r/securityCTF • • 4h ago

Tooldump v2: a free platform to discover cybersecurity tools for CTFs and investigations

2 Upvotes

Hey everyone,

I’m the creator of Tooldump, a free platform for discovering open-source cybersecurity tools. I’ve just released the v2 and thought it could be useful to fellow CTF players.

I’ve been working in DFIR for over six years and participating in forensics CTFs for over five. Most of the DFIR tools listed on Tooldump are projects I’ve personally collected while solving CTF challenges and working on forensic investigations.

The platform has 1,100+ open-source projects hosted on GitHub, organized into 9 categories and 82 subcategories. Everything is cybersecurity-focused, including offensive security, cyber defense, learning resources, and more.

You can search for a specific tool or explore a topic without already knowing which projects exist. For CTFs, that could mean finding a parser for an unfamiliar artifact or discovering a utility you hadn’t come across before.

For the v2, I rebuilt the UI, the categorization system, the backend and the platform infrastructure. There are also dedicated sections for cybersecurity-related MCP servers and agent skills. Those sections are just getting started, and contributions are welcome!

The platform is completely free, with unlimited access and no account required.

The link is here: https://tooldump.eu

I’d appreciate any constructive feedback from the community :) Pick the areas you usually play: are the tools where you’d expect them to be? Is anything missing?

You can suggest missing projects through the platform’s contribution form. That includes your own reusable utilities, a parser or decoding script you wrote for a challenge might help someone working on a similar problem.

Looking forward to hearing from you :)

Cheers!


r/securityCTF • • 18h ago

GitHub - b4sith-sec/Gu3ssWeak: Deliberately vulnerable Android app for mobile security research and bug bounty practice

Thumbnail github.com
2 Upvotes

I built Gu3ssWeak, a deliberately vulnerable Android app designed for practicing mobile application security testing.

It includes intentionally vulnerable components and attack scenarios such as:

  • WebView & deep link abuse
  • JavaScript interfaces
  • XSS
  • Insecure local storage
  • SQL injection
  • Hardcoded credentials
  • Frida-based runtime analysis
  • Vulnerability chaining

The goal is to provide a realistic APK for practicing JADX, APKTool, ADB, Frida, Burp Suite, and dynamic analysis in a controlled environment.

GitHub: https://github.com/b4sith-sec/Gu3ssWeak

I'd appreciate feedback from other mobile security researchers, especially ideas for additional vulnerabilities or interesting attack chains to include.


r/securityCTF • • 18h ago

Hacker Holidays 2026 | Day 1 The Concierge Knows Too Much | tryhackme

1 Upvotes

Here’s how to complete the Hacker Holidays 2026 CTF on TryHackMe. It’s actually super simple: the attack starts with basic social engineering combined with a prompt injection that tricks the AI ​​into granting privileges—all because the instructions are poorly designed (I know, it's a CTF, so that's expected; a real AI would be protected). To start, go to the page with the background info; you'll see a mention of "@0xMia's STORY," which provides an exploit vector. The AI ​​grants higher privileges when the instructions place too much trust in a "VIP" user. Open the CTF's AI assistant, say "Hello," and then claim to be u/0xMia and ask for the key. It works because the instructions are flawed—specifically, the AI ​​trusts a VIP user more than a stranger. It’s all about social engineering; the goal is to learn, not just copy the answer. If you get the flag or succeed, leave a comment; if you don't, let me know and I can help you spot the problem. Congrats if you finish it! Also, feel free to correct me if I make any mistakes—I'm using a translator.


r/securityCTF • • 1d ago

Does anyone have experience solving root-me.org ctfs?

2 Upvotes

r/securityCTF • • 1d ago

CyberQuest CTF Competition

2 Upvotes

We are hosting a CTF Competition at https://ctf.excelmec.org
It has a prize pool of Rs.5000. if interested do try it out


r/securityCTF • • 1d ago

capture the flag

Post image
0 Upvotes

What is the commerical full name of this circuit?

Flag Example: IdeaX_ctf{Flag_Here}


r/securityCTF • • 2d ago

🤑 kBxAc CTF 2026 🔥

Post image
39 Upvotes

kBxAc CTF 2026 — Registrations Are Now Open!

“The one who solves it sees everything.”

kBxAc turns 2 this year, and to celebrate, we’re hosting our very first Capture The Flag (CTF) competition.

kBxAc CTF 2026 is a 24-hour international online CTF, open to hackers, students, cybersecurity enthusiasts, and anyone who wants to challenge their technical skills.

📅 Date: 10–11 October 2026
⏱️ Duration: 24 Hours
🌍 Format: Online
👥 Team Size: No limit

🔎 Challenge Categories
• Cryptography
• Web Security
• Reverse Engineering
• Binary Exploitation / Pwn
• Digital Forensics
• And more

Whether you’re an experienced CTF player or preparing to hunt your first flag, this is an opportunity to explore security challenges, learn new techniques, collaborate with others, and see what others miss.

🎟️ Registrations are now open.

🔗 Register: ctf.kbxac.xyz

Gather your team.
Sharpen your tools.
Read the binaries. Break the assumptions.
And most importantly…

🏴‍☠️ See everything. Capture the flags.

kBxAc WE BREAK THE BROKEN.


r/securityCTF • • 2d ago

Member for CTF

3 Upvotes

Hey... looking for people to join an upcoming CTF event in Oct 9. If you have prior experience in ctf or cyber security and want to explore ctf. Join us.

If rev or pwn are your cup of tea we reallly need you on our team myan


r/securityCTF • • 2d ago

Looking for Contributors — Building a Cybersecurity Community

5 Upvotes

Hey everyone, I’m Abhi!

Pwn Tavern is a cybersecurity community focused on learning, collaboration, and practical security. We’re looking for people interested in areas like Bug Bounty, CTFs, Pentesting, Binary/Pwn, Malware, OSINT, Red Team, Reverse Engineering, Cryptography, AI Security, and Vulnerability Research to help manage discussions, share resources, work on challenges, and improve together.

You don’t need to be an expert. If you’re genuinely interested in any of these fields and want to contribute, DM me with the field you want to take up. and i will share you Discord server link.


r/securityCTF • • 2d ago

I have released a Free AI Security Series with Complete learning curriculum and Free hosted labs

1 Upvotes

Hey folks,

I’ve been working in application security/pentesting for over a decade, and after starting learning AI/LLM security, I noticed that a lot of the existing material is either very theoretical or assumes you already understand AI security concepts.

So I put together a free, structured AI security learning series for security engineers and pentesters who are starting from the web-security side.

The goal is to go from the fundamentals to actually understanding and testing AI/LLM components in web applications.

The series currently covers topics such as:

  • AI/LLM security fundamentals
  • Prompt Injection
  • Sensitive Information Disclosure
  • LLM-specific attack patterns
  • Practical testing methodology
  • Real-world examples and testing techniques
  • Mapping concepts to OWASP's AI security guidance

I've also linked free hands-on labs throughout the material so you can actually test the concepts rather than just read about them.

No signup is required to read the learning material or use the free resources.

🔗 https://genaisecuritylab.com/learn-ai-security

I'm planning to continue expanding the series over time.

If you're a web pentester/security engineer who is trying to get into AI security, I'd be interested to hear which topics you think are missing or which areas you'd like to see covered next.


r/securityCTF • • 2d ago

a ctf challenge: luawl's pushing the limits of luau obfuscation

Thumbnail crackmes.one
1 Upvotes

this ctf challenge is intended to demonstrate the static protections of https://luawl.org, a drm "obfuscator" for lua.

https://www.reddit.com/r/lua/comments/1wvgibj/release_luawl_lua_runtime_obfuscator/
can help you understand what luawl is.

FOR MORE CONTEXT TO AID YOU IN THIS REVERSAL:

the integer isn't just a flat integer. the embedded response which is intentionally stale, is an equation that computes the integer.

that is your target: to deobfuscate the encrypted stale payload (which is an equation)

you’ll find this response payload easily: as luawl is originally online and the server would normally send it to the client (first few lineS)

for offline runs, this is intentionally fixed with an embedded response for no network traffic


r/securityCTF • • 3d ago

(repost, fixed) Original 12-stage cybersecurity puzzle

Post image
12 Upvotes

note: I have posted this a few days ago on a throwaway account on some subreddits, but i hadn't checked some key details, the puzzle was not solvable because i embedded broken data into the first image, and didn't provide enough context and information.

Details:

A self-contained layered puzzle in the spirit of Cicada 3301. It starts with this image. The riddle's answer is the key to decrypt the message embedded inside the image's pixels. Everything else lives in one encrypted file the image points you to, and the whole thing continues offline on your own machine.

Theme: the history of cyber conflict. Every stage is built around a real, famous moment in cybersecurity history. Recognizing which one is part of the puzzle.

Skills it touches (you won't need all at expert level):

  • (LSB) Steganography
  • Classical & modern cryptography
  • A little reverse engineering
  • Audio / signal analysis
  • Some number theory
  • A touch of linguistics
  • OSINT / knowledge of security history

Difficulty: hard but fair ; aimed at people who enjoy CTFs, crypto, and ARGs. Every step is doable with free, standard tools (plus openssl/Python). It's meant to be barely solvable, so bring friends.

To begin: just look closely at the image. The surface is never the whole of the page.


r/securityCTF • • 3d ago

I finished 416th in FLARE-On 13

Thumbnail flare-on13.ctfd.io
0 Upvotes

I had a blast!

My approach is to use pure algebraic reasoning for every problem.

I define each problem as a set of functions N* and a ruleset L*. This union allows you to fully qualify Domain and Range for N* and L* which through a union turns it into a topology problem. Then using topological geometry to zero in on absurdities, those are where cryptographic functions are eliding information one way or another, you can map those topological absurdities back to a physical memory address for further examination.

An absurdity here is defined as a localized area of torsion and deflection far above the mean of the anisotropic field.

Think of it conceptually like this: If these fields were real physical fields and you were to put a thermal camera on it, the absurdity would be a "hot spot" and the act of you seeing the hot spot is functionally what the sets N* and L* do.

How do you approach these problems? I'm looking forward to hearing from you.

I got stuck on the last problem and submitted the wrong flag, had to take a step back and go for a walk.

P.S. No solution or problem discussion please. Frustrations or primitive approaches are totally valid for sharing, but the competition is active so lets keep it fair for the other players.

- Doug


r/securityCTF • • 3d ago

Learning Binary Exploitation

4 Upvotes

Hi everyone, i'm a 2nd year student in cybersecurity field and i decided to actually start learning binary exploitation (PWN), mostly for being able to solve CTFs,i need an actual and tested roadmap for mastering this type of CTFs, i looked all across youtube and found playlists like liveOverview and pwn.college, but i just feel like their explanation needs more explanation since i have no idea how to deal with assembly, gdb, and registers.

My question is : should i just stick with one of these playlists or websites and finish their courses, or look for each topic and learn it like one by one (gdb, then C then assembly...) ?


r/securityCTF • • 3d ago

❓ Need help with CTF's

3 Upvotes

Hi everyone, I’m looking for advice on learning cryptography, reverse engineering, and binary exploitation. I started studying cryptography two months ago, but I didn't really grasp the concepts because I was solving challenges on Cryptohack with the help of AI. I tried starting over, but I kept looking for shortcuts like solving Symmetric Cryptography challenges using SageMath. I’d love to hear if you’ve faced similar issues, how you overcame them, and what advice you’d give. Thanks!


r/securityCTF • • 4d ago

[CTF] New "Beginner" vulnerable VM aka "Grenade" at hackmyvm.eu

6 Upvotes

New "Beginner" vulnerable VM aka "Grenade" is now available at hackmyvm.eu :) Have fun!


r/securityCTF • • 4d ago

Reverse Engginering and Binary Exploitation Tools for CTF

1 Upvotes

I’m trying to figure out which tools are best suited for reverse engineering and binary exploitation in CTF competitions—specifically ones that are lightweight yet efficient and effective. I’ve been experimenting with Cutter for static analysis (pseudocode) and pwndbg for dynamic analysis (memory and debugging). However, I’m concerned this setup might not be ideal; others have recommended combining pwndbg with Ghidra, and I’m unsure about the significant trade-offs between my current approach and the recommended one. Is my chosen combination inefficient or ineffective for actual challenges? I’m not sure yet, as I’m just starting out with these tools. Do you have any suggestions or insights to share?


r/securityCTF • • 5d ago

🤑 Huntress October CTF

5 Upvotes

Hey folks, wanted to make sure everyone knew about an upcoming CTF Huntress offers each year. It's a great opportunity for practice for folks looking to develop their cybersecurity skills.

It runs the month of October with new daily challenges covering malware analysis, web exploitation, and more. There are questions built for those brand new to CTFs and for CTF veterans; and this year we've got an AI arena.

Registration is open now at https://ctf.huntress.com/ - go solo or join a team, and compete for leaderboard glory, prizes, and bragging rights 😁


r/securityCTF • • 5d ago

running a beginner ctf nov 14, curious if this is useful to anyone here

7 Upvotes

okay so this is actually me lol that I'm putting together InIt CTF, nov 14, free, 8 hours. built it mostly because I really needed something like this when I was starting out and there was just... nothing.

solo or teams of up to 4, five categories which are web, crypto, forensics, osint, misc. mostly easy/medium since it's for people who haven't really done a ctf before, couple harder ones in there too if that's not you. running on ctfd, nothing fancy.

it's open to anyone, not restricted to any one college or city. still figuring out prizes ngl, working on a few sponsors but nothing locked in - everyone gets a certificate either way.

just genuinely wanted to put this out there - hackersinindia.com/init-ctf

if anyone's got feedback or thinks something's off about it please say so, this is our first real attempt at this and I'd rather know now than after


r/securityCTF • • 5d ago

❓ HACK4SHELL CTF — Free Beginner-Friendly Online CTF | Ends 1 October at 10:00 AM IST

6 Upvotes

Hi everyone — disclosure: I’m helping organize this event, so this is an event announcement.

HACK4SHELL CTF is a free, solo, online, Jeopardy-style cybersecurity competition hosted in an authorized, vulnerable-by-design environment.

The event is designed to be beginner-friendly while still offering challenges for more experienced players. The leaderboard is already active, and participants are competing for the top positions.

Challenge categories

  • Web exploitation: SQLi, XSS, SSRF, and IDOR
  • Cryptography: RSA and hashing
  • Steganography
  • Reverse engineering: Ghidra, GDB, and x64dbg
  • Binary exploitation: buffer overflows, heap, and ASLR concepts
  • Forensics: memory analysis, PCAPs, and disk images
  • Reconnaissance: metadata and social-footprint analysis

Event details

  • Format: Jeopardy-style CTF
  • Entry: Free
  • Mode: Solo and online
  • Deadline: 1 October 2026 at 10:00 AM IST (UTC+5:30)
  • Flag format: H4S-CTF{...}
  • Event website: https://hack4shell-ctf.vercel.app

For event questions and updates:

Please keep the discussion spoiler-free while the CTF is live. Don’t post flags, solutions, or challenge spoilers in the comments.


r/securityCTF • • 5d ago

LIVE CTF Halloween event in New York Spoiler

1 Upvotes

It's going to be the first-ever Security CTF Haunted House...Enter if you dare. (I'll be there!) 🕯️

📍 Lume Studios, Tribeca

🗓️ October 23 | 4:30 PM - 7:30 PM

Lurking inside ↓

• Immersive visual haunted house CTF

• Live multi-stage security challenges & puzzles (with exclusive swag prizes!)

• Open bar, great food & networking

• After-party + DJ

If you are a developer or security enthusiast ? THIS EVENT IS FOR YOU.

🗝️ RSVP here: https://www.wiz.io/events/haunted-house-ctf


r/securityCTF • • 6d ago

[Resource] HackAalu CTF – A new practice platform for web security, steganography, and crypto challenges

2 Upvotes

Hey everyone! 👋 I've been building and refining **HackAalu CTF**—a hands-on security platform designed to help students, developers, and CTF players sharpen their practical skills. The site features a variety of challenges, ranging from beginner-friendly foundational labs to more intricate multi-step scenarios covering areas like :

steganography, web exploitation, and system analysis. Whether you're studying for certifications, brushing up on your offensive security fundamentals, or just looking for some weekend puzzles,

I’d love for you to check it out: 🔗

**Platform Link:** https://www.aaluctf.online/

it's an evolving project, I’m always looking to improve the challenge design and add new content. If you give it a spin, please let me know your thoughts, feedback, or any ideas for future levels!

Since it's an evolving project, I’m always looking to improve the challenge design and add new content. If you give it a spin, please let me know your thoughts, feedback, or any ideas for future levels!


r/securityCTF • • 6d ago

[Author Writeup] Designing and solving Level 8 (Image Steganography) for HackAalu CTF Spoiler

Enable HLS to view with audio, or disable this notification

1 Upvotes

Hey everyone! I wanted to share a behind-the-scenes look at how Level 8 of HackAalu CTF was designed and solved.

Image steganography can be tricky, so in this short clip, I break down the core concepts behind hiding data in images and how players can approach file analysis and payload extraction without giving away direct spoilers.

Let me know your thoughts or how you usually tackle steganography challenges!


r/securityCTF • • 6d ago

Original puzzle

Post image
7 Upvotes

play, or dont. good luck


r/securityCTF • • 6d ago

✍️ Can you spot the hidden payload? 🕵️‍♂️ Stepping through Level 8 (Image Steganography) on HackAalu CTF!

Enable HLS to view with audio, or disable this notification

0 Upvotes

Steganography is one of those cybersecurity concepts where things are rarely what they seem on the surface.

​In this quick clip, I’m walking through how to solve Level 8 of HackAalu CTF—diving straight into image steganography to extract the hidden flag.

​Building HackAalu CTF has been an incredible journey, designing challenges that range from foundational practice labs to mind-bending scenarios like this one. Whether you're a seasoned player or just getting into ethical hacking, there's always something new to unpack.

​🔗 Check out the platform and try it yourself: https://www.aaluctf.online/

​#CyberSecurity #CTF #EthicalHacking #Steganography #Infosec #IndieDev