> <div data-block-plugin-id="field_block:node:news_release:body" class="block block-layout-builder block-field-blocknodenews-releasebody"> <div class="field field--name-body field--type-text-with-summary field--label-visually_hidden"> <div class="field__label visually-hidden">Body</div> <div class="field__item"><p><span><span><span><span><span><span><span><span class="intro-text">Dylan Victor Knoff is president of the <a href="https://competitivecyber.club" title="MCC">Mason Competitive Cyber (MCC) club</a>, a computer science major, and the kind of self-motivated hacker you might see rummaging through Goodwill bins, in his free time looking for a $4 router that he can use to bolster his resume.</span> </span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span><strong>“</strong>I’ll pull it apart and take the firmware off the chip. It's good fun, responsibly and ethically doing stuff to it, of course, and then reporting vulnerabilities,” he said. </span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>The ŃÇÖȚAV junior likes to examine routers because they are more likely than other devices to have detectable problems. Once he finds a vulnerability, per industry practice, he reports it to the vendor and then <a href="https://www.mitre.org" title="MITRE">MITRE</a>, the nonprofit that that catalogs firmware and software problems. Getting a mention on their common vulnerabilities and exposures listing looks good professionally for young cyber sleuths. </span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>This ambition to make the cyber world a better, safer place is a theme in Knoff’s life. First, he started a Capture the Flag (CTF) team during high school, and then he attended a university cyber club while still a teen. When the Orlando native and first-gen college student could have chosen the local University of Central Florida, instead he left home for George Mason, recognizing the university’s prowess in the field and the benefit of being close to potential employers in the Washington, D.C., metropolitan region. Knowing that breaking into cybersecurity is no Mickey Mouse endeavor, shortly after arriving in Fairfax he networked with the <a href="https://www.battelle.org" title="Battelle">Battelle</a> intern coordinator and subsequently landed a paid, full-time co-op with the STEM giant. </span></span></span></span></span></span></span></p> <figure role="group" class="align-left"><div> <div class="field field--name-image field--type-image field--label-hidden field__item"> <img src="/sites/g/files/yyqcgq291/files/styles/small_content_image/public/2024-12/screen_shot_2024-12-03_at_11.56.00_am.png?itok=Fw9nYe6M" width="330" height="350" alt="Young man stands on a rocky trail" loading="lazy" /></div> </div> <figcaption>When he's not hacking routers, Knoff enjoys Shenandoah National Park</figcaption></figure><p><span><span><span><span><span><span><span>Knoff is on the U.S. Cyber Team and in October competed at the International Cybersecurity Challenge in Santiago, Chile. He said, “We competed against other countries’ teams in a two-day CTF, where one day was attack-and-defend, and the second day was on vulnerability assessment and exploit development.”</span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>Knoff’s research focus is reverse engineering and vulnerability research. “I'll find something wrong with a specific device or framework and I'll find a ‘zero day,’ which is a vulnerability that is unknown to the vendor, and then I'll disclose it to them,” he said, indicating the standard industry practice. </span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>For next year’s <a href="https://www.districtcon.org" title="District Con">DistrictCon</a>, a hacker conference in Washington, D.C., in February, Knoff and two members of MCC participated in the Junkyard Contest, where participants find vulnerabilities in devices; they discovered a stunning eight zero days on one router. </span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>Knoff is giving a separate talk at the conference, on return-oriented programming, a way that hackers can get into a system by reusing code that already exists in a program. “I made this tool that utilizes computer emulation to analyze and visualize the memory side effects of elements that make up a return-oriented attack. Using data aggregation, these elements are then sorted based on their exploitation effects and made easily searchable to an operator.” He made the<strong> </strong>tool open source, available to anyone on GitHub, and is releasing an updated version the day of the talk.</span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>On rare days when he’s not at a keyboard, Knoff enjoys getting outside, especially for a hike. “I love going to Shenandoah with my friends, doing Old Rag and White Oak,” he said, referencing two of the more popular—and challenging—Shenandoah National Park trails. </span></span></span></span></span></span></span></p> <p><span><span><span><span><span><span><span>Currently he’s entertaining offers for two new co-ops, with the hopes of potentially spinning one of those into full-time employment. And whether scaling digital peaks or the rugged trails of Shenandoah, Knoff will find himself climbing
toward discovery and solutions in a safer cyber world.</span></span></span></span></span></span></span></p> </div> </div> </div> <div data-block-plugin-id="field_block:node:news_release:field_content_topics" class="block block-layout-builder block-field-blocknodenews-releasefield-content-topics"> <h2>Topics</h2> <div class="field field--name-field-content-topics field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">Topics</div> <div class="field__items"> <div class="field__item"><a href="/taxonomy/term/3346" hreflang="en">Cyber Security</a></div> <div class="field__item"><a href="/taxonomy/term/10431" hreflang="en">Mason Competitive Cyber</a></div> <div class="field__item"><a href="/taxonomy/term/2186" hreflang="en">computer science</a></div> <div class="field__item"><a href="/taxonomy/term/4066" hreflang="en">Tech Talent Investment Program (TTIP)</a></div> <div class="field__item"><a href="/taxonomy/term/336" hreflang="en">Students</a></div> </div> </div> </div> </div> </div> Tue, 03 Dec 2024 16:48:51 +0000 Nathan Kahl 115026 at Mason Competitive Cyber scores multiple wins at CyberForge 2024  /news/2024-02/mason-competitive-cyber-scores-multiple-wins-cyberforge-2024 <span>Mason Competitive Cyber scores multiple wins at CyberForge 2024 </span> <span><span>Martha Bushong</span></span> <span>Wed, 02/14/2024 - 12:50</span> <div class="layout layout--gmu layout--twocol-section layout--twocol-section--30-70"> <div class="layout__region region-first"> <div data-block-plugin-id="field_block:node:news_release:field_associated_people" class="block block-layout-builder block-field-blocknodenews-releasefield-associated-people"> <h2>In This Story</h2> <div class="field field--name-field-associated-people field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">People Mentioned in This Story</div> <div class="field__items"> <div class="field__item"><a href="/profiles/pcosta" hreflang="und">Paulo Costa</a></div> </div> </div> </div> </div> <div class="layout__region region-second"> <div data-block-plugin-id="field_block:node:news_release:body" class="block block-layout-builder block-field-blocknodenews-releasebody"> <div class="field field--name-body field--type-text-with-summary field--label-visually_hidden"> <div class="field__label visually-hidden">Body</div> <div class="field__item"><p><span class="intro-text">The ŃÇÖȚAV team Mason Competitive Cyber scored first, second, and fourth place at the <a href="https://cyberforge.cvcsa-cyber.org/">Cyberforge 2024</a> competition held on February 11-12. During the two-day conference students heard from industry professionals and enhanced their cyberskills by competing in the Capture the Flag (CTF) competition. </span></p> <div class="align-right"> <div class="field field--name-image field--type-image field--label-hidden field__item"> <img src="/sites/g/files/yyqcgq291/files/styles/small_content_image/public/2024-02/masoncc_2024.png?itok=5hJvzoJx" width="350" height="350" alt="group shot from event" loading="lazy" /></div> </div> <p>“Winning a Virginia-wide competition is pretty good news by itself,” said <a href="https://volgenau.gmu.edu/academics/cyber-security-engineering-department">Cyber Security Engineering Department</a> Chair <a href="https://volgenau.gmu.edu/profiles/pcosta">Paulo Costa</a>. “CyberForge is especially important due to the quality of the teams, the level of effort every team and associated organizations/universities put into it, and the impact it has in the Virginia cybersecurity space."</p> <p>Costa consider this one of the two most important competitions in the area. The other is Virginia Military Institute’s Cyber Fusion event happening later this month on February 23-24.</p> <p>The Cyberforge event featured companies such as MITRE, CCI, G2OPS, HAK5, CompTIA, Virginia Cyber Range, WiCyS, TCM Security, and more. The Mason students competed against top collegiate teams and industry professionals from around Virginia. Students value competitions as these events allow them to meet talented students and industry professionals outside their home institution. </p> <p>The team won multiple different prizes, including but not limited to Canakit raspberry pi 5 kits, CompTIA vouchers, and HAK5 gift cards, but they are most proud of the winner’s plaque, which they hope to display in the department’s office. </p> <p>The event was hosted by the <a href="https://www.cvcsa-cyber.org/" target="_blank">Coastal Virginia Cybersecurity Student Association (CVCSA),</a> Coastal Virginia Commonwealth Cyber Initiative (COVA CCI), and a local college/university's cybersecurity club. </p> </div> </div> </div> <div data-block-plugin-id="field_block:node:news_release:field_content_topics" class="block block-layout-builder block-field-blocknodenews-releasefield-content-topics"> <h2>Topics</h2> <div class="field field--name-field-content-topics field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">Topics</div> <div class="field__items"> <div class="field__item"><a href="/taxonomy/term/3056" hreflang="en">Cybersecurity</a></div> <div class="field__item"><a href="/taxonomy/term/6886" hreflang="en">Department of Cyber Security Engineering</a></div> <div class="field__item"><a href="/taxonomy/term/10431" hreflang="en">Mason Competitive Cyber</a></div> <div class="field__item"><a href="/taxonomy/term/336" hreflang="en">Students</a></div> <div class="field__item"><a href="/taxonomy/term/7171" hreflang="en">Tech Talent Investment Pipeline (TTIP)</a></div> <div class="field__item"><a href="/taxonomy/term/18541" hreflang="en">TTIP</a></div> <div class="field__item"><a href="/taxonomy/term/19491" hreflang="en">Tech Talent Investment Program</a></div> </div> </div> </div> </div> </div> Wed, 14 Feb 2024 17:50:37 +0000 Martha Bushong 110686 at Mason Competitive Cyber heads to national competition for the first time /news/2021-04/mason-competitive-cyber-heads-national-competition-first-time <span>Mason Competitive Cyber heads to national competition for the first time</span> <span><span>Anonymous (not verified)</span></span> <span>Tue, 04/13/2021 - 12:41</span> <div class="layout layout--gmu layout--twocol-section layout--twocol-section--30-70"> <div class="layout__region region-first"> </div> <div class="layout__region region-second"> <div data-block-plugin-id="field_block:node:news_release:body" class="block block-layout-builder block-field-blocknodenews-releasebody"> <div class="field field--name-body field--type-text-with-summary field--label-visually_hidden"> <div class="field__label visually-hidden">Body</div> <div class="field__item"><p>ŃÇÖȚAV’s competitive cyber club is headed to the National Collegiate Cyber Defense Competition (NCCDC) after beating out intense competition in a nationwide wildcard round.  </p> <p>Mason Competitive Cyber is a team of undergraduate students from different majors who spend their free time competing in various cyber competitions. Last year, the team won the CyberFusion State Cup, where they competed against all the universities in Virginia.  </p> <p>This year is the first time the team has advanced to the NCCDC since their first appearance in 2019. “There are two general kinds of competitions: jeopardy and attack-defense. MCC has traditionally excelled in the Jeopardy competitions.  CCDC is an Attack-Defense competition.  In 2019, MasonCC competed in the Mid-Atlantic CCDC for the very first time.  That year we did not make it out of the qualifier round,” says Caleb Yu, vice president for the club.  </p> <p>After their initial loss, some team members weren’t sure if this was the competition for them. But they came back in 2020 and placed higher in their region. The nine regions of the country take the first-place winner from the regional competitions, and this year the team won second place for their region. </p> <p>“Since we won second, we qualified for a wildcard round.  We competed against the eight other second-place teams from the other regions.  Once again, only the first-place team advances to the national finals,” says Yu.  </p> <p>The MCC team pulled out the win, coming in first, with Stanford University’s team taking second. “Stanford got third place in the national competition last year.  When we noticed that they were also in the wildcard round, we knew that we'd have some fierce competition. It feels awesome to have advanced in place of a team that could have been seen as a heavy favorite,” he says.  </p> <p>The team will compete on April 23 through 25 against the top teams from across the country. “We are expecting some fierce competition from the other schools, but our confidence has never been higher,” says Yu.  </p> </div> </div> </div> <div data-block-plugin-id="field_block:node:news_release:field_content_topics" class="block block-layout-builder block-field-blocknodenews-releasefield-content-topics"> <h2>Topics</h2> <div class="field field--name-field-content-topics field--type-entity-reference field--label-visually_hidden"> <div class="field__label visually-hidden">Topics</div> <div class="field__items"> <div class="field__item"><a href="/taxonomy/term/10431" hreflang="en">Mason Competitive Cyber</a></div> <div class="field__item"><a href="/taxonomy/term/3056" hreflang="en">Cybersecurity</a></div> <div class="field__item"><a href="/taxonomy/term/7076" hreflang="en">Student news</a></div> <div class="field__item"><a href="/taxonomy/term/6836" hreflang="en">student organizations</a></div> </div> </div> </div> </div> </div> Tue, 13 Apr 2021 16:41:37 +0000 Anonymous 81551 at