RunHacks Rules of Engagement
Read this before you start a challenge. It applies to every account, every challenge, and every tool you point at us.
What this document is
This page is our authorization statement. It tells you exactly which systems you may attack, which ones you may not, and what behaviour gets your account closed. When you use RunHacks you agree to work inside these limits.
The authorization here covers systems RunHacks owns and operates, and it covers them only for the purpose of playing our challenges. Nothing on this page authorizes you to touch anyone else's systems. If a challenge mentions a company, a person, or a domain, it is fiction we wrote. Real organizations with similar names are not part of the game and are not in scope.
Authorization is per account and is not transferable. It ends the moment your account is suspended or closed.
In scope
You are authorized to probe, scan, enumerate, fuzz, reverse engineer, and social-engineer the following. This includes talking your way past the AI characters that guard them.
- The challenge sites. greyfern.dev, archoninstitute.com, beltwaysignal.com, and any other site a challenge briefing points you at, including their web apps, APIs, and published content.
- The RunHacks mail server. SMTP and IMAP on mail.runhacks.sh, using your own credentials. Send mail to challenge characters, read the replies, and inspect the protocol as much as you like. It is a closed system: nothing arrives from the public internet and nothing you send leaves, so forge senders and pretext freely. The mail guide covers how to connect and what gets refused.
- The RunHacks file server. Read-only SFTP on runhacks.sh port 2222, using an SSH key you enrolled. Read your own files, poke at the protocol, and see what the server refuses. The SSH key guide covers how to connect.
- The AI characters. Prompt injection, pretexting, impersonating someone in the fiction, phishing a character, and any other manipulation of an in-challenge persona is the point of the exercise. Go ahead.
- Your own account's data. Your mailbox, your files, your API keys, your challenge progress.
Out of scope
These are not targets. Attacking them is not a flag, it is a violation.
- runhacks.sh itself. Authentication, sessions, OAuth, billing, the admin interface, and the challenge engine that scores you.
- The database. Any attempt to read, modify, or dump platform storage directly, including flag definitions and other players' records.
- Other players. Their accounts, mailboxes, files, sessions, and API keys. Player mailboxes are real mailboxes. Leave them alone.
- The infrastructure underneath. The hosts, containers, orchestration, cloud accounts, DNS, CI, and any provider we run on.
- Anything we do not own. If a domain, service, or person is not listed in a challenge briefing as a target, treat it as out of scope. Third-party services that a challenge happens to reference are not fair game.
If you cannot tell whether something is in scope, assume it is not, and ask before you touch it.
Prohibited
These rules apply everywhere, including inside challenges that are otherwise in scope.
- No denial of service. No volumetric floods, no resource exhaustion, no deliberately degrading a service for other players.
- No high-rate automated scanning. Automate what you like, but keep it slow enough that a human could plausibly be driving it. If your tooling makes a service slow or unstable, you have gone too far. Default scanner profiles are usually too aggressive.
- No pivoting to third parties. Credentials, tokens, addresses, or hostnames you discover here are for use here. Do not test them anywhere else. A credential that works on a real external service is a bug to report, not a lead to follow.
- No publishing flags or solutions. Do not post flag values, writeups, or step-by-step solutions publicly. Hints and general technique discussion are fine. Spoiling the puzzle ruins it for everyone behind you.
- No smuggling mail out of RunHacks. Every recipient has to exist inside RunHacks or a challenge's fiction; the server refuses anything else. Testing that boundary is fair game, but if you actually get a message delivered to a real address on the outside, that is a vulnerability to report rather than a flag. Don't bulk-mail other players either.
- No destroying evidence or shared state. Do not delete, corrupt, or lock out data that other players depend on.
- No harassment. The characters are fiction and you can be as ruthless with them as you like. Real people, including our staff, are not part of the game.
What we expect from you
- Bring your own tools. Run them from your own machine against the targets. We do not provide a shell to attack from, and we do not want you using our platform as a launch point for anything else.
- Remember the services are real. The story is invented. The mail server, the APIs, and the sites are live software running on shared infrastructure. Treat them the way you would treat a client's staging environment during an engagement.
- Stay in your own account. One account per person. Do not share credentials or API keys.
- Take the smallest step that proves the point. Once you have shown something works, stop. You do not need to escalate further to earn the flag.
Found a real security issue?
Sometimes you will find something that is not part of a challenge: a way into another player's mailbox, a hole in our authentication, a path into the infrastructure. That is a genuine vulnerability, not a flag.
Stop, do not exploit it further, do not read data that is not yours, and mail security@runhacks.sh with what you did and what you saw. We will confirm receipt and keep you updated. Reporting in good faith will never get you in trouble here, and we would much rather hear it from you.
If you break the rules
We may suspend or close your account, revoke your API keys, and remove your flags. Serious or deliberate violations, especially anything that harms another player or a third party, may be reported to the appropriate authorities. Activity outside the scope defined above is not authorized by us and you are on your own for it, legally and otherwise.
Changes
We will update this page as the platform grows and new challenges land. Check back before you start a new challenge. The version in force is the one published here.
RunHacks OS v1.0 · kernel rh-tui 0.9.2 · build 2026.08.25 · about RunHacks