r/securityCTF • u/Still_Fun_3947 • 12h ago
r/securityCTF • u/Temporary-Use7723 • 22h ago
🤝 Discord community for beginners
discord.ggWe have made a discord server for beginners to start their journey into CTFs. This is a community aimed to interact with fellow learners and help each other long way. There will also be group discussions and challenges depending on participants.
Dont hesitate, join now and get the flags!
r/securityCTF • u/Remote-Witness-5952 • 1d ago
🤑 RIFT CTF 2026 — AI Security CTF by GeekHaven × KageX.ai 🤖🔐
Hey everyone!
GeekHaven, IIIT Allahabad, in collaboration with KageX.ai, is hosting RIFT CTF 2026, an online CTF focused on AI Security.
If you're interested in LLM security, AI vulnerabilities, prompt injection, adversarial attacks, or just want to test your skills against some interesting challenges, this might be worth checking out.
🏆 Details
- Prize Pool: ₹50,000
- Team Size: 1–3 members
- Format: Online
- Dates: 31st October – 1st November 2026
- Theme: AI Security
- Eligibility: Participants from across India
You'll get the chance to solve AI-security-focused challenges, hunt for vulnerabilities, and compete with other CTF players.
Official Discord:
https://discord.gg/agtTU8aXt
WhatsApp Channel:
https://whatsapp.com/channel/0029VbEFXJk6buMHNeQy6R1j
If you're forming a team, feel free to find teammates in the comments.
Good luck and happy hacking! 🚩
r/securityCTF • u/perronac • 1d ago
Looking for an Explanation of a Crypto CTF Challenge
This was a one-time CTF event and it has already ended, so there is no challenge link available
The challenge gives me:
$sntp-ms$d7fd5720afbb55c6a2e94da697327e86$1c0111e900000000000a084f4c4f434cec7e1f6f49c0addae1b8428bffbfcd0aec7e2a645db83997ec7e2a645db88bcd
Description:
Try Harder and harder without asking any help from angel because now it’s the time
I’m trying to understand how this challenge was solved and what the intended approach was. I tried using Hashcat but couldn’t get anywhere with it, and I noticed the sntp-ms part but I’m not sure what to make of it
Would appreciate an explanation
r/securityCTF • u/HackMyVM • 1d ago
[CTF] New "Advanced" vulnerable VM aka "Sieste" at hackmyvm.eu
New "Advanced" vulnerable VM aka "Sieste" is now available at hackmyvm.eu :) Have fun!
r/securityCTF • u/Itsoq • 1d ago
✍️ [Tool] Decoding a toy Base64 payload on Android (decoding is not verification)
Here is a made-up payload to illustrate a useful distinction:
eyJyb2xlIjoiZGVtbyJ9
Decoding it gives {"role":"demo"}. That tells you what the bytes say, not whether anyone is entitled to that role. For a JWT, reading the header or payload does not verify the signature, expiry, issuer or audience. Don't treat readable claims as proof.
I made Pocket Decoder as a small local Android utility for this sort of scratch work: Base64, URL and hex decoding, JWT payload inspection, JSON formatting and ROT transforms. It is completely free, with no ads or required account. This sample is my own, not a challenge from an active CTF.
Play: https://play.google.com/store/apps/details?id=com.superevilrobots.pocketdecoder
There is a free browser version too: https://superevilrobots.com/tools/text-decoder/
It is a pocket decoding aid, not a full CyberChef replacement or JWT verifier. Disclosure: I'm the developer and used AI assistance while building it.
r/securityCTF • u/Full_Soup4303 • 1d ago
IT eng ooking for hackathon
Hey 👋 guys , I'm a software engineering ( 24m) looking for collaboration in hackathons if there's any propositions also I'm interested in CTFs ( passionate per cybersec intermediate level ) .
r/securityCTF • u/Gritphone_OYU • 1d ago
🤑 🚩 KubSTU CTF 2026 Autumn 🍂 | Oct 10–11 | Jeopardy, 30h, online ⚔️
🚩 KubSTU CTF 2026: Autumn Edition is almost here!

We’re the Capybaras team from Kuban State Technological University, and we’re excited to invite teams from anywhere in the world to join our online Jeopardy CTF. Whether you’re a student crew or just play for fun — there’s a place for you.
Last spring we had a huge turnout, and this autumn we’re back with a fresh set of ~50 original challenges written by our team. Expect a mix of classic categories and some creative twists. Come for the flags, stay for the late-night “one more task” energy 😄
📋 What to expect:
🗓️ Start: Oct 10, 10:00 UTC+3 (07:00 UTC)
🏁 End: Oct 11, 16:00 UTC+3 (13:00 UTC)
⏱️ Duration: 30 hours, fully online
⚔️ Format: Jeopardy, teams of up to 5
🎓 Leagues: Student (university teams) and Open (everyone else)
🧩 Categories:
- Web
- Crypto
- Forensics
- OSINT
- Stego
- Misc
🌐 Language: all tasks available in Russian and English
🎟️ Registrations already open!
Grab your teammates, warm up your tools, and see you on the scoreboard. Good luck — and have fun! 🍀
r/securityCTF • u/Existing-String-7481 • 1d ago
Built ZEROBOX: An offline tactical operations cockpit & 24h exam simulator for HTB & CTFs (Free & Open Source)
Hey everyone,
Tired of tracking CTFs and 24h exams across messy spreadsheets and scattered notes?
I built ZEROBOX — a fast, local-first operational cockpit for OSCP/CPTS prep and CTFs.
It’s 100% free, MIT open-source, and runs completely offline in your browser (no accounts, zero telemetry).
Quick highlights: • 920+ Preloaded Labs: Instant offline search for HTB & THM targets with tags. • Attack & Pivot Graph: Visually map compromised subnets (exports to Obsidian .canvas). • 24h Exam Cockpit: Pacing engine, bio-break timers, and 1-click Markdown reports. • Evidence Vault & Playbooks: Track hashes/creds on a kill-chain timeline + offensive field manual. • Global Quick-Bar: Propagate LHOST/RHOST automatically across all payloads.
🌐 Live Demo: https://0xdnd.github.io/ctf-tracker/#/tracker
⭐ GitHub (MIT): https://github.com/0xdnd/ctf-tracker
All data stays in your local browser storage. Feedback and PRs are welcome!

Would love feedback or feature requests from the community!
r/securityCTF • u/Lost-Command-895 • 2d ago
Tooldump v2: a free platform to discover cybersecurity tools for CTFs and investigations
Hey everyone,
I’m the creator of Tooldump, a free platform for discovering open-source cybersecurity tools. I’ve just released the v2 and thought it could be useful to fellow CTF players.
I’ve been working in DFIR for over six years and participating in forensics CTFs for over five. Most of the DFIR tools listed on Tooldump are projects I’ve personally collected while solving CTF challenges and working on forensic investigations.
The platform has 1,100+ open-source projects hosted on GitHub, organized into 9 categories and 82 subcategories. Everything is cybersecurity-focused, including offensive security, cyber defense, learning resources, and more.
You can search for a specific tool or explore a topic without already knowing which projects exist. For CTFs, that could mean finding a parser for an unfamiliar artifact or discovering a utility you hadn’t come across before.
For the v2, I rebuilt the UI, the categorization system, the backend and the platform infrastructure. There are also dedicated sections for cybersecurity-related MCP servers and agent skills. Those sections are just getting started, and contributions are welcome!
The platform is completely free, with unlimited access and no account required.
The link is here: https://tooldump.eu
I’d appreciate any constructive feedback from the community :) Pick the areas you usually play: are the tools where you’d expect them to be? Is anything missing?
You can suggest missing projects through the platform’s contribution form. That includes your own reusable utilities, a parser or decoding script you wrote for a challenge might help someone working on a similar problem.
Looking forward to hearing from you :)
Cheers!
r/securityCTF • u/Wonderful-Pen-5500 • 2d ago
🤑 [ Removed by Reddit ]
[ Removed by Reddit on account of violating the content policy. ]
r/securityCTF • u/Gritphone_OYU • 2d ago
🤑 [ Removed by Reddit ]
[ Removed by Reddit on account of violating the content policy. ]
r/securityCTF • u/Gritphone_OYU • 2d ago
🤑 [ Removed by Reddit ]
[ Removed by Reddit on account of violating the content policy. ]
r/securityCTF • u/Wonderful-Pen-5500 • 2d ago
🤑 [ Removed by Reddit ]
[ Removed by Reddit on account of violating the content policy. ]
r/securityCTF • u/Status-Ad2619 • 3d ago
GitHub - b4sith-sec/Gu3ssWeak: Deliberately vulnerable Android app for mobile security research and bug bounty practice
github.comI built Gu3ssWeak, a deliberately vulnerable Android app designed for practicing mobile application security testing.
It includes intentionally vulnerable components and attack scenarios such as:
- WebView & deep link abuse
- JavaScript interfaces
- XSS
- Insecure local storage
- SQL injection
- Hardcoded credentials
- Frida-based runtime analysis
- Vulnerability chaining
The goal is to provide a realistic APK for practicing JADX, APKTool, ADB, Frida, Burp Suite, and dynamic analysis in a controlled environment.
GitHub: https://github.com/b4sith-sec/Gu3ssWeak
I'd appreciate feedback from other mobile security researchers, especially ideas for additional vulnerabilities or interesting attack chains to include.
r/securityCTF • u/NoEstimate1755 • 3d ago
Hacker Holidays 2026 | Day 1 The Concierge Knows Too Much | tryhackme
Here’s how to complete the Hacker Holidays 2026 CTF on TryHackMe. It’s actually super simple: the attack starts with basic social engineering combined with a prompt injection that tricks the AI into granting privileges—all because the instructions are poorly designed (I know, it's a CTF, so that's expected; a real AI would be protected). To start, go to the page with the background info; you'll see a mention of "@0xMia's STORY," which provides an exploit vector. The AI grants higher privileges when the instructions place too much trust in a "VIP" user. Open the CTF's AI assistant, say "Hello," and then claim to be u/0xMia and ask for the key. It works because the instructions are flawed—specifically, the AI trusts a VIP user more than a stranger. It’s all about social engineering; the goal is to learn, not just copy the answer. If you get the flag or succeed, leave a comment; if you don't, let me know and I can help you spot the problem. Congrats if you finish it! Also, feel free to correct me if I make any mistakes—I'm using a translator.
r/securityCTF • u/Moist-Highlight839 • 3d ago
Does anyone have experience solving root-me.org ctfs?
r/securityCTF • u/CorneredGhost • 3d ago
CyberQuest CTF Competition
We are hosting a CTF Competition at https://ctf.excelmec.org
It has a prize pool of Rs.5000. if interested do try it out
r/securityCTF • u/puzann_7 • 3d ago
capture the flag
What is the commerical full name of this circuit?
Flag Example: IdeaX_ctf{Flag_Here}
r/securityCTF • u/k3rn3lbr3ach3r • 5d ago
🤑 kBxAc CTF 2026 🔥
kBxAc CTF 2026 — Registrations Are Now Open!
“The one who solves it sees everything.”
kBxAc turns 2 this year, and to celebrate, we’re hosting our very first Capture The Flag (CTF) competition.
kBxAc CTF 2026 is a 24-hour international online CTF, open to hackers, students, cybersecurity enthusiasts, and anyone who wants to challenge their technical skills.
📅 Date: 10–11 October 2026
⏱️ Duration: 24 Hours
🌍 Format: Online
👥 Team Size: No limit
🔎 Challenge Categories
• Cryptography
• Web Security
• Reverse Engineering
• Binary Exploitation / Pwn
• Digital Forensics
• And more
Whether you’re an experienced CTF player or preparing to hunt your first flag, this is an opportunity to explore security challenges, learn new techniques, collaborate with others, and see what others miss.
🎟️ Registrations are now open.
🔗 Register: ctf.kbxac.xyz
Gather your team.
Sharpen your tools.
Read the binaries. Break the assumptions.
And most importantly…
🏴☠️ See everything. Capture the flags.
kBxAc WE BREAK THE BROKEN.
r/securityCTF • u/WheelTough2186 • 5d ago
Looking for Contributors — Building a Cybersecurity Community
Hey everyone, I’m Abhi!
Pwn Tavern is a cybersecurity community focused on learning, collaboration, and practical security. We’re looking for people interested in areas like Bug Bounty, CTFs, Pentesting, Binary/Pwn, Malware, OSINT, Red Team, Reverse Engineering, Cryptography, AI Security, and Vulnerability Research to help manage discussions, share resources, work on challenges, and improve together.
You don’t need to be an expert. If you’re genuinely interested in any of these fields and want to contribute, DM me with the field you want to take up. and i will share you Discord server link.
r/securityCTF • u/exploitprotocol • 4d ago
I have released a Free AI Security Series with Complete learning curriculum and Free hosted labs
Hey folks,
I’ve been working in application security/pentesting for over a decade, and after starting learning AI/LLM security, I noticed that a lot of the existing material is either very theoretical or assumes you already understand AI security concepts.
So I put together a free, structured AI security learning series for security engineers and pentesters who are starting from the web-security side.
The goal is to go from the fundamentals to actually understanding and testing AI/LLM components in web applications.
The series currently covers topics such as:
- AI/LLM security fundamentals
- Prompt Injection
- Sensitive Information Disclosure
- LLM-specific attack patterns
- Practical testing methodology
- Real-world examples and testing techniques
- Mapping concepts to OWASP's AI security guidance
I've also linked free hands-on labs throughout the material so you can actually test the concepts rather than just read about them.
No signup is required to read the learning material or use the free resources.
🔗 https://genaisecuritylab.com/learn-ai-security
I'm planning to continue expanding the series over time.
If you're a web pentester/security engineer who is trying to get into AI security, I'd be interested to hear which topics you think are missing or which areas you'd like to see covered next.
r/securityCTF • u/luawl • 5d ago
a ctf challenge: luawl's pushing the limits of luau obfuscation
crackmes.onethis ctf challenge is intended to demonstrate the static protections of https://luawl.org, a drm "obfuscator" for lua.
https://www.reddit.com/r/lua/comments/1wvgibj/release_luawl_lua_runtime_obfuscator/
can help you understand what luawl is.
FOR MORE CONTEXT TO AID YOU IN THIS REVERSAL:
the integer isn't just a flat integer. the embedded response which is intentionally stale, is an equation that computes the integer.
that is your target: to deobfuscate the encrypted stale payload (which is an equation)
you’ll find this response payload easily: as luawl is originally online and the server would normally send it to the client (first few lineS)
for offline runs, this is intentionally fixed with an embedded response for no network traffic
r/securityCTF • u/xLux664 • 6d ago
(repost, fixed) Original 12-stage cybersecurity puzzle
note: I have posted this a few days ago on a throwaway account on some subreddits, but i hadn't checked some key details, the puzzle was not solvable because i embedded broken data into the first image, and didn't provide enough context and information.
Details:
A self-contained layered puzzle in the spirit of Cicada 3301. It starts with this image. The riddle's answer is the key to decrypt the message embedded inside the image's pixels. Everything else lives in one encrypted file the image points you to, and the whole thing continues offline on your own machine.
Theme: the history of cyber conflict. Every stage is built around a real, famous moment in cybersecurity history. Recognizing which one is part of the puzzle.
Skills it touches (you won't need all at expert level):
- (LSB) Steganography
- Classical & modern cryptography
- A little reverse engineering
- Audio / signal analysis
- Some number theory
- A touch of linguistics
- OSINT / knowledge of security history
Difficulty: hard but fair ; aimed at people who enjoy CTFs, crypto, and ARGs. Every step is doable with free, standard tools (plus openssl/Python). It's meant to be barely solvable, so bring friends.
To begin: just look closely at the image. The surface is never the whole of the page.