🏁 CTF

Complete CTF Guide

Capture The Flag — The ultimate guide to mastering cybersecurity competitions.

1. Introduction to CTFs

Capture The Flag (CTF) competitions are cybersecurity challenges where participants solve puzzles to find hidden "flags" (secret strings). CTFs help develop real-world hacking skills in a legal environment.

Types of CTFs


2. CTF Categories & Tools

A. Web Exploitation

Common Vulnerabilities: SQLi, XSS, CSRF, SSRF, JWT attacks

Tools: Burp Suite, OWASP ZAP, SQLmap

Example Challenge:

🌐 Web SQL Injection
http://ctf.site/login.php?id=1'
Find the flag by exploiting SQL injection.

B. Reverse Engineering

Techniques: Static analysis (Ghidra, IDA Pro), Dynamic analysis (x64dbg, GDB)

Example Challenge:

🔧 Reverse crackme.c
// crackme.c
if (input == 0xDEADBEEF) print_flag();

C. Binary Exploitation

Common Attacks: Buffer overflows, ROP, Format strings

Tools: Pwntools, GDB with Peda

Example Challenge:

💥 Binary Pwntools
from pwn import *
p = process('./vuln')
p.sendline(cyclic(100))

D. Cryptography

Common Challenges: RSA, AES, XOR, Frequency analysis

Tools: CyberChef, RsaCtfTool

Example Challenge:

🔐 Crypto Decryption
Ciphertext: U2FsdGVkX19zZWFzb24=
Password: "password"

E. Forensics

Common Tasks: Memory dump analysis (Volatility), Packet analysis (Wireshark), File carving (binwalk)

Example Challenge: Analyze memory.dmp to find the hacker's IP.

F. Miscellaneous

OSINT, Steganography, Programming


3. CTF Strategies

A. General Approach

  1. Recon — Examine all provided files
  2. Research — Google keywords, similar CTFs
  3. Exploit — Use appropriate tools
  4. Submit — Flag format: FLAG{...}

B. Time Management


4. Hands-On Labs Setup

A. Local Practice Environments

  1. VulnHub — Download vulnerable VMs (Metasploitable, Kioptrix)
  2. HTB (Hack The Box) — Online machines
💻 Terminal HTB Connection
# Connect via OpenVPN
openvpn lab_user.ovpn
  1. TryHackMe — Guided learning paths

B. Essential Tools Setup

💻 Terminal Install CTF Tools
# Install CTF tools on Kali
sudo apt install -y gdb peda pwntools steghide binwalk volatility

5. Step-by-Step CTF Walkthrough

Challenge: Web Login Bypass

Given:

🌐 Target Web Login
http://ctf.site/login
Source: <!-- /source.php -->

Steps:

  1. View source → Find /source.php
  2. Analyze code:
📄 Source source.php
if ($_POST['password'] == md5('secret')) $flag = "FLAG{...}";
  1. Generate MD5 hash:
💻 Terminal MD5 Hash
echo -n 'secret' | md5sum
  1. Submit password hash → Get flag!

6. CTF Platforms

Platform Type Difficulty
Hack The Box Live machines Medium-Hard
TryHackMe Guided labs Beginner
CTFtime Competition hub All levels
picoCTF Jeopardy Beginner
OverTheWire War games Progressive

7. Advanced Techniques

A. Automating with Python

🐍 Python Automation
import requests

for i in range(100):
    r = requests.get(f'http://ctf.site?id={i}')
    if "FLAG{" in r.text:
        print(r.text)

B. Binary Patch Exploits

💻 Terminal Binary Patch
# Change JZ to JNZ in binary
printf '\x75' | dd of=./binary bs=1 seek=$((0x1234)) conv=notrunc

C. Memory Corruption

🐍 Python ROP Chain
# ROP chain example
rop = ROP('./binary')
rop.call('system', ['/bin/sh'])

8. CTF Team Tips


9. Post-CTF Learning

  1. Read writeups for unsolved challenges
  2. Recreate challenges for deeper understanding
  3. Build your own CTFs (CTFd framework)

10. Free Practice Resources

  1. picoCTF — Beginner-friendly
  2. OverTheWire Bandit — Linux skills
  3. Cryptopals — Crypto challenges
  4. MalwareTech Challenges — Beginner RE

Conclusion

🔹 Next Steps

  1. Create free account on HTB/TryHackMe
  2. Join CTFtime.org for upcoming events
  3. Solve picoCTF 2024 challenges

🚀 Want a curated list of beginner CTFs? Here's my recommended starting path:

  1. OverTheWire Bandit (Linux)
  2. picoCTF (General)
  3. HTB Starting Point
  4. NahamCon CTF

😊 Would you like personalized challenge recommendations based on your skill level?