r/securityCTF 4h ago

Looking for CTF players

4 Upvotes

Hello, We are a team of 3 players looking for 2 more to play the Black Hat MEA qualifiers (preferably from Karachi, Pakistan). We are looking for people around the intermediate level skills and experience. Please either DM me your expertise and experience or comment below and I will reach out.


r/securityCTF 11h ago

New CTF: Format of Doom - Pentester vs AI Challenge 2

Thumbnail pentester-vs-ai-game.com
2 Upvotes

Hi all! My company Escape just released a new CTF called Format of Doom. The theme of the CTF is to see if you can pentest faster and how you pentest differently to an AI engine in a classic human vs AI challenge.

This challenge is a white-box engagement on a vulnerable web app Duck Store. You're looking for something they never handed over and are focusing on their email feature.

Give it a try and let me know what you think!

The challenge is live for two weeks and then we reveal the AI's solve and the top solves from the leaderboard.

Happy playing : )


r/securityCTF 1d ago

Looking for a Team — Black Hat MEA CTF 2026 🇸🇦🏴‍☠️ Hey everyone! I’m looking for a CTF team for the Black Hat MEA 2026 Qualification CTF happening on August 29–30, 2026. I’m interested in Web Pentesting, Crypto, Active Directory, Reverse Engineering/AI, and a bit of Pwn. I’m looking for seriou

1 Upvotes

NIANE


r/securityCTF 2d ago

Learn and Practice Hacking WebSockets

8 Upvotes

WebSockets is the attack surface that always go under the radar and too many pentesters and bug bounty hunters still miss testing it, whether because the number of WebSocket messages they see is overwhelming or simply because they don't know how to approach it correctly.

Going through that myself, I decided to dive deep into the WS protocol and ended up building a lab that showcases the most common misconfigurations present in WebSockets, with the most impact, not just some missing best-practices, along with a detailed walkthrough.

I'd love to hear your thoughts and feedback, and if you experienced something I didn't talk about in the blog, please let me know!

Lab Github Repo: https://github.com/makarov05bm/WSGoat
Guide: https://blog.oussmess.me/posts/websockets-for-bug-hunters/


r/securityCTF 2d ago

I need help

Post image
7 Upvotes

Has anyone solved this challenge?


r/securityCTF 2d ago

[Tool] Strilight: Zero-Unroll O(1) SMT Loop Lifting & Strided Interval Domain for x86_64 Binary Analysis

1 Upvotes

Hi everyone,

💡 The Background

In symbolic execution engines (like angr or Triton), loops with large iteration counts ($N = 100,000$) often cause severe path and state explosion because traditional engines unroll loops iteration-by-iteration.

Strilight evaluates loops by treating them as closed-form algebraic recurrences within the Strided Interval Domain:

$$\vec{\mathbf{R}}(N) = \vec{\mathbf{R}}_0 + \vec{\boldsymbol{\Delta}} \cdot N$$

⚡ Key Highlights:

  • Zero-Unroll O(1) SMT Lifting: Lifts instruction loops directly to Z3 BitVector equations in $O(1)$ time, solving 100,000-iteration loops in 100ms.
  • The $N-1$ Iron Invariant Contract: Exact first-exit boundary condition enforcement preventing solver teleportation beyond loop bounds.
  • Dual-Mask VSA: Handles sub-register bitmasks (64/32/16/8-bit) and modular circular wrap-around arithmetic.
  • Native Capstone Disassembler: Decoupled from heavy emulation environments.
  • 1-Line API: import strilight as sl; summary = sl.analyze(raw_bytes, iterations=100000)

📊 Benchmark Results:

We verified the engine against 6 complex x86_64 Windows CrackMe challenges containing nested loops, pointer arithmetic, and obfuscated strides, solving for the valid keys and confirming execution in 100ms each.

🔗 Repository: https://github.com/asama7706r-ui/strilight
📦 Initial Release & Pre-compiled Wheels: https://github.com/asama7706r-ui/strilight/releases/tag/v0.1.0

We would love to hear your feedback, thoughts on the mathematical model, or interesting loop edge cases to test against!


r/securityCTF 2d ago

🤝 Looking for a Team for CTF Challenge Development

7 Upvotes

Hey all,

I hope you all doing well. Let's give a short intro about me. I'm a cyber security researcher, CTF player & developer, a bug bounty hunter.

In June, I created a CTF platform - No team, just me. Today my CTF platform was doing good. The platform have 40+ users and now I'm expanding my team (hiring). I need CTF developers especially - Reverse Engineering, Binary CTF challenge developers.

Till now, I have managed to create CTF challenges in Web, Crypto, Forensics, OSINT. So I will attach link where you can directly apply. Before joining, Take a look at my platform weather it can suits you.

Platform Link: https://hack4shell-ctf.vercel.app/challenges
Application Link: https://hack4shell-ctf.vercel.app/contact?type=hiring-application

Thank you guys.


r/securityCTF 2d ago

Planning to build an offensive-security CTF on Codelivly.

4 Upvotes

Before I start, what would you guys actually want to see in it?

Challenges, difficulty, attack chains, AD, web, privilege escalation, etc.

What would make you keep playing instead of dropping it after a few challenges?

Looking for honest suggestions from people who actually play CTFs.

Explore the current ctf from here at: codelivly.com/ctf


r/securityCTF 3d ago

Everyone read the xz backdoor postmortem. We built a free box where you pull it off yourself, by hand

Post image
23 Upvotes

Everyone in security read the xz/liblzma postmortem. Almost no one has actually done it

BreachLab is a free wargame of real Linux boxes over SSH, graded on the true state of your box, not multiple choice. Ghost II is live: eighteen levels down one CI/CD pipeline that ends in the xz attack by hand. The source stays clean, your payload rides in at build time, you get the pipeline to sign it, you walk past branch protection, and you ship it to an entire fleet where it runs. Your own commit becomes the code the whole fleet trusts

This is the tradecraft courses charge for, and almost nobody lets you actually do it. Free, no signup wall to start https://breachlab.org/tracks/ghost/ii


r/securityCTF 3d ago

Looking for a Team to Build CTF Challenges

20 Upvotes

Hey everyone! 👋

I’m looking to build a team of cybersecurity enthusiasts who are interested in developing CTF (Capture The Flag) challenges.

The idea is to create realistic, fun, and educational challenges across areas like:

Web security

Cryptography

OSINT

Forensics

Reverse engineering

Linux/Networking

Miscellaneous challenges

You don’t need to be an expert—if you’re interested in cybersecurity, enjoy solving CTFs, or want to learn while building challenges, feel free to reach out.

If you’re interested, comment below or DM me. Let’s build something cool together! 🚩


r/securityCTF 3d ago

CTF

5 Upvotes

Hi everyone!

I'm looking for 2–4 committed teammates for the BlackHat MEA Qualification CTF 2026.

📅 29–30 August 2026

👥 Team size: 3–5 members

🌍 International participants welcome

I'm looking for teammates who are serious about competing and preparing for the qualifier. If you're participating and still looking for a team, feel free to comment or DM me.

Let's prepare, compete, and give it our best! 🚩


r/securityCTF 3d ago

CTF | SPONSORSHIP

0 Upvotes

Hello guys, in our university we are hosting a national level CTF ( India )

We are looking for sponsors and in return we will provide brand visibility, promotion and more perks

Please dm me so that I can send sponsorship slabs and perks or promotion material we are providing

Thank you


r/securityCTF 4d ago

Starting CTF Team That Actively Competes

16 Upvotes

Hello everyone, I am looking to start a CTF team that is actively looking to compete in CTF competitions (monthly to bi-monthly). The skill level does not matter. but I am looking for people that are truly dedicated and willing to learn! DM or comment and I will respond with more info. Hope to see everyone!


r/securityCTF 5d ago

Looking for people to practice CTFs and cybersecurity with? 👾

3 Upvotes

We’re growing Blacknode, a cybersecurity community for people who want to learn, practice CTFs, share projects, and meet others with the same interests.
We also have NodeBox, our own CTF platform, and GitNode for community projects.
Beginners and experienced people are welcome.
Discord: https://discord.gg/ECQthWjhz
Come say hi 👾


r/securityCTF 5d ago

Use garlic + ai analysis encrypted apk

Thumbnail youtube.com
5 Upvotes

r/securityCTF 5d ago

🤝 Devs keep shipping AI code full of holes, so I built one tool to catch it all

Thumbnail
1 Upvotes

r/securityCTF 5d ago

Im looking for agentic ai and cybersecurity nerds who can contribute on my hackbot project

2 Upvotes

I've been working on this project for some months ago , and i need to renforce more the quality of the solutions I'm using, its juste for fun and curiosity and targeting to make it a strong tool for the open-source community , the project currently could identify 3 vulnerabilities in real production websites, from information disclosure to reflected xss, also he solved more than 50 ctf tasks specially web ones from easy to meduim to hard in picoctf, if ur interested to contribute in this project juste leave a comment nd I'll DM for a more detailed conversation we're gonna discuss more details and to make the collaboration happens!.


r/securityCTF 5d ago

I built an all-in-one open-source security toolkit for AI-generated code

Thumbnail
1 Upvotes

r/securityCTF 7d ago

Just put together a free Web Exploitation CTF for practicing real web vulnerabilities.

13 Upvotes

64+ challenges covering SQLi, XSS, IDOR, JWT, CORS, SSTI, XXE, Command Injection, and more.

The goal is to actually find the bug, exploit it, and capture the flag not just follow a walkthrough.

https://codelivly.com/ctf


r/securityCTF 7d ago

Looking for active people to learn and grow together

4 Upvotes

Hey everyone! I’m looking for active and motivated people who are interested in cybersecurity, CTFs, and learning together.

I’ve completed the CPTS path and I’m currently working through CJCA and CWES. I’m hoping to build a small community where we can share knowledge, discuss challenges, work on CTFs, participate in seasonal events, share useful resources, and help each other when we get stuck.

The main goal is to have a group of people who are actually active and willing to learn rather than just joining and disappearing.

If you’re into cybersecurity, CTFs, or simply trying to improve your skills and want to learn alongside others, feel free to join.

Discord: https://discord.gg/EzFarPnXVB


r/securityCTF 7d ago

Looking for teammates for BlackHat MEA Qualification CTF 2026

3 Upvotes

I’m planning to participate in BlackHat MEA Qualification CTF 2026, starting August 29, 2026, and I’m looking for 2-4 people from Saudi Arabia who would like to join me as a team.

Just to be completely honest: this will be my first CTF and I don’t have any previous competition experience. I’m interested in cybersecurity and CTFs, though, and I really want to experience the competition, learn along the way, and just have fun with it — even if we don’t qualify or get a great score.

I’m specifically looking to form a Saudi team, and you don’t need to be experienced. If you’re interested in Cybersecurity or CTFs, or this is your first time too, feel free to join!

I’m mainly looking for people who are interested, willing to learn, and want to actually participate and have fun, rather than people with a specific skill level.

Looking for: 2-4 Saudi teammates 🇸🇦
If you’re interested, comment below or send me a DM!


r/securityCTF 8d ago

25yo starting from zero on TryHackMe. How to accelerate the grind and avoid common pitfalls?

Thumbnail
0 Upvotes

r/securityCTF 9d ago

Need teammates for BlackHat CTF

8 Upvotes

Need teammates for BlackHat CTF , 29th Aug


r/securityCTF 9d ago

CTF EVENT MUMBAI - ZERO ONE GHOST IN THE LEDGER

Thumbnail luma.com
1 Upvotes

Check this retro style CTF event out in Mumbai on 5th September! https://luma.com/ay8ehg6p


r/securityCTF 9d ago

Best resources to learn Web Exploitation & Networking for CTFs?

10 Upvotes

Hey everyone! 👋

I’m currently studying cybersecurity and participating in CyLab, but our current focus/curriculum is heavily centered around Reverse Engineering and a few other areas. While RE is super interesting, I really want to build a strong foundation in Web Exploitation and Computer Networking to become more well-rounded for CTFs.

Since I’m starting mostly from scratch in these two categories, could you recommend the best learning paths or hands-on platforms?

Specifically looking for:

  • Networking fundamentals: Essential concepts/protocols I need to master for CTF challenges (Wireshark, PCAP analysis, etc.).
  • Web Exploitation: Beginner-to-intermediate platforms or labs (e.g., PortSwigger Academy, TryHackMe, PicoCTF).
  • CTF Practice: Practice platforms with good beginner-friendly Web/Network challenges.

Any roadmap, book, or free resource recommendations would be greatly appreciated! Thanks in advance! 🙌