Hack.lu CTF 2026
- Starts
- Ends
- Runs for
- 48 hours
- Format
- Jeopardy (online)
- Rating weight
- 94.74 - Flagship
- Teams registered
- 53
Run by FluxFingers, with prizes listed on CTFtime.
What the organisers say
Hack.lu CTF is organized by FluxFingers, the CTF team of Ruhr-University Bochum (Germany). This will be the 16th edition.
Prep briefing
What past editions were made of
Counted across 72 challenges from 2025, 2024, 2023, 2022, using the categories the scoreboards themselves used. Two things to hold in mind while reading it. The archive indexes challenges that someone published a solution to, not whole scoreboards, so this is the shape of what people wrote about rather than of everything that was set. And where a scoreboard gave no category the challenge lands in misc, so a large misc slice means “unlabelled” rather than “miscellaneous”.
- misc 57%(24)
- pwn 21%(9)
- web 19%(8)
- crypto 2%(1)
What to have open when it starts
Misc
Misc is whatever did not fit, which in practice means encodings and esolangs. Identify, do not guess.
- Cipher identifier and automatic decoder
- Recipe builder: chain decodes and transforms
- Brainfuck and esolang decoder
- Base64 decoder and encoder
- Regex tester with match offsets and capture groups
New to this? Read Recognising encodings, Misc, esolangs and prompt injection
Pwn
Get the offset and the libc base mechanically, so the thinking is spent on the chain rather than on arithmetic.
- Cyclic pattern generator and offset finder
- Buffer overflow offset finder
- Libc base address calculator
- ROP gadget finder
- Pwntools exploit script generator
New to this? Read Binary exploitation, Fuzzing and crash triage, After the shell: privilege escalation
Web
Read the token before you read the source. A session cookie that decodes is the shortest path through half the web board.
- JWT decoder and signature verifier
- Flask session cookie decoder
- HTTP request replayer
- Directory and path scanner
- HTTP security header analyzer
New to this? Read Web recon and attack surface, Injection: SQL and everything after it, Client-side: XSS and the browser's trust model, Sessions, tokens and access control, Server-side takeover: from input to execution, APIs, GraphQL and application logic
The challenges people wrote about most
From previous editions, ordered by how many published solutions each attracted. Reading two solutions to one of these is the closest thing to a warm-up for this event that exists.
- byorpwn · 2022 · 6 writeups
- Based Encodingmisc · 2023 · 5 writeups
- LOKALTALpwn · 2025 · 3 writeups
- MÅRQUEEweb · 2025 · 3 writeups
- Ordersystem pwn · 2022 · 3 writeups
- Awesomenotes Imisc · 2023 · 2 writeups