Lesson pack 5 · Foundation · 90 minutes
Misc, esolangs and prompt injection
The category you cannot prepare for by learning a technique - so prepare the triage instead, and learn to identify a dozen shapes on sight.
Print this page for a paper plan - the navigation and links drop out.Student-facing version
Before the session
- Nothing to install. Students need a browser and https://ctfpal.com. Confirm the room can reach it once; after that it works offline.
- Read the lesson yourself first - about 13 minutes.
- Have one worked example ready to paste. The classroom link builder on the instructor page turns it into a URL that opens preloaded.
Objectives
Written as things a student can do afterwards, so they can be assessed rather than asserted.
- Identify Brainfuck, Whitespace, Ook!, JSFuck and Piet from their character sets alone
- Use a distinct-character count as a first-pass identifier for any unknown text
- Recognise the recurring misc shapes: encoding chains, damaged codes, audio, text steganography
- Read a file in hex before concluding it is empty or plain
- Separate a prompt-injection challenge's instruction channel from its data channel, and attack the join
- Recognise when a challenge is a joke and automate rather than repeat
Running order (90 min)
| Time | What happens |
|---|---|
| 0:00-0:09 | Frame the problemWhat the category looks like when you meet it cold, and why the naive approach fails. |
| 0:09-0:27 | Teach the methodThe technique itself, on the board or from the lesson. No tools open yet. |
| 0:27-0:50 | Demonstrate liveSame technique, in the workspace, on your worked example. Narrate every choice. |
| 0:50-1:21 | Practice setStudents work the challenges. Circulate rather than present. |
| 1:21-1:30 | Checkpoint and wrapCollect the artefact, name what comes next. |
Tools used
- Brainfuck and esolang decoder - Run Brainfuck, Ook!, Befunge, Whitespace, Deadfish, and friends. Esolangs are a recognition problem more than an execution problem.https://ctfpal.com/?tool=brainfuck-interpreter
- Cipher identifier and automatic decoder - Paste anything and find out what it is. ctfpal runs every decoder and rotation, including multi-pass cascades, and ranks results by English-likeness and flag patterns.https://ctfpal.com/?tool=cipher-identifier
- Zero-width character and text steganography decoder - Reveal messages hidden in zero-width Unicode characters, trailing whitespace, and homoglyph substitution - text steganography that survives copy-paste.https://ctfpal.com/?tool=zero-width-decoder
- QR code decoder - Decode QR codes from any image, including inverted, low-contrast, and partially damaged codes. Nothing is uploaded.https://ctfpal.com/?tool=qr-decoder
- Audio spectrogram and SSTV decoder - View a WAV as a spectrogram to find text drawn in frequency space, decode Morse and SSTV, and extract LSB data from audio samples.https://ctfpal.com/?tool=audio-spectrogram
- Recipe builder: chain decodes and transforms - Build a repeatable chain of operations - decode, decompress, XOR, decrypt - see the output after every step, and share the whole thing as a link.https://ctfpal.com/?tool=recipe-builder
- Regex tester with match offsets and capture groups - Test regular expressions live against sample text, with every match’s offset, capture groups, and named groups broken out.https://ctfpal.com/?tool=regex-tester
Reading
- Esolangs and the misc pile - 4 min. Brainfuck, Whitespace, Piet and the rest are recognisable on sight once you know what to look at. Plus the rest of the misc category: what it actually contains, and the triage that resolves most of it in under a minute.
- Prompt injection: a field guide for AI CTF challenges - 5 min. LLM-backed challenges hide a flag in a system prompt or behind a tool the model can call. The tactics that get it out - direct overrides, roleplay, token smuggling, and the indirect injection that turns a document into an instruction.
- Writing your own CTF tooling in Go - 4 min. Sometimes the fastest way to solve a challenge is a fifty-line program nobody has written yet. Why Go is a strong fit for one-off CTF tools - concurrency, static binaries, a batteries-included stdlib - and the patterns that come up again and again.
Practice set
Real picoCTF challenges tagged with this module’s techniques, easiest first. Assign the first three in class and the rest as homework.
- Binary Search - picoCTF 2024, easy
- Codebook - Beginner picoMini 2022, easy
- convertme.py - Beginner picoMini 2022, easy
- dont-use-client-side - picoCTF 2019, easy
- fixme1.py - Beginner picoMini 2022, easy
- fixme2.py - Beginner picoMini 2022, easy
- 1_wanna_b3_a_r0ck5tar - picoCTF 2019, medium
- Client-side-again - picoCTF 2019, medium
- Failure Failure - picoCTF 2026, medium
- homework - picoMini by redpwn, hard
- Sequences - picoCTF 2022, hard
- Some Assembly Required 4 - picoCTF 2021, hard
Checkpoint (gradeable)
Given five unlabelled artifacts, identify what each one is and name the tool that opens it, without solving any of them.
Deliberately a produced artefact rather than a quiz question: it is either there or it is not, which makes it fast to mark and hard to bluff. Every tool in ctfpal is deterministic, so two students who did the work correctly hand in the same value.
Where the room gets stuck
Resist the urge to teach how Brainfuck works. The transferable skill is identification, and an hour spent on tape semantics is an hour not spent seeing ten different shapes.
- Learning how Brainfuck works instead of learning to recognise it. Identification transfers to the next nine languages; tape semantics transfer to none of them.
- Solving a hundred-round challenge by hand for the first twenty rounds before writing the script. If the shape repeats, the script is the challenge.
- Treating an LLM challenge as a riddle. The bug is nearly always structural - untrusted text reaching a channel that is read as instructions - not a magic phrase.
- Concluding a file is empty because a viewer shows nothing. Zero-width characters, whitespace encodings and data appended past the end marker are all invisible to everything except a hex dump.
- Normalising the text before counting its characters. The distinct-character count is the identifier, and stripping whitespace or invisible codepoints destroys exactly the signal that Whitespace and zero-width encodings carry.
If a student wants the subject, not the answer
Chapter-level references, so a student can be pointed at twenty pages rather than at a book. Nothing here is required to complete the module.
- Practical AI Security, Harriet Farlow. Chapter 4, Attacks and Weaknesses. Puts prompt injection in a taxonomy with the other model attacks, so it stops looking like a party trick.
- Black Hat Go, Tom Steele, Chris Patten, and Dan Kottmann. Chapter 2, TCP, Scanners, and Proxies. The smallest complete example of writing the tool instead of repeating the task by hand.
- Practical AI Security, Harriet Farlow. Chapter 6, Red Teaming AI. Case-study attacks against real models, which is the closest thing in the corpus to the method a prompt-injection challenge rewards.
If you finish early
- Hand out a challenge from the cross-CTF index in this category - each one has published solutions to compare afterwards.
- Run the same input through Identify and let the class argue with the ranking. Disagreeing with a confidence score is where the technique actually lands.
- Ask a student to break their own example - construct an input that defeats the tool, and explain why.
Take this into a room
Markdown files, built here in your browser. They print, they open in anything, and they carry the challenge text - so the session works with no network in the room.