corCTF 2025
41 challenges with 44 published community solutions between them. Solution links go to CTFtime’s task page, which aggregates every writeup for a challenge - individual blog posts rot, the aggregator does not. 14 of them also carry the solution corCTF 2025’s own organisers published, which is linked on the challenge itself.
Full task list on CTFtimeBinary exploitation10
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
Also written up in: mito753/Kernel-Exploit-Dojo, mito753/Kernel-Exploit-Dojo, mito753/Kernel-Exploit-Dojo, mito753/Kernel-Exploit-Dojo, mito753/Kernel-Exploit-Dojo, mito753/Kernel-Exploit-Dojo, mito753/Kernel-Exploit-Dojo, mito753/Kernel-Exploit-Dojo
- linux-kernel
- pwn
- amd
- side-channel
Same technique in picoCTF: hijacking, VNE, lockdown-horses
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: exploit/exploit.c, exploit/write_evil.c, exploit/write_evil.h
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: exploit/dummy.c, exploit/exploit.py
Also written up in: nobodyisnobody/write-ups, nobodyisnobody/write-ups
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: solve.sh
Also written up in: AmIAHuman/writeups
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: sol.txt
- linux-kernel
- 0day
- pwn
Same technique in picoCTF: hijacking, VNE, lockdown-horses
Tua Cugina Systems
1 official solutionAlso written up in: nobodyisnobody/write-ups
- ld_preload
- nsjail-escape
- pwn
- tc
Same technique in picoCTF: lockdown-horses, Guessing Game 1, Bizz Fuzz
Upload
1 official solutionAlso written up in: nobodyisnobody/write-ups
zenerational aura Powerful kernel exploitation primitive via panic on oops
1 official solutionAlso written up in: uz56764.tistory.com
Uncategorised10
The upstream scoreboard did not say, so neither do we.
Also written up in: jiegec/ctf-writeups, c240030/openArchiveCTF
Corctf Dev 2
1 official solutionAlso written up in: cor.team
Encrypt
1 official solutionAlso written up in: c240030/openArchiveCTF
Also written up in: c240030/openArchiveCTF
Nintendo Sswitch
1 official solutionAlso written up in: jiegec/ctf-writeups
Also written up in: c240030/openArchiveCTF
Python URL Parsing Confusion
1 official solutionAlso written up in: fireshellsecurity.team
Secret Portal
1 official solutionAlso written up in: theballmarcus/theballmarcus-ctf-writeups
Touch Grass 3
1 official solutionAlso written up in: jiegec/ctf-writeups
Yamlquiz
1 official solutionAlso written up in: jiegec/ctf-writeups
Misc9
Everything that fits no other box: esolangs, puzzles, scripting exercises, and the jail escapes that have not yet earned their own category.
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: solver/build.rs, solver/src/main.rs
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: solve/pid.c
Control 36 Solves
1 official solutionAlso written up in: cyber-man.pl
Also written up in: 7rocky.github.io
Fizzbuzz100
1 official solutionAlso written up in: 7rocky.github.io
Fizzbuzz101
1 official solutionAlso written up in: 7rocky.github.io
Fizzbuzz102
1 official solutionAlso written up in: 7rocky.github.io
Qcg K
1 official solutionAlso written up in: 7rocky.github.io
Two Wrongs
1 official solutionAlso written up in: 7rocky.github.io
Reverse engineering6
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: solution.py, solve.sh
Also written up in: cor.team
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: solve_intended_solution.py
Also written up in: cor.team
- functional-programming
- rev
- google-sheets
- transpiler
- oop
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Also written up in: cor.team
- vm
- rev
- floating-point
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
- vm
- brainfuck
- rev
Same technique in picoCTF: Checkpass, WinAntiDbg0x100, WinAntiDbg0x200
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: solution_tester.py
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: solve.py
Cryptography5
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: chall/solve/solve.py, chall/solve/src/lib.rs
Also written up in: president-xd/Writeups
Rules
1 official solutionAlso written up in: president-xd/Writeups
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: chall/solve/solve.py
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: solve_sudoku.py
Web1
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Published by the organisers in Crusaders-of-Rust/corctf-2025-public-challenge-repo: solve.py