SecLeaf Q2 CTF 2026
22 challenges with 22 published solutions between them. CTFtime lists this event but has no writeups filed against it, so it is absent from the index CTFtime feeds. These were found in public repositories instead. Each link is pinned to the commit it was read from.
The event on CTFtimeForensics9
Recover something from a file, a capture, or a disk image - often from a part of it the format says is unused.
Almost There
1 official solutionForce Push Wont Save You
1 official solutionForgotten Snapshot
1 official solutionForgotten snapshot Writeup
1 official solutionImportant
1 official solutionImportant Writeup
1 official solutionMemGhost Writeup
1 official solutionneedle in context Writeup
1 official solutionThe Invoice Incident Writeup
1 official solution
Uncategorised6
The upstream scoreboard did not say, so neither do we.
Digital Rockstar
1 official solutionForce push wont save you Writeup
1 official solutionRet2win
1 official solutionThe Invoice Incident
1 official solutionVaultcore
1 official solutionWrong Turn
1 official solution
Cryptography3
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Double Trouble
1 official solutionMilitary Grade Encryption
1 official solutionmilitary grade encryption Writeup
1 official solution
Web2
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Hidden Panel
1 official solutionHidden panel Writeup
1 official solution
Binary exploitation1
Turn a memory-safety bug in a native binary into control of execution. Usually a stack overflow, a format string, or a heap primitive.
ret2win Writeup
1 official solution
Reverse engineering1
Work out what a compiled program does without its source, then work backwards from the check to the input that passes it.
VaultCore Writeup
1 official solution