Writeup index
Two views on the same idea: a short list of technique primers, and an archive of CTF challenges that already have published solutions to compare.
188,302 solutions across 97,783 challenges. Three sources, searched together:
3,179 challenges
The author's own writeup and solve script, from the challenge repository. Listed first: the intended solution, not a reconstruction. 2,200 are in no other index.
19,680 challenges
Solutions collected on each challenge's CTFtime task page. 9,094 have two or more to compare here; the 2+ filter counts all three sources, so it finds more. picoCTF's 513 lead with picoctfsolutions.com instead.
84,720 challenges
Read from 11,997 public repositories on GitHub, GitLab and Codeberg, pinned to the commit so a restructure cannot 404 them. 4,340 events are here from this source alone.
Loading 19,680 challenges…
A curated, technique-tagged list. Every entry teaches one named technique and links back into the relevant ctfpal tool - a “what should I learn next” map rather than an archive.
16 of 16
Wiener’s attack on small private exponent RSAintermediate
crypto · Wikipedia (canonical reference)
When d < N^(1/4) / 3, the continued-fraction expansion of e/N reveals d as one of its convergents. The Wiener attack tile in the RSA tab implements this directly.
rsawienercontinued-fractionsOpen the text mode → rsa tab in ctfpal to apply this.
Coppersmith’s stereotyped-message attackadvanced
crypto · May et al.
Recover an unknown low-bit chunk of an RSA plaintext when the high bits are known and the public exponent is small. ctfpal ships a Howgrave-Graham formulation under the RSA tab.
rsacoppersmithlatticelllOpen the text mode → rsa tab in ctfpal to apply this.
Håstad’s broadcast attack on low-exponent RSAintermediate
crypto · Stern / Håstad
If the same message is sent to e or more recipients under different moduli, CRT and an e-th root recover it. The RSA tab auto-runs this when three ciphertexts are present.
rsahastadcrtOpen the text mode → rsa tab in ctfpal to apply this.
The padding-oracle attack on CBC modeintermediate
crypto · Cryptopals Set 3
If decryption leaks whether the PKCS7 padding was valid, a CBC ciphertext is recoverable byte-by-byte without the key. Ctfpal automates the byte search against any CORS-accessible oracle.
aescbcpadding-oraclepkcs7Open the crypto mode → padding tab in ctfpal to apply this.
ECDSA: nonce reuse leaks the private keyintermediate
crypto · Bill Buchanan
Two signatures with the same r expose k, and from k the long-term private key d. The ECDSA reuse panel does the algebra given two (r, s, z) triples.
ecdsanonce-reuseOpen the crypto mode → ecdsa tab in ctfpal to apply this.
Breaking the many-time pad (OTP key reuse)beginner
crypto · crypto.stackexchange
When the same key XORs many messages, C_i ⊕ C_j = P_i ⊕ P_j. Crib-drag (or column-by-column English frequency) recovers the key. Crypto > OTP crib drag.
xorotpcrib-dragOpen the crypto mode → cribdrag tab in ctfpal to apply this.
Hash length-extension on MD5/SHA-1/SHA-256intermediate
crypto · Ron Bowes
Merkle-Damgård hashes with secret prefix MAC are forgeable: given H(secret || data) and len(secret), produce H(secret || data || glue || append). The Length-extension tab forges this in-browser.
md5sha-1sha-256length-extensionOpen the crypto mode → lengthext tab in ctfpal to apply this.
Recovering MT19937 state from outputsintermediate
crypto · Cryptopals Set 3
Mersenne Twister’s tempering function is invertible: 624 consecutive 32-bit outputs reveal the entire state and let you predict all future values. The MT19937 tab does this and predicts the next.
prngmt19937Open the crypto mode → mt tab in ctfpal to apply this.
SSTI: server-side template injection (Jinja2)intermediate
web · PayloadsAllTheThings
When user input is rendered through a templating engine, payloads like {{config}} or {{7*7}} confirm injection; {{cycler.__init__.__globals__.os.popen(...)}} reaches RCE in Jinja2.
sstijinja2Forging Flask session cookiesbeginner
web · HackTricks
Flask signs cookies with itsdangerous. With the SECRET_KEY (often leaked via debug or RCE), you can forge any session. The Forge mode decodes + re-signs Flask cookies.
flaskitsdangeroussessionOpen the forge mode tab in ctfpal to apply this.
JWT bypass via alg=none and HS256 confusionintermediate
web · PortSwigger
A JWT verifier that trusts the alg header lets you forge tokens with alg=none. Public-key-as-HMAC-secret confusion is the other classic. The JWT tab forges both.
jwtalg-nonekey-confusionOpen the text mode → jwt tab in ctfpal to apply this.
Hiding data after PNG IENDbeginner
forensics · Ange Albertini
Most PNG renderers stop at the IEND chunk, but the file can carry arbitrary trailing data - ZIPs, more PNGs, raw flags. The PNG chunks tab surfaces those bytes immediately.
pngpolyglotcarvingOpen the file mode → png tab in ctfpal to apply this.
LSB steganography: PixelKnot, OpenStego, and friendsbeginner
stego · RickdeJager
Hidden data is usually in the least-significant bit of each channel. ctfpal’s Steganography tab sweeps every plane/channel and runs OpenStego dictionary attacks in-browser.
lsbopenstegosteghideOpen the file mode → stego tab in ctfpal to apply this.
ret2libc 101intermediate
pwn · ir0nstone
Overflow saves return address into libc. The Pwn tab provides cyclic-pattern offsets, ROP gadget search, and libc symbol reference offsets for the common glibc builds.
ropret2libcstack-overflowOpen the pwn mode tab in ctfpal to apply this.
Format-string bugs: reading + writing memoryintermediate
pwn · OWASP
%n writes; %hn / %hhn write narrower; %p reads. The Pwn tab includes a format-string builder that crafts the exact payload to set an arbitrary address to a value.
format-stringprintfOpen the pwn mode tab in ctfpal to apply this.
Decoding Brainfuck / Ook! / Whitespacebeginner
misc · esolangs.org
Misc tab runs Brainfuck, Ook!, Befunge-93, ><>, Whitespace, and Deadfish directly in the browser. Auto-triage detects which one your input is.
esolangbrainfuckwhitespaceOpen the text mode → misc tab in ctfpal to apply this.