Misc, esolangs and prompt injection
The category you cannot prepare for by learning a technique - so prepare the triage instead, and learn to identify a dozen shapes on sight.
Assumes1. Recognising encodings
By the end you can
- Identify Brainfuck, Whitespace, Ook!, JSFuck and Piet from their character sets alone
- Use a distinct-character count as a first-pass identifier for any unknown text
- Recognise the recurring misc shapes: encoding chains, damaged codes, audio, text steganography
- Read a file in hex before concluding it is empty or plain
- Separate a prompt-injection challenge's instruction channel from its data channel, and attack the join
- Recognise when a challenge is a joke and automate rather than repeat
1. Read
Esolangs and the misc pile
Brainfuck, Whitespace, Piet and the rest are recognisable on sight once you know what to look at. Plus the rest of the misc category: what it actually contains, and the triage that resolves most of it in under a minute.
Prompt injection: a field guide for AI CTF challenges
LLM-backed challenges hide a flag in a system prompt or behind a tool the model can call. The tactics that get it out - direct overrides, roleplay, token smuggling, and the indirect injection that turns a document into an instruction.
Writing your own CTF tooling in Go
Sometimes the fastest way to solve a challenge is a fifty-line program nobody has written yet. Why Go is a strong fit for one-off CTF tools - concurrency, static binaries, a batteries-included stdlib - and the patterns that come up again and again.
2. Use the tools
In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.
- Brainfuck and esolang decoder
Run Brainfuck, Ook!, Befunge, Whitespace, Deadfish, and friends. Esolangs are a recognition problem more than an execution problem.
Open it in the workspace - Cipher identifier and automatic decoder
Paste anything and find out what it is. ctfpal runs every decoder and rotation, including multi-pass cascades, and ranks results by English-likeness and flag patterns.
Open it in the workspace - Zero-width character and text steganography decoder
Reveal messages hidden in zero-width Unicode characters, trailing whitespace, and homoglyph substitution - text steganography that survives copy-paste.
Open it in the workspace - QR code decoder
Decode QR codes from any image, including inverted, low-contrast, and partially damaged codes. Nothing is uploaded.
Open it in the workspace - Audio spectrogram and SSTV decoder
View a WAV as a spectrogram to find text drawn in frequency space, decode Morse and SSTV, and extract LSB data from audio samples.
Open it in the workspace - Recipe builder: chain decodes and transforms
Build a repeatable chain of operations - decode, decompress, XOR, decrypt - see the output after every step, and share the whole thing as a link.
Open it in the workspace - Regex tester with match offsets and capture groups
Test regular expressions live against sample text, with every match’s offset, capture groups, and named groups broken out.
Open it in the workspace
3. Try one now
Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.
4. Practise on the real thing
Real picoCTF challenges that use these techniques, easiest first. 33 match in total - see the full index.
Common mistakes
The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.
- Learning how Brainfuck works instead of learning to recognise it. Identification transfers to the next nine languages; tape semantics transfer to none of them.
- Solving a hundred-round challenge by hand for the first twenty rounds before writing the script. If the shape repeats, the script is the challenge.
- Treating an LLM challenge as a riddle. The bug is nearly always structural - untrusted text reaching a channel that is read as instructions - not a magic phrase.
- Concluding a file is empty because a viewer shows nothing. Zero-width characters, whitespace encodings and data appended past the end marker are all invisible to everything except a hex dump.
- Normalising the text before counting its characters. The distinct-character count is the identifier, and stripping whitespace or invisible codepoints destroys exactly the signal that Whitespace and zero-width encodings carry.
Checkpoint
Given five unlabelled artifacts, identify what each one is and name the tool that opens it, without solving any of them.
Teaching note
Resist the urge to teach how Brainfuck works. The transferable skill is identification, and an hour spent on tape semantics is an hour not spent seeing ten different shapes.
Go deeper
The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.
Chapter 4, Attacks and Weaknesses
Practical AI Security - Harriet Farlow
Puts prompt injection in a taxonomy with the other model attacks, so it stops looking like a party trick.
Chapter 2, TCP, Scanners, and Proxies
Black Hat Go - Tom Steele, Chris Patten, and Dan Kottmann
The smallest complete example of writing the tool instead of repeating the task by hand.
Chapter 6, Red Teaming AI
Practical AI Security - Harriet Farlow
Case-study attacks against real models, which is the closest thing in the corpus to the method a prompt-injection challenge rewards.
Every book the curriculum cites has a page in the library.