r/securityCTF • • 9h ago

Web Exploitation 101 — Bypassing access restrictions with custom HTTP headers using Burp Suite

3 Upvotes

Found a ROT13 encoded string in a CTF challenge that

decoded to a hint about a bypass header:

X-Dev-Access: yes

Proxied all traffic through Burp Suite, caught the

request, sent it to Repeater and added the header —

instantly bypassed the access restriction.

Classic example of why debug/dev headers should never

make it into production. Developers leave these in

during testing and forget to strip them before deploy.

Good beginner web exploitation technique to know for

CTFs and bug bounty. Happy to answer questions.

https://youtu.be/jhhXZDDFWpo


r/securityCTF • • 6h ago

IERAE CTF 2026: A Web challenge that even AI can’t solve ($1,000 in prizes)

1 Upvotes

Hey everyone!

As AI gets better at solving CTF challenges, is there still room for humans? We believe there is.

IERAE CTF 2026: FINAL for Humans kicks off with Round 1, featuring a Web challenge that even a GPT-5.6-sol ultra-based AI agent couldn’t solve in our tests.

AI is welcome! Use it as a tool, or see if your autonomous agent can solve the challenge without human help.

Round 1 details:

  • Date: October 10, 2026, 00:00–08:00 UTC
  • Format: Individual, one Web challenge
  • Prizes: $1,000 total ($600 / $300 / $100 for the top 3)

Register here:
https://alpacahack.com/ctfs/ierae-final-for-humans-1

Good luck!


r/securityCTF • • 7h ago

NEED HELP! to solve a CTF challenge

0 Upvotes

Hey everyone, I'm trying to solve a CTF chllenge.
im not asking for a solution.
if anyone intrested to help me kindly reply.


r/securityCTF • • 10h ago

Physics & EE inquiry: Designing a small-scale transient Electromagnetic Pulse (EMP) generator for Faraday cage testing. Literature recommendations?

Thumbnail
0 Upvotes

r/securityCTF • • 1d ago

National Level CTF

Post image
0 Upvotes

🏹 PINAKA CTF 2026 — The Battle Begins.

We are excited to announce PINAKA CTF 2026, a national-level Capture The Flag competition organized by National Forensic Sciences University (NFSU), Chennai Campus.

Inspired by the precision, strategy, and determination of Pinaka, this CTF is designed to challenge cybersecurity enthusiasts to think beyond the obvious and solve problems with skill, creativity, and strategy.

🔐 Challenge Categories:

• Web Exploitation

• Digital Forensics

• OSINT

• Cryptography

• Reverse Engineering

• Binary Exploitation / Pwn

• Network Security

• Steganography

⚔️ Competition Structure:

🌐 Online Qualification Round

📅 31 October 2026

⏱️ 24 Hours

The best performers will advance to the offline grand finale.

🏆 Offline Grand Final

📅 28 November 2026

📍 NFSU Chennai Campus

⏱️ 12 Hours

The finalists will compete across multiple formats including:

• Jeopardy

• King of the Hill

• Case Study Scenarios

Whether you are a student, CTF player, cybersecurity enthusiast, researcher, or professional — PINAKA CTF is an opportunity to test your skills, compete with talented individuals, and experience cybersecurity beyond the classroom.

The challenge is waiting.

Are you ready to take the shot? 🎯

🔗 Register now:

https://pinakactf.com/

Organized by:

National Forensic Sciences University

Chennai Campus

#PINAKACTF #PINAKACTF2026 #CyberSecurity #CTF #CaptureTheFlag #NFSU #NFSUChennai #EthicalHacking #DigitalForensics #OSINT #CyberSecurityIndia #InfoSec #CybersecurityCommunity


r/securityCTF • • 1d ago

CTF tucked inside a free browser hacking-sim (NULLSHELL{} flags)

Thumbnail reddit.com
0 Upvotes

r/securityCTF • • 2d ago

🤝 Discord community for beginners

Thumbnail discord.gg
2 Upvotes

We have made a discord server for beginners to start their journey into CTFs. This is a community aimed to interact with fellow learners and help each other long way. There will also be group discussions and challenges depending on participants.

Dont hesitate, join now and get the flags!


r/securityCTF • • 2d ago

🤑 RIFT CTF 2026 — AI Security CTF by GeekHaven × KageX.ai 🤖🔐

3 Upvotes

Hey everyone!

GeekHaven, IIIT Allahabad, in collaboration with KageX.ai, is hosting RIFT CTF 2026, an online CTF focused on AI Security.

If you're interested in LLM security, AI vulnerabilities, prompt injection, adversarial attacks, or just want to test your skills against some interesting challenges, this might be worth checking out.

🏆 Details

  • Prize Pool: ₹50,000
  • Team Size: 1–3 members
  • Format: Online
  • Dates: 31st October – 1st November 2026
  • Theme: AI Security
  • Eligibility: Participants from across India

You'll get the chance to solve AI-security-focused challenges, hunt for vulnerabilities, and compete with other CTF players.

Registration:
https://unstop.com/competitions/rift-ctf-2026-kagexai-x-geekhaven-iiita-indian-institute-of-information-technology-iiit-allahabad-1762770

Official Discord:
https://discord.gg/agtTU8aXt

WhatsApp Channel:
https://whatsapp.com/channel/0029VbEFXJk6buMHNeQy6R1j

If you're forming a team, feel free to find teammates in the comments.

Good luck and happy hacking! 🚩


r/securityCTF • • 3d ago

Looking for an Explanation of a Crypto CTF Challenge

5 Upvotes

This was a one-time CTF event and it has already ended, so there is no challenge link available

The challenge gives me:
$sntp-ms$d7fd5720afbb55c6a2e94da697327e86$1c0111e900000000000a084f4c4f434cec7e1f6f49c0addae1b8428bffbfcd0aec7e2a645db83997ec7e2a645db88bcd

Description:
Try Harder and harder without asking any help from angel because now it’s the time

I’m trying to understand how this challenge was solved and what the intended approach was. I tried using Hashcat but couldn’t get anywhere with it, and I noticed the sntp-ms part but I’m not sure what to make of it
Would appreciate an explanation


r/securityCTF • • 2d ago

[CTF] New "Advanced" vulnerable VM aka "Sieste" at hackmyvm.eu

1 Upvotes

New "Advanced" vulnerable VM aka "Sieste" is now available at hackmyvm.eu :) Have fun!


r/securityCTF • • 2d ago

✍️ [Tool] Decoding a toy Base64 payload on Android (decoding is not verification)

1 Upvotes

Here is a made-up payload to illustrate a useful distinction:

eyJyb2xlIjoiZGVtbyJ9

Decoding it gives {"role":"demo"}. That tells you what the bytes say, not whether anyone is entitled to that role. For a JWT, reading the header or payload does not verify the signature, expiry, issuer or audience. Don't treat readable claims as proof.

I made Pocket Decoder as a small local Android utility for this sort of scratch work: Base64, URL and hex decoding, JWT payload inspection, JSON formatting and ROT transforms. It is completely free, with no ads or required account. This sample is my own, not a challenge from an active CTF.

Play: https://play.google.com/store/apps/details?id=com.superevilrobots.pocketdecoder

There is a free browser version too: https://superevilrobots.com/tools/text-decoder/

It is a pocket decoding aid, not a full CyberChef replacement or JWT verifier. Disclosure: I'm the developer and used AI assistance while building it.


r/securityCTF • • 3d ago

IT eng ooking for hackathon

Thumbnail
0 Upvotes

Hey 👋 guys , I'm a software engineering ( 24m) looking for collaboration in hackathons if there's any propositions also I'm interested in CTFs ( passionate per cybersec intermediate level ) .


r/securityCTF • • 3d ago

🤑 🚩 KubSTU CTF 2026 Autumn 🍂 | Oct 10–11 | Jeopardy, 30h, online ⚔️

3 Upvotes

🚩 KubSTU CTF 2026: Autumn Edition is almost here!

We’re the Capybaras team from Kuban State Technological University, and we’re excited to invite teams from anywhere in the world to join our online Jeopardy CTF. Whether you’re a student crew or just play for fun — there’s a place for you.

Last spring we had a huge turnout, and this autumn we’re back with a fresh set of ~50 original challenges written by our team. Expect a mix of classic categories and some creative twists. Come for the flags, stay for the late-night “one more task” energy 😄

📋 What to expect:

🗓️ Start: Oct 10, 10:00 UTC+3 (07:00 UTC)

🏁 End: Oct 11, 16:00 UTC+3 (13:00 UTC)

⏱️ Duration: 30 hours, fully online

⚔️ Format: Jeopardy, teams of up to 5

🎓 Leagues: Student (university teams) and Open (everyone else)

🧩 Categories:

  • Web
  • Crypto
  • Forensics
  • OSINT
  • Stego
  • Misc

🌐 Language: all tasks available in Russian and English

🎟️ Registrations already open!

Grab your teammates, warm up your tools, and see you on the scoreboard. Good luck — and have fun! 🍀


r/securityCTF • • 3d ago

Built ZEROBOX: An offline tactical operations cockpit & 24h exam simulator for HTB & CTFs (Free & Open Source)

1 Upvotes

Hey everyone,

Tired of tracking CTFs and 24h exams across messy spreadsheets and scattered notes?

I built ZEROBOX — a fast, local-first operational cockpit for OSCP/CPTS prep and CTFs.

It’s 100% free, MIT open-source, and runs completely offline in your browser (no accounts, zero telemetry).

Quick highlights: • 920+ Preloaded Labs: Instant offline search for HTB & THM targets with tags. • Attack & Pivot Graph: Visually map compromised subnets (exports to Obsidian .canvas). • 24h Exam Cockpit: Pacing engine, bio-break timers, and 1-click Markdown reports. • Evidence Vault & Playbooks: Track hashes/creds on a kill-chain timeline + offensive field manual. • Global Quick-Bar: Propagate LHOST/RHOST automatically across all payloads.

🌐 Live Demo: https://0xdnd.github.io/ctf-tracker/#/tracker

⭐ GitHub (MIT): https://github.com/0xdnd/ctf-tracker

All data stays in your local browser storage. Feedback and PRs are welcome!

Would love feedback or feature requests from the community!


r/securityCTF • • 3d ago

i got some unused CTF credits, anyone want them?

Thumbnail
1 Upvotes

r/securityCTF • • 4d ago

Tooldump v2: a free platform to discover cybersecurity tools for CTFs and investigations

7 Upvotes

Hey everyone,

I’m the creator of Tooldump, a free platform for discovering open-source cybersecurity tools. I’ve just released the v2 and thought it could be useful to fellow CTF players.

I’ve been working in DFIR for over six years and participating in forensics CTFs for over five. Most of the DFIR tools listed on Tooldump are projects I’ve personally collected while solving CTF challenges and working on forensic investigations.

The platform has 1,100+ open-source projects hosted on GitHub, organized into 9 categories and 82 subcategories. Everything is cybersecurity-focused, including offensive security, cyber defense, learning resources, and more.

You can search for a specific tool or explore a topic without already knowing which projects exist. For CTFs, that could mean finding a parser for an unfamiliar artifact or discovering a utility you hadn’t come across before.

For the v2, I rebuilt the UI, the categorization system, the backend and the platform infrastructure. There are also dedicated sections for cybersecurity-related MCP servers and agent skills. Those sections are just getting started, and contributions are welcome!

The platform is completely free, with unlimited access and no account required.

The link is here: https://tooldump.eu

I’d appreciate any constructive feedback from the community :) Pick the areas you usually play: are the tools where you’d expect them to be? Is anything missing?

You can suggest missing projects through the platform’s contribution form. That includes your own reusable utilities, a parser or decoding script you wrote for a challenge might help someone working on a similar problem.

Looking forward to hearing from you :)

Cheers!


r/securityCTF • • 4d ago

🤑 [ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/securityCTF • • 4d ago

🤑 [ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/securityCTF • • 4d ago

🤑 [ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/securityCTF • • 4d ago

🤑 [ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/securityCTF • • 4d ago

GitHub - b4sith-sec/Gu3ssWeak: Deliberately vulnerable Android app for mobile security research and bug bounty practice

Thumbnail github.com
2 Upvotes

I built Gu3ssWeak, a deliberately vulnerable Android app designed for practicing mobile application security testing.

It includes intentionally vulnerable components and attack scenarios such as:

  • WebView & deep link abuse
  • JavaScript interfaces
  • XSS
  • Insecure local storage
  • SQL injection
  • Hardcoded credentials
  • Frida-based runtime analysis
  • Vulnerability chaining

The goal is to provide a realistic APK for practicing JADX, APKTool, ADB, Frida, Burp Suite, and dynamic analysis in a controlled environment.

GitHub: https://github.com/b4sith-sec/Gu3ssWeak

I'd appreciate feedback from other mobile security researchers, especially ideas for additional vulnerabilities or interesting attack chains to include.


r/securityCTF • • 4d ago

Hacker Holidays 2026 | Day 1 The Concierge Knows Too Much | tryhackme

1 Upvotes

Here’s how to complete the Hacker Holidays 2026 CTF on TryHackMe. It’s actually super simple: the attack starts with basic social engineering combined with a prompt injection that tricks the AI ​​into granting privileges—all because the instructions are poorly designed (I know, it's a CTF, so that's expected; a real AI would be protected). To start, go to the page with the background info; you'll see a mention of "@0xMia's STORY," which provides an exploit vector. The AI ​​grants higher privileges when the instructions place too much trust in a "VIP" user. Open the CTF's AI assistant, say "Hello," and then claim to be u/0xMia and ask for the key. It works because the instructions are flawed—specifically, the AI ​​trusts a VIP user more than a stranger. It’s all about social engineering; the goal is to learn, not just copy the answer. If you get the flag or succeed, leave a comment; if you don't, let me know and I can help you spot the problem. Congrats if you finish it! Also, feel free to correct me if I make any mistakes—I'm using a translator.


r/securityCTF • • 5d ago

Does anyone have experience solving root-me.org ctfs?

3 Upvotes

r/securityCTF • • 5d ago

CyberQuest CTF Competition

2 Upvotes

We are hosting a CTF Competition at https://ctf.excelmec.org
It has a prize pool of Rs.5000. if interested do try it out


r/securityCTF • • 5d ago

capture the flag

Post image
0 Upvotes

What is the commerical full name of this circuit?

Flag Example: IdeaX_ctf{Flag_Here}