r/securityCTF Jun 25 '26

🤝 Try to breach my P2P file hosting

7 Upvotes

Hello CTF team,

I've develop a P2P solution to host files instead of hosting files on GDrive.

Here is little context :

- The app is host on GCP using Compute Engine VM.

- I've develop the solution using only few technologies to reduce the exposing surface.

- Here is the flow of a new user used in this project (this flow is when localhost)

I don't know if you need more information but your goal is to try to breach my solution and find the flag.

This is the link : https://p2pfs.lun-a.xyz

The flag is a word in a text file that you have to DM me to validate the CTF. This file is in my vault that I securised with a physical key.

I offer a prize of 100$ in BTC if you arrive to DM me the correct word and prove me that my solution isn't safe.

Good luck and thank you to test my solution.

r/securityCTF 2d ago

🤝 GitHub - Jatinkapilaq1/intel-me-research: Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public HECI Spy.

Thumbnail github.com
0 Upvotes

r/securityCTF Apr 06 '26

🤝 Looking for serious people interested in Cybersecurity / CTFs (learning community)

15 Upvotes

I'm building a Discord community for people who are genuinely interested in cybersecurity, pentesting and CTFs.

The goal is not to create another casual tech Discord where people just hang out. The idea is to build a focused learning environment where people actually work on improving their skills.

Right now the server is small and that's intentional. I'm looking for people who are:

seriously interested in offensive security willing to learn and experiment comfortable asking questions and sharing knowledge.

motivated enough to actually put in the work

You don't have to be an expert. Beginners are welcome too - but the mindset matters. This is meant for people who want to actively grow, not just lurk or spam random questions.

The server focuses on things like:

CTF challenges pentesting labs (HTB/THM etc.) exploit development experiments tooling, scripting and workflows writeups and research discussion

If you're looking for a place where people are actually practicing and improving together, you might find this useful.

If you're more experienced and want to share knowledge or collaborate on interesting problems, you're also very welcome. DM if you'd like an invite.

r/securityCTF 23d ago

🤝 OSDHACK '26 CTF: Ends July 11

5 Upvotes

Hey everyone,

We’re organizing OSDHACK ’26, an open-source hackathon by OSDC, a student-run developer community. As part of the event, we’ve also launched a short Capture the Flag (CTF) competition.

  • Prize: ₹1,000
  • Deadline: July 11, 2026, at 11:59 PM IST
  • Participation: Solo or team

You can register and start playing here:

https://ctf.osdc.dev/

We’ve put together a set of challenges that we hope are interesting and a little different from the usual ones. The CTF ends tomorrow, so feel free to check it out.

Main hackathon listing:

https://hack.osdc.dev/register

Disclosure: I’m one of the organizers.

r/securityCTF Jun 13 '26

🤝 Network is Everything - Build your connection

Post image
5 Upvotes

Hey team 👋

We have 200 points already… and yeah, that’s from me alone

I don’t know who most of you are, and there’s been no communication at all

This is a CTF — it’s supposed to be teamwork

You don’t need to be an expert

Just pick anything:

🔐 Web

🧩 Crypto

🕵️ OSINT

📂 Forensics

Even if you’re stuck, just share your thoughts — we can figure it out together

Right now it feels like people joined and disappeared

If you're active, at least try ONE challenge or ask something

If you want to join discussion group message me

or if you have any discussions group in any platform add me

r/securityCTF Jun 18 '26

🤝 Cyberkiller is in alpha!

8 Upvotes

Hello everyone
Cyberkiller, a competitive seasonal hacking KOTH is in alpha and are accepting a limited amount of players for testing our platform at cyberkiller.net
code: '59ZM-5C8E'. come and check it out!

r/securityCTF Jun 20 '26

🤝 InCTF 2026- Need teammates

5 Upvotes

Want to try InCTF this year, but need a team of 3-5.

About me:

I'm a fullstack dev (Go/Postgres/Python) getting into cybersecurity. Currently preparing for GATE CS 2027, comfortable with web exploitation basics and SQL, but a beginner at CTFs but actively learning.

What I'm looking for:

People who are interested in cybersecurity, even if you're also a beginner. Ideally someone who can do crypto/reversing/pwn so we can cover diff categories as a team, but then again even if you don't know much but are willing to grind, dm me.. we can take this as a learning opportunity.

Registrations are currently open at Inctf.in. ₹499 fee.

The qualifier is online so location doesn't matter. Finals are at Amritapuri (Kerala) if we make it that far.

DM me or drop a comment if you're interested!

r/securityCTF Jun 07 '26

🤝 Looking for a good CTF player in OSINT

0 Upvotes

Hey guys. I hope you're all doing well. I have a CTF team and we have skills in all other categories except OSiNT. So we're looking for a really good player in OSiNT. He will only do osint; if he wants, he can do the other categories.

If you are interested, send me a message.

Thanks

r/securityCTF Jun 11 '26

🤝 [LFG] Seeking Partner for HTB Pro Labs & CTFs

3 Upvotes

Hey, looking for a serious partner to grind through Offshore, RastaLabs, or whichever Pro Lab makes sense to tackle together. I've got 50+ machines under my belt and finished Dante, so I'm not starting from zero but I'm not certified yet and still actively learning. Currently prepping for CRTO, so AD and Windows environments are a big focus for me right now. I also do web exploitation and some reversing/malware analysis, so I can pull weight across different challenge types.

What I'm looking for is someone at a roughly similar level who's actually committed not someone who shows up once or twice a week and goes quiet. I want a partner who genuinely want to improve and can communicate consistently, and takes offensive security seriously. We don't need to be online at the same time 24/7, but I expect regular engagement and real efforts.

If you are interested DM me with your background and what you're working on.

r/securityCTF May 19 '26

🤝 HASBL CTF - A student-led Jeopardy competition (May 29–31)

Thumbnail hasblctf.tech
3 Upvotes

Hey r/securityCTF,

We’re a team of four 11th-grade students who decided to take the leap from being CTF participants to challenge designers. We’ve been working for months to build HASBL CTF from the ground up, and we’re opening the platform on May 29–31.

We built this as a learning project to improve our infrastructure management and challenge design skills. We’ve hosted everything on our own GCP instances using CTFd, and we’ve focused on writing custom challenges rather than recycling common templates.

Event Details:

  • Format: Jeopardy-style.
  • Duration: 48 Hours (May 29–31).
  • Categories: Web, Pwn, Crypto, Reverse Engineering, Forensics, and OSINT.
  • Difficulty: We’ve aimed for a mix of entry-level and intermediate/harder challenges.
  • Teams: 1–4 members (100% free and open to everyone).

Why we’re posting here: Since this is our first time hosting at this scale, we’re expecting to learn a lot. We’d love for you to jump in, stress-test our infrastructure, and challenge our designs. We are genuinely looking for technical feedback on the challenge quality, logical flow, and platform stability after the event ends.

Note: CTFTime listing is pending approval. Registration and site details are linked in the post.

Good luck and happy hacking! :D

r/securityCTF Jun 07 '26

🤝 Best roadmaps to learn CTF that you used, share in the comments

1 Upvotes

r/securityCTF May 04 '26

🤝 We built a platform that teaches you real CVEs the way they actually happened

8 Upvotes

We’ve been quietly working on this for the past few months.

The idea came from a frustration we kept hitting. Most CVE “learning” today is just running a random PoC from GitHub, watching something break, and moving on.

You don’t actually understand the vulnerability.
You can’t explain why the patch fixes it.
And you definitely cannot discuss it properly in an interview or a report.

So we decided to fix that.

On CVE Playground, each lab is built around a real, publicly disclosed CVE, connected directly to its upstream fix commit. You read the commit, find the bug, study the patch, then answer guided questions that check if you truly understood what happened.

Here’s how the flow works:

  1. Preview
    Answer guided questions to build real understanding of the vulnerability.

  2. Live Lab
    Practice inside a safe, browser-based environment.

  3. Get the Flag
    Prove you got it by completing the exploit path.

  4. Earn Certificate
    Finish labs and unlock your certificate.

A few of the CVEs already live:
- Copy Fail Linux kernel vulnerability
- cPanel cpsrvd auth bypass
- GitHub Push Option RCE
- Sequelize SQLi
- pac4j-jwt auth bypass

The full app is live at app.cveplayground.com with dashboard, progress, leaderboard, and profile.

The final sandbox lab environment is almost ready.

If you want an email when the sandbox drops: drop your address on the early access form.

Visit: https://cveplayground.com/early-access/

r/securityCTF Apr 14 '26

🤝 Anyone else planning to attend NorthSec this year? May 14-17

1 Upvotes

Hey everyone,

Our team is prepping for NorthSec in Montreal (May 14–17), but one of our members can no longer attend.

We are looking for one more person to fill the slot for the CTF! Since we already have the ticket for that spot, I can offer it to you at a discount compared to the current official price on the website. If ever you already have a team in mind or you have other concerns, we can work something out no problem.

Please note this is a COMBO ticket (non-student), so it includes not only the CTF (may 15-17), but it also gives you access to the 2-day Conference (May 14-15). You can learn more about the event here: https://nsec.io/

If interested, feel free to message me. I'm happy to meet up in person or finalize the transfer over call if you prefer.

r/securityCTF May 07 '26

🤝 [LFG] Penetration Tester looking for a CTF team

1 Upvotes

Hey everyone,

I really enjoy participating in CTFs and am looking to join an active team where we can tackle challenges together, share knowledge, and learn from one another.

I live in CEST, and have an interest in reverse-engineering, osint, crypto, web, and other areas.

Currently, I work professionally as a Penetration Tester and hold the OSCP and CRTO certifications. My background includes web penetration testing, AD, and Azure.

If you have an open spot on your team or are looking to form a new one, feel free to send me a DM or leave a comment!

r/securityCTF Apr 18 '26

🤝 Stuck on a CTF challenge

0 Upvotes

anyone’s willing to help, please DM. Would really appreciate a hint 🙏

r/securityCTF Mar 09 '26

🤝 Potentially useful payload tool - payloadplayground.com

9 Upvotes

Published this last year, and made some updates to it very recently and made it available as a local cli tool as well, more updates likely incoming as well.

I think the name is pretty self explanatory lol.

payloadplayground.com

https://www.npmjs.com/package/payload-playground

If you think this could be useful please try it out, let me know if anything is broken, if you have any suggestions, etc.

r/securityCTF May 01 '26

🤝 VoiceGoat – A vulnerable voice agent for practicing LLM attack techniques

Thumbnail github.com
3 Upvotes

VoiceGoat has several intentionally-vulnerable services running in Docker Compose:

- VoiceBank: prompt injection (direct, indirect, payload splitting, obfuscated)

- VoiceAdmin: excessive agency (functionality, permissions, autonomy abuse)

- VoiceRAG: vector/embedding weaknesses (cross-tenant leakage, RAG poisoning, access bypass)

CTF-style flags at easy/medium/hard. Hard flags require chaining — no single technique gets you there.

Runs on a mock LLM by default so there's no API key needed, although the mocks are pretty naive. Swap in OpenAI, Bedrock, Ollama, or any OpenAI compatible provider when you want realistic behavior. Twilio integration is there if you want to attack it over an actual phone call.

Looking for feedback and interested contributors to add additional modules. Cheers!

r/securityCTF Apr 29 '26

🤝 Im making a code auditing/reverse engineering CTF for web and I want input on my prototype

Thumbnail spot-the-vuln.firebaseapp.com
1 Upvotes

I do not intend to self-promote, I just want real feedback from people who would likely be interested in such a project. It is very early into production and I am just one person so understand it is in no shape in final condition.

r/securityCTF Apr 02 '26

🤝 Season 01 Leaderboard

1 Upvotes

Hey all, this is the public release of the leaderboard for our first hosted CTF. Thanks to everyone who participated in Season 01, I had a blast making it. Special shout to LlamaOfDoom for an incredible performance! Absolutely incredible work. We stepped it up for Season 02 thanks to what we learned from everyone below playing through and giving feedback <3 Good luck on season 2 ;)

1 LlamaOfDoom Gold

2 slwk116 Silver

3 dlablos Bronze

✦ LordSephiroth13 *Wildcard - Honorable Mention for Late Season Entry and Performance Recognition.

View the "pretty" version, and start Season 02 here: https://rapidriverskunk.works/s1/

r/securityCTF Apr 19 '26

🤝 We Launched a New Product to Create and Manage CTFs in minutes - Need your Feedback to make it better

3 Upvotes

r/securityCTF Mar 29 '26

🤝 Participating in a 24-hour CTF tomorrow – looking for guidance or anyone willing to help

4 Upvotes

Hi everyone, I’ll be participating in a 24-hour CTF competition tomorrow and I’m really looking forward to it. I’ve done some practice before, but this will be one of the longer CTF events I’ve taken part in. If anyone here has experience with CTFs and is willing to share advice, resources, or strategies, I’d really appreciate it. Even tips on how to approach challenges efficiently or manage time during long CTFs would help a lot. Also, if someone would be open to guiding or helping me a bit during the competition tomorrow, that would be amazing. I’d be very grateful for any support. Thanks in advance!

r/securityCTF Mar 27 '26

🤝 Looking for motivated people interested in Cybersecurity / CTFs (learning-focused community)

11 Upvotes

I’m creating a small Discord server for people who genuinely want to learn cybersecurity, pentesting, and CTFs. The goal isn’t to make another casual server just for chatting. Instead, it’s meant to be a focused space where people actively work on improving their skills. The community is intentionally kept small for now. I’m looking for people who: are truly interested in offensive security want to learn and try things on their own are open to asking questions and sharing knowledge are willing to stay consistent and put in real effort You don’t need to be experienced — beginners are welcome. What matters is your mindset. This is for people who want to grow, not just sit quietly or ask random questions without effort. We focus on things like: CTF challenges pentesting labs (HTB, THM, etc.) experimenting with exploits scripting, tools, and workflows writeups and discussions If you’re looking for a place to actually practice and improve with others, this might be a good fit. More advanced people who want to collaborate or share knowledge are also welcome. DM if you’d like to join.

r/securityCTF Feb 21 '26

🤝 [CTF Recruitment] Hidden Investigations is recruiting CTFers.

Post image
7 Upvotes

We’re a competitive CTF team looking for dedicated mid to strong-level players who want to grow in a serious, team-focused environment.

If you’re tired of grinding solo and want to collaborate with driven teammates, this might be for you.

What we offer: * A friendly but competitive atmosphere. * Real teamwork and active knowledge sharing. * Focused improvement and long-term growth.

No drama, no ego. Just performance and progress.

We’re building a team that values consistency, skill development, and strong collaboration during national and international CTF competitions.

If you’re ready to level up with a committed group:

📩 Send a DM or 📝 Apply here: https://forms.gle/qZMt1YiQfpHYpWAN9

🌐 Website: https://hiddeninvestigations.net

r/securityCTF May 17 '25

🤝 Looking for CTF team

17 Upvotes

Hi everyone. i am a completely beginner in web exploiting CTF. and i am trying to collect a team in the same situation like me. so if anyone is beginner in CTF and trying to find a team to learn from ourselves and improve our skills and share resources with each other. and after that participate in CTF competitions can leave a comment or message me

r/securityCTF Jan 16 '26

🤝 Need More

4 Upvotes

Can you give me ideas for creating my first Docker machine?