Cybersecurity CTF Challenges

⚠️ Access denied: login required to view private community content.

About the challenges:

Challenges are mixed:
These challenges span multiple categories: PHP-related vulnerabilities (LFI, RFI, SQL Injection), Web security (XSS, Cookie poisoning, SSTI), Cryptography (Caesar cipher, Base64, AES), Forensics (memory dump, stego), and Password cracking.

Primarily web security-focused, with a strong PHP backend flavor:
Many challenges target common PHP weaknesses, but also include client-side JavaScript vulnerabilities and cryptographic concepts.

Target audience / community:
These challenges are ideal for web security enthusiasts, penetration testers, CTF players, and developers learning about common vulnerabilities — especially those focused on PHP and full-stack web security.

Suitable for:

  • Beginners through advanced learners (since difficulty ranges from easy to hard)
  • Capture The Flag (CTF) competitions
  • Cybersecurity training platforms focused on real-world web app flaws

Password Cracking

0 / 3 0 pts

Basic Hash Cracking

Easy 50 pts

Salted Hash Cracking

Medium 100 pts

Advanced NTLM Cracking

Hard 200 pts

SQL Injection

0 / 3 0 pts

Basic SQL Injection

Easy 50 pts

Union Injection

Medium 100 pts

Blind SQL Injection

Hard 200 pts

LFI/RFI

0 / 3 0 pts

Remote File Inclusion

Easy 50 pts

Simple LFI

Medium 100 pts

Log Poisoning

Hard 200 pts

XSS

0 / 3 0 pts

Reflected XSS

Easy 50 pts

DOM XSS

Medium 100 pts

Stored XSS

Hard 200 pts

Cryptography

0 / 3 0 pts

Caesar Cipher

Easy 50 pts

Layered Base64

Medium 100 pts

AES Encrypted File

Hard 200 pts

Web Exploitation

0 / 3 0 pts

Header Leak

Easy 50 pts

Cookie Poison

Medium 100 pts

RenderTrap

Hard 200 pts

Forensics

0 / 3 0 pts

EXIF Metadata

Easy 50 pts

Stego Image

Medium 100 pts

Memory Dump Analysis

Hard 200 pts