Handbook
Technique-first chapters on capture-the-flag. Each one teaches a method you can apply the same night - how to recognise it, why it works, and where the shortcut lives inside ctfpal. No war stories, no tool dumps, no “install these forty repos”.
Looking for solved challenges instead? The writeup index maps each technique to a canonical walkthrough.
Method & misc
How to triage anything, how to read a design for its intended flaw, and the categories that fit nowhere else - OSINT, esolangs, AI, hardware, side channels, and smart contracts.
- miscrevised August 12, 20267 min
Smart contract challenges: reentrancy, storage, and the EVM
Blockchain CTF without the jargon. Reading a contract you only have bytecode for, the storage slot that is public whether or not the variable is, reentrancy and delegatecall, and why on-chain randomness is never random.
blockchainsolidityevmreentrancy - miscrevised August 11, 20268 min
The first ten minutes: a triage playbook for any CTF challenge
Most challenges are lost to flailing, not to difficulty. Here is a repeatable order of operations for an unknown blob, an unknown file, and an unknown service - and the point at which you should stop guessing and start reading.
methodologytriagebeginnerencoding - miscrevised August 5, 20267 min
Side channels: when how long it took is the answer
Timing attacks against string comparison and modular exponentiation, error messages that distinguish too much, size and cache oracles, and the statistical discipline that separates a real signal from network noise.
side-channeltiming-attackoraclecache - miscrevised August 4, 20266 min
Spot the encoding: reading base64, base32, hex and friends at a glance
Alphabet, length, and padding are enough to name almost any encoding on sight. A field guide to the encodings CTFs actually use, the magic prefixes that tell you what is underneath, and the traps that make a correct guess look wrong.
encodingbase64base32hex - miscrevised August 1, 20267 min
Hardware and signal challenges: logic captures, RF, and barcodes
What to do with a logic-analyzer capture, how to recognise UART, SPI and I2C from their waveforms, decoding a Flipper sub-GHz or IR file, reading damaged QR codes, and where the flag hides in a JTAG or SWD dump.
hardwarelogic-analyzeruartspi - miscrevised April 17, 20265 min
Prompt injection: a field guide for AI CTF challenges
LLM-backed challenges hide a flag in a system prompt or behind a tool the model can call. The tactics that get it out - direct overrides, roleplay, token smuggling, and the indirect injection that turns a document into an instruction.
aillmprompt-injectionjailbreak - miscrevised April 10, 20264 min
What the endpoint sees: ETW, AMSI, and userland hooks
Blue-team and detection challenges ask you to reason about how code gets watched on Windows. The three telemetry sources - ETW, AMSI, and inline API hooks - what each one records, and why evasion challenges target them.
windowsdetectionetwamsi - miscrevised April 7, 20264 min
Writing your own CTF tooling in Go
Sometimes the fastest way to solve a challenge is a fifty-line program nobody has written yet. Why Go is a strong fit for one-off CTF tools - concurrency, static binaries, a batteries-included stdlib - and the patterns that come up again and again.
gotoolingconcurrencyscanning - miscrevised April 3, 20264 min
Esolangs and the misc pile
Brainfuck, Whitespace, Piet and the rest are recognisable on sight once you know what to look at. Plus the rest of the misc category: what it actually contains, and the triage that resolves most of it in under a minute.
esolangbrainfuckwhitespacepiet - miscrevised January 30, 20265 min
Windows privilege escalation: tokens, SIDs, and the impersonation shortcut
Windows boot2root boxes escalate differently from Linux. The access-token model that decides what you can do, the privileges worth having, and the service-account impersonation trick that turns SeImpersonate into SYSTEM.
windowsprivesctokenssid - miscrevised January 27, 20266 min
Linux privilege escalation: the shell is the middle of the challenge
A CTF that drops you on a box as a low-privileged user has only started. The enumeration order that finds the way up fast - SUID binaries, sudo rules, cron, capabilities, writable PATH - and how each one becomes root.
linuxprivescsuidsudo - miscrevised January 20, 20264 min
Working a leaked dataset: OSINT on a pile of data
Some OSINT challenges hand you a dump - a CSV, a SQL export, a folder of documents - and a question buried in it. The command-line workflow for turning gigabytes of leaked data into the one record that answers the challenge.
osintdatagrepcsv - miscrevised January 16, 20265 min
OSINT as a method, not a lucky search
Open-source intelligence challenges reward discipline over cleverness. The pivot loop, what metadata actually survives, how to geolocate from an image without recognising the place - and where the line is.
osintrecongeolocationmetadata - miscrevised January 9, 20265 min
Thinking like the designer: finding the intended flaw
The hardest CTF challenges have no memory-corruption and no injection - just a system whose logic can be bent. Threat modeling from the attacker's chair: trust boundaries, assumptions, and the questions that find a logic bug.
threat-modelinglogic-bugstrust-boundarydesign
Crypto
Classical statistics, XOR, RSA, discrete logs and curves, block cipher modes, hashes, and the random number generators that were never random.
- cryptorevised July 28, 20267 min
Chi-squared, index of coincidence, and why classical ciphers fall
Caesar, Vigenère, and substitution ciphers do not need guesswork - they need two statistics. How chi-squared scores a candidate plaintext, how the index of coincidence recovers a key length, and how to combine them into an attack that runs in milliseconds.
classicalcaesarvigenerefrequency-analysis - cryptorevised July 21, 20266 min
XOR, crib dragging, and the two-time pad
Single-byte XOR, repeating-key XOR, and keystream reuse are three faces of the same weakness. How to recover a key length from Hamming distance, drag a crib across a XOR of two plaintexts, and know when a stream cipher has handed you the answer.
xorcrib-dragone-time-padkeystream-reuse - cryptorevised July 14, 20267 min
The RSA attack decision tree
RSA challenges are not solved by knowing every attack - they are solved by reading the parameters and picking the one attack that matches. A decision tree from e and n to Fermat, Wiener, Håstad, common modulus, and the oracle attacks.
rsafactoringwienerhastad - cryptorevised June 30, 20267 min
Hash cracking that actually works: identify, wordlist, rules, mask
Cracking is a search problem, and most failed attempts are searches aimed at the wrong space. How to identify a hash from its shape, choose between wordlist, rules, and mask attacks, and recognise the hashes you should not be brute-forcing at all.
hashescrackinghashcatwordlists - cryptorevised May 18, 20268 min
Elliptic curves in CTF: nonce reuse, biased nonces, and invalid curves
ECDSA leaks its private key when a nonce repeats, when a nonce is biased by a few bits, or when the curve you were handed is not the curve the implementation thinks it is. The four failure modes, what each looks like in a transcript, and how to run them.
eccecdsanonce-reuselattice - cryptorevised May 14, 20267 min
Discrete logs and the ways Diffie-Hellman is set up wrong
Baby-step giant-step, Pohlig-Hellman on a smooth group order, small-subgroup confinement, and the unauthenticated key exchange that is really a man in the middle. How to tell which discrete-log attack a challenge is asking for by looking at the parameters.
diffie-hellmandiscrete-logpohlig-hellmanbsgs - cryptorevised May 11, 20267 min
Hash length extension: appending to a message you cannot read
Why MD5, SHA-1 and SHA-256 let you forge a valid `H(secret || message || padding || yours)` without ever knowing the secret, how to recognise a vulnerable MAC construction on sight, and which hashes are immune.
hashlength-extensionmerkle-damgardmd5 - cryptorevised May 8, 20268 min
Predicting the random: LCGs, Mersenne Twister, and seeded PRNGs
How to tell a cryptographic RNG from a statistical one, recover an LCG's parameters from a handful of outputs, untemper MT19937 back to its internal state, and beat a token generator that was seeded with the current time.
prnglcgmersenne-twistermt19937 - cryptorevised May 6, 20269 min
AES is fine. The mode around it is the challenge
ECB detection and cut-and-paste, CBC bit flipping, the padding oracle, and what happens when a CTR or GCM nonce repeats. Five attacks that never touch the block cipher itself, because the mode is where CTF authors put the bug.
aesecbcbcpadding-oracle
Web
Recon, then the injection classes, then the ones that are not injection at all - traversal, upload, race conditions, desync, and the browser's own trust rules.
- webrevised July 10, 20267 min
Sessions, cookies, CORS and CSRF: the browser's trust rules
Which origin can read what, why a cookie is scoped differently from everything else in the browser, and the four ways a session is stolen without ever finding an XSS: CSRF, a permissive CORS policy, cookie tossing, and session fixation.
csrfcorscookiessamesite - webrevised July 3, 20266 min
File upload: getting the wrong bytes into the right place
Beating extension checks, MIME checks and magic-byte checks, why a polyglot file is valid twice, and the three things that have to be true before an uploaded file becomes code execution.
file-uploadrcepolyglotmagic-bytes - webrevised June 26, 20266 min
Prototype pollution: editing the base class of every object
Why `__proto__` in a JSON body changes objects the code never touched, how to find the merge that lets you do it, and the gadget hunt that turns a polluted property into XSS on the client or command execution on the server.
prototype-pollutionjavascriptnodejsgadget - webrevised June 23, 20267 min
Attacking JWTs: alg=none, algorithm confusion, and the header fields nobody audits
A JSON Web Token is a signed claim you were handed and asked to give back. Every classic JWT bug is a place where the verifier lets the token choose how it is verified - alg=none, RS256 to HS256 confusion, kid injection, and attacker-hosted key URLs.
jwtauthenticationalgorithm-confusionalg-none - webrevised June 19, 20266 min
Injection beyond SQL: NoSQL, LDAP, XPath, CRLF and SSI
Every query language is injectable, and each one has a different syntax for always-true. Mongo operator injection, LDAP filter injection, XPath blind extraction, header injection through CRLF, and the server-side includes nobody remembers exist.
nosqlmongodbldapxpath - webrevised June 12, 20266 min
Request smuggling: when the proxy and the server disagree
CL.TE, TE.CL, TE.TE and the HTTP/2 downgrade desyncs. How two servers reading the same bytes can disagree about where one request ends, what that buys you, and how to detect it without wrecking the target.
request-smugglingdesynchttpproxy - webrevised June 5, 20266 min
Race conditions: spending the same balance twice
Limit overruns, TOCTOU on the filesystem, and the single-packet attack that removes network jitter from the equation. How to recognise a race in a feature description and how to actually win one.
race-conditiontoctousingle-packet-attackconcurrency - webrevised May 4, 20267 min
Command injection: making the shell run your half of the string
Where a shell gets invoked, the separators that split one command into two, how to confirm a blind injection you cannot see, and the argument-injection variant that needs no shell metacharacters at all.
command-injectionrceblindargument-injection - webrevised May 1, 20268 min
Path traversal and local file inclusion: from ../ to code execution
Getting out of the directory the application meant you to stay in, the filters that try to stop you and why they fail, PHP stream wrappers, and the four routes from reading a file to executing one.
path-traversallfirfiphp-wrappers - webrevised February 24, 20269 min
Reading serialized blobs, and the gadget chains hiding behind them
How to recognise PHP, Java, Python, .NET, and Node serialized data on sight, edit it by hand when that is enough, and build a property-oriented chain out of the target's own classes when it is not.
deserializationpicklephp-object-injectiongadget-chain - webrevised February 20, 20269 min
Template injection and the long climb out of a Python jail
{{7*7}} returning 49 is the easy part. What follows is the interesting part: identifying the engine from one probe, then walking Python's object graph from an empty list to os.system with imports, dots, quotes, and underscores taken away from you.
sstijinja2sandbox-escapepyjail - webrevised February 17, 20267 min
XXE: turning an XML parser into a file reader
Any feature that parses XML - and that includes SVG, DOCX, and SOAP - can be told to fetch files and URLs of your choosing. How to confirm it, read files with a classic payload, and exfiltrate through an external DTD when nothing comes back.
xxexmlwebsvg - webrevised February 13, 202611 min
SSRF: making the server fetch the flag for you
A CTF web box almost never exposes the thing that holds the flag. Server-side request forgery is how you borrow the server's network position - the features that fetch URLs, the filter bypasses that actually work, and the internal endpoints worth asking for once you are through.
ssrfwebfilter-bypassmetadata - webrevised February 10, 20266 min
Hacking APIs: the bugs that live between endpoints
Modern web challenges are increasingly a REST or GraphQL API and a token. The four vulnerabilities that dominate API CTF - broken object-level auth, broken function-level auth, mass assignment, and GraphQL introspection - and how to test each one.
apirestgraphqlbola - webrevised February 6, 20265 min
SQL injection: from a broken quote to the whole database
SQLi challenges reward a systematic climb: confirm the injection, work out the query shape, pull data with UNION, and fall back to boolean and time oracles when the output is hidden. Plus the auth-bypass one-liners and how to beat basic filters.
sqliwebunionblind-sqli - webrevised February 3, 20265 min
XSS in CTF: getting your JavaScript to run in someone else's page
Cross-site scripting challenges are rarely about popping alert(1) - they are about stealing an admin bot's cookie or acting as it. The three XSS types, the contexts that decide your payload, and how to exfiltrate once the script runs.
xsswebjavascriptcsp - webrevised January 6, 20264 min
Web recon: finding the endpoint the challenge is really about
The flag on a web challenge is usually behind a route the homepage never links to. Content discovery, JavaScript mining, parameter hunting, and reading the response headers - the reconnaissance that turns a blank page into an attack surface.
webreconcontent-discoveryfuzzing
Binary exploitation
The stack, the heap, format strings, integer arithmetic, shellcode, and fuzzing your way to the crash in the first place.
- pwnrevised June 9, 20268 min
From crash to shell: stack overflows, offsets, ret2win, and ret2libc
A segfault is not an exploit. The path from an unexpected crash to a controlled instruction pointer to a shell, with the mitigation checks that decide which technique you need and the stack-alignment detail that breaks working exploits.
pwnbuffer-overflowropret2libc - pwnrevised May 28, 20266 min
Integer bugs: overflow, signedness, truncation, and the off-by-one
The length check that passes because the length wrapped, the negative index that survives a bounds check, and the 16-bit truncation that turns 65,540 into 4. Where arithmetic bugs come from and how to spot them in a decompiler.
integer-overflowsignednesstruncationoff-by-one - pwnrevised May 25, 20267 min
Writing shellcode that fits: constraints, encoders, and seccomp
The execve stub in twenty-three bytes, and what to do when the buffer is short, the bytes must be printable, nulls are forbidden, or seccomp has taken execve away. Shellcode as a constraint-satisfaction problem.
shellcodeassemblyexecveseccomp - pwnrevised May 21, 20269 min
The glibc heap: chunks, bins, and the four bugs that matter
What malloc actually stores, why tcache made modern heap exploitation easy, and how use-after-free, double free, tcache poisoning and a one-byte overflow each turn into an arbitrary write. The menu-driven heap challenge, decoded.
heapglibcmalloctcache - pwnrevised March 17, 20266 min
Coverage-guided fuzzing: making the crash come to you
When a pwn or rev challenge hands you a parser and asks for the bug, you can read every line - or you can let AFL++ find the crash while you sleep. Harnesses, corpus, sanitizers, and what to do when the fuzzer gets stuck on a checksum.
fuzzingaflasanpwn - pwnrevised March 13, 20265 min
Format string bugs: when %n writes where you point
A single printf(user_input) is a read and a write primitive in disguise. How %x leaks the stack, %s dereferences arbitrary pointers, and %n turns a logging bug into a controlled memory write - the whole ladder from leak to code execution.
pwnformat-stringprintfgot-overwrite
Reversing
Native binaries, managed bytecode, WebAssembly, Android, firmware, and the anti-analysis tricks written specifically to slow you down.
- revrevised July 24, 20265 min
Reversing WebAssembly: a stack machine in the browser tab
Reading .wasm as text, finding the exported function that checks your flag, following the linear memory that holds the strings, and why the JavaScript glue is usually where the answer is.
webassemblywasmbrowserreverse-engineering - revrevised July 17, 20266 min
Reversing managed code: .NET, Java, and Python bytecode
When the binary is not machine code but bytecode with names attached, the job stops being disassembly and becomes reading. Decompiling .NET and Java back to source, disassembling .pyc, and what obfuscators actually take away.
dotnetjavajvmpython - revrevised March 31, 20264 min
Triage at scale: hashing, similarity, and finding the odd sample
When a challenge hands you a folder of a hundred binaries and one is different, reversing each by hand is the wrong move. Import hashing, fuzzy hashing, and YARA turn a pile of samples into a sorted, searchable set.
malwaretriageimphashssdeep - revrevised March 27, 20265 min
Anti-analysis tricks, and how reversing challenges use them
Malware-flavoured rev challenges borrow the real thing's defences: anti-debugging, anti-VM, timing checks, and packing. What each trick looks like in a disassembler and the one-line answer to each.
reverse-engineeringanti-debuganti-vmpacking - revrevised March 20, 20265 min
Firmware challenges: the filesystem hiding inside the blob
A firmware image is a whole embedded Linux system packed into one file. How to pull the filesystem out with binwalk, find the hardcoded secrets and backdoors CTF authors plant, and recognise the bootloader and flash layout around it.
firmwareiotbinwalksquashfs - revrevised March 10, 20265 min
Watching a binary run: dynamic analysis for reversing
Static disassembly tells you what a binary can do; running it tells you what it actually does. Tracing syscalls and library calls, breaking at the right moment in a debugger, and when to escalate to instrumentation or symbolic execution.
reverse-engineeringdynamic-analysisgdbltrace - revrevised February 27, 20265 min
Taking an Android app apart
An APK is a zip, and most of what a mobile challenge turns on is in metadata rather than in code. The manifest rules that decide the attack surface, how to navigate DEX without a decompiler, and when to stop reading and start hooking.
androidapkdexsmali - revrevised January 13, 20266 min
Reading a binary you have never seen before
A reversing challenge hands you an executable and no question. The order that gets you to the check function fastest - protections, strings, symbols, cross-references - and the four comparison patterns that account for most flag checks.
reversingelfdisassemblydecompiler
Forensics
Disk images, memory dumps, packet captures, documents, archives, logs, boot records, and repositories that were never meant to be public.
- forensicsrevised August 21, 20265 min
Git forensics: an exposed .git is the whole source tree
How to reconstruct a repository from an exposed .git directory over HTTP, find the secret that was committed and then deleted, recover dangling objects from a repo you already have, and read the other version-control leftovers.
gitsource-disclosuresecretsdangling-objects - forensicsrevised August 18, 20267 min
Archive attacks: ZIP crypto, known plaintext, and Zip Slip
Cracking a password-protected archive without cracking the password, why legacy ZipCrypto falls to twelve known bytes, path traversal through an entry name, and the structural tricks that make one archive hold two different sets of files.
ziparchivezipcryptoknown-plaintext - forensicsrevised August 14, 20267 min
Document forensics: taking apart a PDF and an Office file
A PDF is a graph of objects and an Office document is a zip of XML. Both hide things in places a viewer never renders. How to enumerate the structure, pull out streams and macros, and follow what the document tries to fetch.
pdfofficemacrosvba - forensicsrevised June 2, 20267 min
PCAP triage: finding the flag in a hundred thousand packets
Network forensics challenges hand you a capture and no question. The triage order that finds the answer fast - protocol hierarchy, conversations, streams - plus the exfiltration channels people actually hide flags in: DNS, ICMP, USB, and TLS you can decrypt.
pcapwiresharktsharknetwork-forensics - forensicsrevised April 14, 20265 min
Log forensics and threat hunting for blue-team CTF
Defensive challenges hand you logs and ask what the attacker did. Building a timeline, following the kill chain, and using MITRE ATT&CK as a checklist to turn a pile of events into the story that holds the flag.
forensicslogsthreat-huntingblue-team - forensicsrevised March 24, 20264 min
The boot process as a target: MBR, VBR, and bootkits
Before the OS loads, a chain of tiny programs runs from the first sectors of the disk - and a forensics challenge can hide a flag, or a bootkit, right there. How the boot chain works and how to analyse the sectors it lives in.
forensicsbootmbrvbr - forensicsrevised March 6, 20268 min
Reversing a binary protocol from a capture
A CTF hands you a pcap of some custom protocol and no specification. The structures every hand-rolled protocol is built from - magic, length prefixes, TLV, varints - and a repeatable way to turn a hex dump into a parser that reads the flag out.
networkprotocolreverse-engineeringpcap - forensicsrevised March 3, 20265 min
Memory dump triage: what was running, what was typed, what was on disk
A raw memory image answers three questions and you should ask them in that order. Why psscan beats pslist for a challenge, where command lines actually live, and how to get from a dump to a registry hive.
memory-forensicsvolatilitypsscanregistry - forensicsrevised January 23, 20265 min
Disk image forensics: partitions, deleted files, and slack
A forensics challenge hands you a raw disk image and no map. The layered way to take it apart - partition table, filesystem, deleted files, unallocated space, and slack - so the flag stops hiding in the gaps between files.
forensicsdisk-imagesleuthkitcarving
Stego
Images, audio, and text - three carriers, one layered workflow each.
- stegorevised August 7, 20266 min
Hiding in text: zero-width characters, homoglyphs, and whitespace
A paragraph that looks ordinary and carries a payload. How to detect zero-width and bidirectional control characters, spot a Cyrillic letter posing as a Latin one, read whitespace encodings, and recover the bits.
steganographyunicodezero-widthhomoglyph - stegorevised July 31, 20267 min
Audio steganography: spectrograms, LSB, and signals that are not music
A layered workflow for audio challenges - what the waveform tells you, why the spectrogram is almost always the first move, decoding DTMF and SSTV and Morse, and the LSB and metadata tricks that hide in a WAV.
audiosteganographyspectrogramwav - stegorevised June 16, 20267 min
A workflow for image steganography, from magic bytes to bit planes
Stego challenges reward order, not inspiration. The sequence that finds the payload: container checks before pixel checks, structure before statistics, and the specific tells that separate a PNG trick from a JPEG one.
steganographypngjpeglsb