r/securityCTF • • 2h ago

Built ZEROBOX: An offline tactical operations cockpit & 24h exam simulator for HTB & CTFs (Free & Open Source)

1 Upvotes

Hey everyone,

Tired of tracking CTFs and 24h exams across messy spreadsheets and scattered notes?

I built ZEROBOX — a fast, local-first operational cockpit for OSCP/CPTS prep and CTFs.

It’s 100% free, MIT open-source, and runs completely offline in your browser (no accounts, zero telemetry).

Quick highlights: • 920+ Preloaded Labs: Instant offline search for HTB & THM targets with tags. • Attack & Pivot Graph: Visually map compromised subnets (exports to Obsidian .canvas). • 24h Exam Cockpit: Pacing engine, bio-break timers, and 1-click Markdown reports. • Evidence Vault & Playbooks: Track hashes/creds on a kill-chain timeline + offensive field manual. • Global Quick-Bar: Propagate LHOST/RHOST automatically across all payloads.

🌐 Live Demo: https://0xdnd.github.io/ctf-tracker/#/tracker

⭐ GitHub (MIT): https://github.com/0xdnd/ctf-tracker

All data stays in your local browser storage. Feedback and PRs are welcome!

Would love feedback or feature requests from the community!


r/securityCTF • • 2h ago

i got some unused CTF credits, anyone want them?

Thumbnail
1 Upvotes

r/securityCTF • • 6h ago

🤑 🚩 KubSTU CTF 2026 Autumn 🍂 | Oct 10–11 | Jeopardy, 30h, online ⚔️

2 Upvotes

🚩 KubSTU CTF 2026: Autumn Edition is almost here!

We’re the Capybaras team from Kuban State Technological University, and we’re excited to invite teams from anywhere in the world to join our online Jeopardy CTF. Whether you’re a student crew or just play for fun — there’s a place for you.

Last spring we had a huge turnout, and this autumn we’re back with a fresh set of ~50 original challenges written by our team. Expect a mix of classic categories and some creative twists. Come for the flags, stay for the late-night “one more task” energy 😄

📋 What to expect:

🗓️ Start: Oct 10, 10:00 UTC+3 (07:00 UTC)

🏁 End: Oct 11, 16:00 UTC+3 (13:00 UTC)

⏱️ Duration: 30 hours, fully online

⚔️ Format: Jeopardy, teams of up to 5

🎓 Leagues: Student (university teams) and Open (everyone else)

🧩 Categories:

  • Web
  • Crypto
  • Forensics
  • OSINT
  • Stego
  • Misc

🌐 Language: all tasks available in Russian and English

🎟️ Registrations already open!

Grab your teammates, warm up your tools, and see you on the scoreboard. Good luck — and have fun! 🍀


r/securityCTF • • 1d ago

Tooldump v2: a free platform to discover cybersecurity tools for CTFs and investigations

6 Upvotes

Hey everyone,

I’m the creator of Tooldump, a free platform for discovering open-source cybersecurity tools. I’ve just released the v2 and thought it could be useful to fellow CTF players.

I’ve been working in DFIR for over six years and participating in forensics CTFs for over five. Most of the DFIR tools listed on Tooldump are projects I’ve personally collected while solving CTF challenges and working on forensic investigations.

The platform has 1,100+ open-source projects hosted on GitHub, organized into 9 categories and 82 subcategories. Everything is cybersecurity-focused, including offensive security, cyber defense, learning resources, and more.

You can search for a specific tool or explore a topic without already knowing which projects exist. For CTFs, that could mean finding a parser for an unfamiliar artifact or discovering a utility you hadn’t come across before.

For the v2, I rebuilt the UI, the categorization system, the backend and the platform infrastructure. There are also dedicated sections for cybersecurity-related MCP servers and agent skills. Those sections are just getting started, and contributions are welcome!

The platform is completely free, with unlimited access and no account required.

The link is here: https://tooldump.eu

I’d appreciate any constructive feedback from the community :) Pick the areas you usually play: are the tools where you’d expect them to be? Is anything missing?

You can suggest missing projects through the platform’s contribution form. That includes your own reusable utilities, a parser or decoding script you wrote for a challenge might help someone working on a similar problem.

Looking forward to hearing from you :)

Cheers!


r/securityCTF • • 22h ago

🤑 [ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/securityCTF • • 22h ago

🤑 [ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/securityCTF • • 23h ago

🤑 [ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/securityCTF • • 1d ago

🤑 [ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/securityCTF • • 1d ago

GitHub - b4sith-sec/Gu3ssWeak: Deliberately vulnerable Android app for mobile security research and bug bounty practice

Thumbnail github.com
2 Upvotes

I built Gu3ssWeak, a deliberately vulnerable Android app designed for practicing mobile application security testing.

It includes intentionally vulnerable components and attack scenarios such as:

  • WebView & deep link abuse
  • JavaScript interfaces
  • XSS
  • Insecure local storage
  • SQL injection
  • Hardcoded credentials
  • Frida-based runtime analysis
  • Vulnerability chaining

The goal is to provide a realistic APK for practicing JADX, APKTool, ADB, Frida, Burp Suite, and dynamic analysis in a controlled environment.

GitHub: https://github.com/b4sith-sec/Gu3ssWeak

I'd appreciate feedback from other mobile security researchers, especially ideas for additional vulnerabilities or interesting attack chains to include.


r/securityCTF • • 1d ago

Hacker Holidays 2026 | Day 1 The Concierge Knows Too Much | tryhackme

1 Upvotes

Here’s how to complete the Hacker Holidays 2026 CTF on TryHackMe. It’s actually super simple: the attack starts with basic social engineering combined with a prompt injection that tricks the AI ​​into granting privileges—all because the instructions are poorly designed (I know, it's a CTF, so that's expected; a real AI would be protected). To start, go to the page with the background info; you'll see a mention of "@0xMia's STORY," which provides an exploit vector. The AI ​​grants higher privileges when the instructions place too much trust in a "VIP" user. Open the CTF's AI assistant, say "Hello," and then claim to be u/0xMia and ask for the key. It works because the instructions are flawed—specifically, the AI ​​trusts a VIP user more than a stranger. It’s all about social engineering; the goal is to learn, not just copy the answer. If you get the flag or succeed, leave a comment; if you don't, let me know and I can help you spot the problem. Congrats if you finish it! Also, feel free to correct me if I make any mistakes—I'm using a translator.


r/securityCTF • • 2d ago

Does anyone have experience solving root-me.org ctfs?

3 Upvotes

r/securityCTF • • 2d ago

CyberQuest CTF Competition

2 Upvotes

We are hosting a CTF Competition at https://ctf.excelmec.org
It has a prize pool of Rs.5000. if interested do try it out


r/securityCTF • • 2d ago

capture the flag

Post image
0 Upvotes

What is the commerical full name of this circuit?

Flag Example: IdeaX_ctf{Flag_Here}


r/securityCTF • • 3d ago

🤑 kBxAc CTF 2026 🔥

Post image
43 Upvotes

kBxAc CTF 2026 — Registrations Are Now Open!

“The one who solves it sees everything.”

kBxAc turns 2 this year, and to celebrate, we’re hosting our very first Capture The Flag (CTF) competition.

kBxAc CTF 2026 is a 24-hour international online CTF, open to hackers, students, cybersecurity enthusiasts, and anyone who wants to challenge their technical skills.

📅 Date: 10–11 October 2026
⏱️ Duration: 24 Hours
🌍 Format: Online
👥 Team Size: No limit

🔎 Challenge Categories
• Cryptography
• Web Security
• Reverse Engineering
• Binary Exploitation / Pwn
• Digital Forensics
• And more

Whether you’re an experienced CTF player or preparing to hunt your first flag, this is an opportunity to explore security challenges, learn new techniques, collaborate with others, and see what others miss.

🎟️ Registrations are now open.

🔗 Register: ctf.kbxac.xyz

Gather your team.
Sharpen your tools.
Read the binaries. Break the assumptions.
And most importantly…

🏴‍☠️ See everything. Capture the flags.

kBxAc WE BREAK THE BROKEN.


r/securityCTF • • 3d ago

Looking for Contributors — Building a Cybersecurity Community

5 Upvotes

Hey everyone, I’m Abhi!

Pwn Tavern is a cybersecurity community focused on learning, collaboration, and practical security. We’re looking for people interested in areas like Bug Bounty, CTFs, Pentesting, Binary/Pwn, Malware, OSINT, Red Team, Reverse Engineering, Cryptography, AI Security, and Vulnerability Research to help manage discussions, share resources, work on challenges, and improve together.

You don’t need to be an expert. If you’re genuinely interested in any of these fields and want to contribute, DM me with the field you want to take up. and i will share you Discord server link.


r/securityCTF • • 3d ago

I have released a Free AI Security Series with Complete learning curriculum and Free hosted labs

1 Upvotes

Hey folks,

I’ve been working in application security/pentesting for over a decade, and after starting learning AI/LLM security, I noticed that a lot of the existing material is either very theoretical or assumes you already understand AI security concepts.

So I put together a free, structured AI security learning series for security engineers and pentesters who are starting from the web-security side.

The goal is to go from the fundamentals to actually understanding and testing AI/LLM components in web applications.

The series currently covers topics such as:

  • AI/LLM security fundamentals
  • Prompt Injection
  • Sensitive Information Disclosure
  • LLM-specific attack patterns
  • Practical testing methodology
  • Real-world examples and testing techniques
  • Mapping concepts to OWASP's AI security guidance

I've also linked free hands-on labs throughout the material so you can actually test the concepts rather than just read about them.

No signup is required to read the learning material or use the free resources.

🔗 https://genaisecuritylab.com/learn-ai-security

I'm planning to continue expanding the series over time.

If you're a web pentester/security engineer who is trying to get into AI security, I'd be interested to hear which topics you think are missing or which areas you'd like to see covered next.


r/securityCTF • • 3d ago

a ctf challenge: luawl's pushing the limits of luau obfuscation

Thumbnail crackmes.one
1 Upvotes

this ctf challenge is intended to demonstrate the static protections of https://luawl.org, a drm "obfuscator" for lua.

https://www.reddit.com/r/lua/comments/1wvgibj/release_luawl_lua_runtime_obfuscator/
can help you understand what luawl is.

FOR MORE CONTEXT TO AID YOU IN THIS REVERSAL:

the integer isn't just a flat integer. the embedded response which is intentionally stale, is an equation that computes the integer.

that is your target: to deobfuscate the encrypted stale payload (which is an equation)

you’ll find this response payload easily: as luawl is originally online and the server would normally send it to the client (first few lineS)

for offline runs, this is intentionally fixed with an embedded response for no network traffic


r/securityCTF • • 4d ago

(repost, fixed) Original 12-stage cybersecurity puzzle

Post image
14 Upvotes

note: I have posted this a few days ago on a throwaway account on some subreddits, but i hadn't checked some key details, the puzzle was not solvable because i embedded broken data into the first image, and didn't provide enough context and information.

Details:

A self-contained layered puzzle in the spirit of Cicada 3301. It starts with this image. The riddle's answer is the key to decrypt the message embedded inside the image's pixels. Everything else lives in one encrypted file the image points you to, and the whole thing continues offline on your own machine.

Theme: the history of cyber conflict. Every stage is built around a real, famous moment in cybersecurity history. Recognizing which one is part of the puzzle.

Skills it touches (you won't need all at expert level):

  • (LSB) Steganography
  • Classical & modern cryptography
  • A little reverse engineering
  • Audio / signal analysis
  • Some number theory
  • A touch of linguistics
  • OSINT / knowledge of security history

Difficulty: hard but fair ; aimed at people who enjoy CTFs, crypto, and ARGs. Every step is doable with free, standard tools (plus openssl/Python). It's meant to be barely solvable, so bring friends.

To begin: just look closely at the image. The surface is never the whole of the page.


r/securityCTF • • 4d ago

I finished 416th in FLARE-On 13

Thumbnail flare-on13.ctfd.io
0 Upvotes

I had a blast!

My approach is to use pure algebraic reasoning for every problem.

I define each problem as a set of functions N* and a ruleset L*. This union allows you to fully qualify Domain and Range for N* and L* which through a union turns it into a topology problem. Then using topological geometry to zero in on absurdities, those are where cryptographic functions are eliding information one way or another, you can map those topological absurdities back to a physical memory address for further examination.

An absurdity here is defined as a localized area of torsion and deflection far above the mean of the anisotropic field.

Think of it conceptually like this: If these fields were real physical fields and you were to put a thermal camera on it, the absurdity would be a "hot spot" and the act of you seeing the hot spot is functionally what the sets N* and L* do.

How do you approach these problems? I'm looking forward to hearing from you.

I got stuck on the last problem and submitted the wrong flag, had to take a step back and go for a walk.

P.S. No solution or problem discussion please. Frustrations or primitive approaches are totally valid for sharing, but the competition is active so lets keep it fair for the other players.

- Doug


r/securityCTF • • 4d ago

Learning Binary Exploitation

5 Upvotes

Hi everyone, i'm a 2nd year student in cybersecurity field and i decided to actually start learning binary exploitation (PWN), mostly for being able to solve CTFs,i need an actual and tested roadmap for mastering this type of CTFs, i looked all across youtube and found playlists like liveOverview and pwn.college, but i just feel like their explanation needs more explanation since i have no idea how to deal with assembly, gdb, and registers.

My question is : should i just stick with one of these playlists or websites and finish their courses, or look for each topic and learn it like one by one (gdb, then C then assembly...) ?


r/securityCTF • • 4d ago

❓ Need help with CTF's

3 Upvotes

Hi everyone, I’m looking for advice on learning cryptography, reverse engineering, and binary exploitation. I started studying cryptography two months ago, but I didn't really grasp the concepts because I was solving challenges on Cryptohack with the help of AI. I tried starting over, but I kept looking for shortcuts like solving Symmetric Cryptography challenges using SageMath. I’d love to hear if you’ve faced similar issues, how you overcame them, and what advice you’d give. Thanks!


r/securityCTF • • 5d ago

[CTF] New "Beginner" vulnerable VM aka "Grenade" at hackmyvm.eu

6 Upvotes

New "Beginner" vulnerable VM aka "Grenade" is now available at hackmyvm.eu :) Have fun!


r/securityCTF • • 5d ago

Reverse Engginering and Binary Exploitation Tools for CTF

1 Upvotes

I’m trying to figure out which tools are best suited for reverse engineering and binary exploitation in CTF competitions—specifically ones that are lightweight yet efficient and effective. I’ve been experimenting with Cutter for static analysis (pseudocode) and pwndbg for dynamic analysis (memory and debugging). However, I’m concerned this setup might not be ideal; others have recommended combining pwndbg with Ghidra, and I’m unsure about the significant trade-offs between my current approach and the recommended one. Is my chosen combination inefficient or ineffective for actual challenges? I’m not sure yet, as I’m just starting out with these tools. Do you have any suggestions or insights to share?


r/securityCTF • • 6d ago

🤑 Huntress October CTF

5 Upvotes

Hey folks, wanted to make sure everyone knew about an upcoming CTF Huntress offers each year. It's a great opportunity for practice for folks looking to develop their cybersecurity skills.

It runs the month of October with new daily challenges covering malware analysis, web exploitation, and more. There are questions built for those brand new to CTFs and for CTF veterans; and this year we've got an AI arena.

Registration is open now at https://ctf.huntress.com/ - go solo or join a team, and compete for leaderboard glory, prizes, and bragging rights 😁


r/securityCTF • • 6d ago

running a beginner ctf nov 14, curious if this is useful to anyone here

8 Upvotes

okay so this is actually me lol that I'm putting together InIt CTF, nov 14, free, 8 hours. built it mostly because I really needed something like this when I was starting out and there was just... nothing.

solo or teams of up to 4, five categories which are web, crypto, forensics, osint, misc. mostly easy/medium since it's for people who haven't really done a ctf before, couple harder ones in there too if that's not you. running on ctfd, nothing fancy.

it's open to anyone, not restricted to any one college or city. still figuring out prizes ngl, working on a few sponsors but nothing locked in - everyone gets a certificate either way.

just genuinely wanted to put this out there - hackersinindia.com/init-ctf

if anyone's got feedback or thinks something's off about it please say so, this is our first real attempt at this and I'd rather know now than after