Skip to content

Handbook

Technique-first chapters on capture-the-flag. Each one teaches a method you can apply the same night - how to recognise it, why it works, and where the shortcut lives inside ctfpal. No war stories, no tool dumps, no “install these forty repos”.

Looking for solved challenges instead? The writeup index maps each technique to a canonical walkthrough.

Method & misc

How to triage anything, how to read a design for its intended flaw, and the categories that fit nowhere else - OSINT, esolangs, AI, hardware, side channels, and smart contracts.

Crypto

Classical statistics, XOR, RSA, discrete logs and curves, block cipher modes, hashes, and the random number generators that were never random.

Web

Recon, then the injection classes, then the ones that are not injection at all - traversal, upload, race conditions, desync, and the browser's own trust rules.

Binary exploitation

The stack, the heap, format strings, integer arithmetic, shellcode, and fuzzing your way to the crash in the first place.

Reversing

Native binaries, managed bytecode, WebAssembly, Android, firmware, and the anti-analysis tricks written specifically to slow you down.

Forensics

Disk images, memory dumps, packet captures, documents, archives, logs, boot records, and repositories that were never meant to be public.

Stego

Images, audio, and text - three carriers, one layered workflow each.