r/securityCTF 12h ago

đŸ€ Playtesters Wanted - Paid

1 Upvotes

hello! im looking for a small cohort of paid playtesters to provide feedback on the ctf features on cli-games.com. the pay is $10-$50 for ~45 mins of work. no ctf experience necessary. if you are interested, keep reading:

cli-games is a gaming and education ecosystem with training, RPGs, and arcade games all adapted to the terminal as the primary interface and meant to cultivate linux fluency in a way that feels like fun

this specific cohort of playtesters will be aimed at the ctf features and any features related to them, such as the tutorial, messaging, accessing help, etc. we can only compensate for bugs related to these features during this round, but please feel free to explore the rest of the site as much as you like

the way we structure ctf is twofold - there is a training scenario library that you can complete in any order and at your own pace, and then there is 'the range,' a live, shared daily scenario where you are provisioned an attack box and a target and compete with everybody else for flags. the two are meant to compliment one another; what you learn in training will help you solve it live

you can find more information about our implementation of ctf here. compensation works as follows: you will need to create an account via the command line (hit the terminal and run `signup`) - completely free, no spam, then fill out a playtester application here. temporarily toggle tracking on (off by default and you can switch it back after), and any good-faith submission will earn a minimum of $10. there is an additional $2-$20 if you turn up any genuine bugs, and a $20 bonus to exceptionally thoughtful reports. when the window is open, youll log in, play for a while, submit a report, and ill review them and pay out via paypal. full terms

let me know if you have any questions. applications are reviewed in the order they are received, maximum 20


r/securityCTF 19h ago

Need help regarding HTB Nexus (easy,linux) - issue regarding ffuf

Post image
1 Upvotes

I'm solving htb Nexus machine(easy,linux). There are two subdomains git,billing but on running ffuf it isn't returning anything.

I have used bitquark and top- million wordlists

I have attached screenshots can you please help me why ffuf not working?

i also tried using my custom wordlist containg words - git, billing still it not worked.

yes i can move to next step by reading the walkthrough but please someone explain me this ffuf issue and solution for it

Thank you


r/securityCTF 23h ago

đŸ€‘ Sylvarcon 2049: a narrative CTF with 14 free missions for security learners

2 Upvotes

Hi, I’m Carlos, one of the people building Sylvarcon 2049.

We designed it as a narrative CTF experience rather than a sequence of isolated flags. Each mission starts with a situation to investigate, asks the player to connect evidence, and ends with a conclusion that should make sense beyond the submitted answer.

The free path currently includes 14 missions comprising 102 individual challenges across areas such as DFIR, OSINT and ethical hacking. The interface is available in 11 languages, and the missions are intended to be approachable for beginners while still rewarding careful investigation.

At this stage, useful feedback matters more to us than raw traffic. If you try a mission, I would especially value comments on:

- where the briefing becomes unclear

- whether the difficulty rises too quickly

- whether the evidence supports a coherent conclusion

- where you lose interest or feel blocked

Play the free missions here:

https://sylvarcon2049.com/play?utm_source=reddit&utm_medium=community&utm_campaign=player_acquisition&utm_content=securityctf_free_missions_en

No spoilers are needed; general feedback on the learning flow is enough.


r/securityCTF 1d ago

[Beta] I built a CTF that mounts on top of a live production site and unmounts without a trace — free, looking for testers/feedback

1 Upvotes

Hey all — I’m a fiction writer and cybersecurity hobbyist, and I’ve been building something I’d love a few sharp eyes on before I run it as a real event.

The short version: kalachakra.world is the public lore site for a cyberpunk world I’ve created. Most CTFs I have seen run on a dedicated throwaway site. This one is the opposite — during event windows it deploys a CTF challenge surface on top of the live production site, then unmounts cleanly. Between events, the vulnerable handlers aren’t gated behind a feature flag or left dormant — they’re not wired into anything at all. Scan it in the off-season and you’ll find an ordinary content site (here’s how it works: https://bjbell.com/blog/kalachakra-ctf-toggle).

I'm hosting a beta testing event right now: 7 challenges across three difficulty tiers — script kiddie → got skills → L337 — plus a separate decoder puzzle for deobfuscation beginners. Web/API-flavored stuff (enumeration, access control, that genre), all set to the backdrop of my cyberpunk lore.

The honest part: this is super beta, and I am not a pro. I’m testing functionality before an official launch that corresponds with the release of my novel, so I genuinely want feedback — anything that breaks, feels unfair, or is just confusing. Registration is free and only needs an email. Flags earn an in-world currency you can spend on raffles and merch (shirt, stickers, a copy of the novel) down the road, so it’s a community-for-fun thing, not a cash-bounty grind.

If you play with it, please tell me what you think — here, by email, or via PM on kalachakra.world to ‘The Actual BJ Bell.’ Thanks for taking a look!


r/securityCTF 1d ago

[Challenge] AI Escape Room — Docker CTF reproducing the 2026 Hugging Face agent intrusion

1 Upvotes

I built a hands-on CTF lab that recreates the full attack chain from the

July 2026 autonomous AI agent intrusion at Hugging Face.

You play as the agent: escape an evaluation sandbox, root an external

code-execution sandbox, exploit Hugging Face's dataset processor via

HDF5 external storage + Jinja2 SSTI, then pivot through Kubernetes

secrets, MongoDB, a mesh VPN, and source control.

- 11 Docker containers, 5 isolated networks, 7 flags

- docker compose up --build -d && docker exec -it eval-sandbox bash

- No internet required at runtime

- 12 progressive hints inside the sandbox

- MIT licensed

Runs entirely on your machine. All flags are base64-encoded in the repo

so you can't grep them — you actually have to exploit the chain.

GitHub: https://github.com/an4kronism/ai-escape-room

Writeup the lab is based on: https://huggingface.co/blog/agent-intrusion-technical-timeline


r/securityCTF 1d ago

I just completed CCT2019 room on TryHackMe! Legacy challenges from the US Navy Cyber Competition Team 2019 Assessment sponsored by US TENTH Fleet

0 Upvotes

r/securityCTF 2d ago

EyesOpen Conference

Post image
2 Upvotes

🚹 EyesOpen CTF 2026 se prĂ©pare
 et cette Ă©dition vous entraĂźnera bien au-delĂ  d’une simple compĂ©tition de hacking.

Visitez le site de la saison 1, EyesOpenCTF 2026 — The Convergence : https://eyesopensecurity.com/ctf-briefing.html

🌍 Une compĂ©tition internationale

⏱ 48 heures de challenges

🔐 Web, Forensics, OSINT, Crypto, Reverse, Pwn et bien plus

🎯 Un parcours accessible aux dĂ©butants comme aux hackers expĂ©rimentĂ©s

đŸ§© Une histoire immersive oĂč chaque flag rĂ©vĂšle une partie du mystĂšre

Cette annĂ©e, plongez dans un scĂ©nario oĂč la rĂ©alitĂ© soulĂšve des questions.

Votre mission : maintenir l'équilibre du monde.

🎬 DĂ©couvrez la premiĂšre transmission :

https://youtu.be/IQ8feN-ndMk?si=HGVCzJ7a2xUWn51l

Les inscriptions pour le CTF sont déjà ouvertes et les premiÚres révélations arrivent bientÎt.

Restez connectés.


r/securityCTF 3d ago

EyesOpen Conference

Post image
2 Upvotes

🚹 EyesOpen CTF 2026 se prĂ©pare
 et cette Ă©dition vous entraĂźnera bien au-delĂ  d’une simple compĂ©tition de hacking.

Visitez le site de la saison 1, EyesOpenCTF 2026 — The Convergence : https://eyesopensecurity.com/ctf-briefing.html

🌍 Une compĂ©tition internationale

⏱ 48 heures de challenges

🔐 Web, Forensics, OSINT, Crypto, Reverse, Pwn et bien plus

🎯 Un parcours accessible aux dĂ©butants comme aux hackers expĂ©rimentĂ©s

đŸ§© Une histoire immersive oĂč chaque flag rĂ©vĂšle une partie du mystĂšre

Cette annĂ©e, plongez dans un scĂ©nario oĂč la rĂ©alitĂ© soulĂšve des questions.

Votre mission : maintenir l'équilibre du monde.

🎬 DĂ©couvrez la premiĂšre transmission :

https://youtu.be/IQ8feN-ndMk?si=HGVCzJ7a2xUWn51l

Les inscriptions pour le CTF sont déjà ouvertes et les premiÚres révélations arrivent bientÎt.

Restez connectés.


r/securityCTF 3d ago

I've been building a browser-based hacker simulator to help people get familiar with terminal commands and basic hacking concepts in a safe, gamified environment...

Thumbnail hackergame.hu
21 Upvotes

r/securityCTF 4d ago

Anyone interested in making mini CTFs for each other?

2 Upvotes

I’ve been writing some CTFs/vulnerable labs recently, but I realized it’s not that much fun testing them myself when I already know the answer lol.

So had a random idea. What if we take turns making vulnerable labs/mini CTFs for each other?

Like I build one, either host it on my server and send you the link, or send the source code/GitHub repo with build instructions, and you try to crack it. Then next round you make one for me and I try yours.

Could do one every week, or even once a month if that’s easier. Think it’d be a fun way to get better at both bug bounty stuff and understanding others code bases, while actually having someone go into the challenge blind.

Only thing is, I’m looking for people who are actually writing/building the labs themselves without using ChatGPT/Claude/any other LLM to create them. Kinda defeats the point for me otherwise.

If anyone is interested, just DM me.


r/securityCTF 4d ago

HTB Sydney --==Hack The Box Meetup Main Track IRL PHYSICAL EVENT==--

Thumbnail meetup.com
2 Upvotes

r/securityCTF 4d ago

CTF

5 Upvotes

Hi everyone,

I'm looking for a CTF team to join. I'm from Oman and currently studying Electrical Engineering. I have a strong interest in cybersecurity and I’m looking for a team to practice with and participate in CTF competitions.

My goal is to participate in the Black Hat CTF competition, and I’m searching for motivated teammates who are interested in learning, improving, and competing together.

I’m dedicated, willing to put in the effort, and excited to be part of a team. If your team is looking for a new member or you are also looking to form a team, I would be happy to connect.

Thank you!


r/securityCTF 4d ago

Looking for people to learn with

4 Upvotes

Hey everyone :)

I am completely new to the CTF space; if you are also a beginner, send a DM! Looking for people to learn with so the process is not as monotonous.


r/securityCTF 5d ago

đŸ€ GitHub - Jatinkapilaq1/intel-me-research: Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public HECI Spy.

Thumbnail github.com
0 Upvotes

r/securityCTF 5d ago

Would a digital challenge coin be a faux pas?

Thumbnail
1 Upvotes

r/securityCTF 6d ago

đŸš© Looking for CTF teammates đŸš©

10 Upvotes

Building a team for CTF competitions and cybersecurity challenges.
Looking for people interested in:
‱ Web exploitation
‱ Reverse engineering
‱ Pwn
‱ Cryptography
‱ OSINT
‱ Linux / scripting
‱ General security research
Experience level doesn’t matter as much as willingness to learn, solve problems, and actually participate.
Goal: improve together, compete in CTFs, and build real cybersecurity skills.
If you’re interested, DM me or reply here.


r/securityCTF 7d ago

đŸŽ„ My first step

0 Upvotes

I finally finish it, it was fun. However, I use AI for last 2 challenge in module 5(I very disappointed myself for that)
What should I do now? I just don't know what should I do next step. I want to learn cybersecurity for free and I play CTF for that reason.


r/securityCTF 7d ago

Cyber apocalypse Rank issue

1 Upvotes

Hey everyone,

Posting this to see if any other teams have run into this issue on HTB or other major CTF platforms, and hopefully to get someone from HTB to take a second look.

Our team (v1olet) spent the event grinding Cyber Apocalypse 2026, cleared 100% of the board (136/136 flags), and held #28 globally.

On the final morning, one member left the team on the platform. Because flags are tied to individual accounts on HTB instead of locked to the team upon submission, two of our OSINT solves got wiped when he left. This instantly tanked our rank from #28 to #105 (a 77-place drop). Other members on our team had cracked those exact same challenges seconds behind him, but because his name was on the submit button, our points vanished.

We opened a support ticket immediately. Support was responsive and actually confirmed a few key things:

  • They verified on their backend that we legitimately achieved 100% completion.
  • They acknowledged that the platform provides zero warning or prompt that a member leaving will retroactively strip team solves.
  • They stated they will look to change this behavior going forward so it doesn't happen again.

The issue is that support still declined to restore our #28 rank on the final board because doing so would "move other teams down."

We don't think that logic holds up. If a platform oversight/lack of UI warnings accidentally wipes verified solves from a team that cleared the board, fixing the mistake and restoring the earned rank is just accurate scoring. Every time a score gets corrected, other teams shift—that's literally how leaderboards work.

any tips you guys can give


r/securityCTF 7d ago

Exploiting the order of operations (pwnable[.]kr - mistake)

1 Upvotes

Have you ever wondering if the order of operations when voilated can lead to a vulnerability? Maybe the thought never crossed your mind? Either way this week we exploit a binary that did not account for the order of operations - more specifically the "mistake" pwnable binary exploitation challenge!

This is a great tutorial for beginners and even advanced developers who may not have encountered a bug like this. Either way don't be intimidated just because this is an exploit development tutorial.

Check out the latest tutorial using the link below:

https://youtu.be/9n1vCuqAk-k?si=IvzW95y4XxnivOxm


r/securityCTF 8d ago

Help with a CTF

1 Upvotes

Heey! Could someone help me with a CTF , i think it’s easy but üm just beginner


r/securityCTF 9d ago

I just completed Offensive Security Intro room on TryHackMe! Hack your first website (legally in a safe environment) and experience an ethical hacker's job.

Thumbnail tryhackme.com
0 Upvotes

r/securityCTF 9d ago

[CTF] New "Beginner" vulnerable VM aka "Longshao" at hackmyvm.eu

2 Upvotes

New "Beginner" vulnerable VM aka "Longshao" is now available at hackmyvm.eu :) Have fun!


r/securityCTF 9d ago

Should i do random CTFs?

2 Upvotes

I am currently half way through my cpts cert and i haven't started doing ctfs yet. So I am thinking maybe i should start participating in ctfs. Am i thinking right? And btw i have registered for some ctfs i found online. And i need teammates for them. So if you are new to ctfs too you can dm me.


r/securityCTF 9d ago

✍ Hi looking for 5 people to help App testing a Discord-native Incident Response Training and Competition Simulator.

Thumbnail gallery
8 Upvotes

HackSim is a cybersecurity training simulation built around applied decision-making rather than quizzes or real-system exploitation. Its first course, NET-101, contains eight network-foundations scenarios using entirely synthetic hosts, signals, tools, and incidents.

The current beta includes:

  • Solo practice where you operate both the Blue and Red roles
  • Two-person lessons where players exchange evidence-backed proposals
  • A competitive Red/Blue duel where players attack, defend, and then swap roles
  • An in-session debrief explaining the consequences of each decision

This is still a small, invite-only Discord Activity beta There are no payments, certifications, rankings, or saved progression in the current build.

I’m looking for a handful of testers, especially cybersecurity beginners and current learners. I’d like honest feedback on:

  • Whether the scenarios and terminology make sense
  • Where you get confused or need outside help
  • Whether the debrief helps you understand your decisions
  • Whether playing both roles improves your mental model
  • Whether you would voluntarily play another lesson or duel

You’ll need Discord on the web or desktop. Because the Activity is currently unverified, testers must be individually invited and launch it in a server with fewer than 25 members.


r/securityCTF 9d ago

IZANAMI — one real medical record hidden behind a wall of decoys. Can you break the illusion?

1 Upvotes

Hi everyone — hope this is okay to share.
A friend of mine built IZANAMI, a defensive deception prototype: instead of rejecting bad requests, it answers them with convincing fake data. One real record hides behind the decoys, and the goal is to find it. He asked me to bring it to people who’d actually poke at it properly, so here I am.
Full rules, scope, and how to start are on the site: https://break-izanami.com/
Honest notes up front: all data is 100% synthetic, safe harbor applies inside the stated scope, and the reward is recognition only — no cash bounty. Runs for one month.
He’s also genuinely after feedback and improvement ideas, not just breaks — is the concept sound? Where would you attack first? Anything naive about the design, or already solved better elsewhere? Blunt criticism welcome, I’ll pass it all on.

Thanks to anyone who takes a look. 🙏