Internet Explorer is not supported. Please use an alternative browser.
Error during challenge fetch. Please reload or use an alternative browser.

Dashboard

72

Total Challenges

29,975

Total Users

102,346

Total Solves

495

Monthly Solves
2020-04-11 02:07:08lottco0:44:18
The 247/CTF is a security Capture The Flag (CTF) learning environment. The platform contains a number of hacking challenges where you can test your skills across web, cryptography, networking, reversing and exploitation by solving problems to recover flags. Unless otherwise stated in the challenge description, all flags will follow the format of 247CTF{32-HEX}.

Once you solve a challenge and obtain the flag, you can submit and rate the challenge based on its difficulty. For example, you can solve this challenge right now by submitting the flag 247CTF{64b3c32a6856093faed367149ecaafb7}.
Login to play!
It's free!
2020-04-11 03:12:52lottco0:37:3517,082
A number of challenges require you to download files in order to be able to solve them. All challenge files are served bundled in a zip archive without a password. While none of our challenges are malicious or intended to cause harm, we still recommend you use a virtual machine when downloading and running applications from websites you don't trust - including this one.

Click on the ‘DOWNLOAD CHALLENGE’ button to the right of this text description to download the challenge and submit the flag!
Login to play!
It's free!
2020-04-11 03:13:02lottco0:34:5516,895
At the 247/CTF, challenges are not shared with multiple players and VPNs are not required. Instead, you have the control to start and stop your own unique challenge instance at any time. Once you have launched a challenge, you can access the instance by clicking on the pop up which loads in the bottom right hand corner of every page.

Click the ‘START CHALLENGE’ button to the right of this text description to start a web challenge. Once the challenge instance is launched, click on the pop up on the bottom right hand corner containing the challenge name to access the web application and submit the flag!
Unlock Hint
Login to play!
It's free!
2020-04-11 03:13:10lottco0:28:3617,761
At the 247/CTF, challenges are not shared with multiple players and VPNs are not required. Instead, you have the control to start and stop your own unique challenge instance at any time. Once you have launched a challenge, you can access the instance by clicking on the pop up which loads in the bottom right hand corner of every page.

Click the ‘START CHALLENGE’ button to the right of this text description to start a socket challenge. Once the challenge instance is launched, the pop up will contain either a tcp:// or udp:// link to access the socket hosting your challenge. Connect to the socket using a tool such as netcat or telnet and submit the flag!
Unlock Hint
Login to play!
It's free!
2020-04-11 02:07:43lottco2:00:39
At the 247/CTF, we try to minimise push messaging. To stay up to date with new challenge releases, news and updates we recommend you follow us on Twitter. Can you find the 247/CTF on Twitter? The flag is in the pinned tweet!
Login to play!
It's free!
2020-07-28 12:05:253ng_H3ndi2:00:16
The 247/CTF platform enables you to practise and improve your practical CTF skills. We also host a YouTube channel where we explain and explore CTF theory. Can you find the 247CTF on YouTube? The flag is in the channel about page!
Login to play!
It's free!
2021-01-05 11:05:39jusb31:57:57
The 247/CTF Discord server is a place to discuss CTF challenges, problems and ideas with a like minded community. You can join the 247/CTF Discord server via the following link.

Once you join the server, you can link your 247CTF account with Discord by sending a direct message to the 247CTF-BOT. You can view your Discord link code in your 247CTF profile (click the 'EDIT PROFILE' button). Once you link your accounts, the Discord bot will give you a flag!
Login to play!
It's free!
2020-04-11 03:13:15Driikolu1:19:4810,472
A number of challenges will require you to create solutions which are more efficiently solved by making use of a programming language to automate and perform the computations. For this purpose, we recommend to make use of Python as well as complementary libraries such as requests and pwntools.

If you are not sure where to start with Python, we recommend the introductory Python 101 for Hackers course.

Click the ‘START CHALLENGE’ button to the right of this text description to start a socket challenge. Utilise a programming language to interface with the socket and automate solving 500 simple addition problems to receive the flag. Take care when interfacing with unknown remote services - '\n' is not the only way to end
Unlock Hint
Login to play!
It's free!
2019-09-11 07:40:01MSC11:07:448:02:272.94/5.010,601YT
Can you recover the secret XOR key we used to encrypt the flag?
Login to play!
It's free!
2019-10-07 00:11:01nyz1:53:221 day, 11:14:352.92/5.04,289YT
This encryption service will encrypt almost any plaintext. Can you abuse the implementation to actually encrypt every plaintext?
Unlock Hint
Login to play!
It's free!
2020-12-17 09:39:07b4d4 days, 2:38:511 day, 10:07:222.93/5.01,744
We RSA encrypted the flag, but forgot to save the private key. Is it possible to recover the flag without it?
Login to play!
It's free!
2021-03-17 00:32:43pottm1:21:513 days, 21:39:362.99/5.0919
We put together a substitution-flag-permutation network. We encrypted the flag with the network, but forgot to write down the key. Can you reverse the network and recover the flag plaintext?
Login to play!
It's free!
2019-10-10 06:04:52jusb35:17:593 days, 21:21:373.07/5.01,061
We XOR encrypted this file, but forgot to save the password. Can you recover the password for us and find the flag?
Login to play!
It's free!
2019-10-15 09:26:16jusb32:17:233 days, 8:13:183.15/5.01,119
This encryption service will encrypt the flag along with any plaintext, but it won't decrypt it. Can you recover the flag anyway?
Unlock Hint
Login to play!
It's free!
2019-10-16 07:06:56jusb31:57:043 days, 8:37:553.33/5.01,267
We are trying to save time by limiting our calls to random. Can you abuse the predictable encryption mechanism to recover the flag?
Unlock Hint
Login to play!
It's free!
2020-10-18 11:19:33jusb330 days, 8:34:313 days, 8:03:283.67/5.0579
Can you abuse the flag HMAC implementation and forge a valid request?
Unlock Hint
Login to play!
It's free!
2019-09-24 06:38:52gynvael7 days, 15:00:293 days, 20:28:213.68/5.0778
We ran out of time to implement encryption for our cipher. Can you abuse the decryption implementation to recover the flag?
Unlock Hint
Login to play!
It's free!
2019-08-18 22:16:37shang11 day, 8:32:304 days, 17:08:121.94/5.05,609
We didn't have time to setup and test a proper jail, so this text editor will have to do for now. Can you break free?
Unlock Hint
Login to play!
It's free!
2019-09-26 08:43:54livinskull1 day, 9:49:024 days, 17:02:332.04/5.02,3952,968YT
Can you think of a number which at the same time is one more than itself?
Login to play!
It's free!
2019-09-27 07:25:02livinskull1 day, 11:15:5116 days, 23:10:322.28/5.01,7481,795
Can you guess the secret number to win the lottery? The prize is a flag!
Login to play!
It's free!
2019-08-18 22:15:47shang110 days, 9:39:5216 days, 22:57:132.34/5.02,128
The webserver for this challenge is storing sensitive data in memory. Can you read it? Did anybody patch since 2014?
Unlock Hint
Login to play!
It's free!
2020-05-02 08:03:27b4d5:16:255 days, 16:56:142.37/5.01,561
Can you find the bug and trigger an exception in this web application?
Unlock Hint
Login to play!
It's free!
2019-10-18 22:40:04Robin_Jadoul0:23:4816 days, 22:10:522.42/5.01,508
We created a hidden painting which will lead you to the flag. Can you connect the dots and piece it back together?
Login to play!
It's free!
2019-10-17 06:38:29chingyinwan1230:55:415 days, 16:41:452.58/5.01,025
We have had enough of everybody reading our flags. Since all of our cryptography implementations have been broken, we decided not to roll our own!
Login to play!
It's free!
2021-10-07 09:26:16reductor30 days, 23:33:555 days, 15:24:273.0/5.0350
We encoded the flag in a terse, but Turing complete programming language. Can you identify the valid characters required to extract the flag?
Login to play!
It's free!
2022-01-01 08:24:27pottm1:21:0516 days, 21:21:363.12/5.0341233
Can you sneak the secret code past the canary hidden down the challenge mine?
Login to play!
It's free!
2020-11-17 09:41:32b4d6:26:365 days, 14:01:133.09/5.0682
Our admins take their backup policies very seriously. Every single second they "/bin/tar czf *" our entire home directory. Can you trick the admin's into leaking the flag?
Unlock Hint
Login to play!
It's free!
2020-09-18 09:15:01Peace-Maker30 days, 2:53:2310 days, 3:47:013.48/5.0583
We don’t want to share the entire binary, but we will provide a 1-byte memory leak. Can you abuse the leak to gain code execution on the server?
Unlock Hint
Login to play!
It's free!
2019-10-15 07:04:02Ske0:55:403 days, 7:32:582.62/5.03,840
Can you identify the flag hidden within the error messages of this ICMP traffic?
Login to play!
It's free!
2019-08-19 07:33:41snowscan13 days, 9:12:3917 days, 21:05:492.87/5.01,090
We are trying to decrypt a packet capture taken on our internal network. We know you can decrypt the data using the correct private key, but we simply have too many. Can you identify the correct key?
Login to play!
It's free!
2019-10-04 23:34:36ENOENT1:19:5917 days, 21:00:002.98/5.0565
Can you recover the private key we used to download the flag over a TLS encrypted connection?
Login to play!
It's free!
2020-07-20 09:34:11Peace-Maker30 days, 7:00:0517 days, 20:16:543.11/5.0408
We are trying to improve resource utilisation by spreading data across several subflows. We needed to install a new kernel module, but the speed upgrade is worth it! Can you combine requests and recover the flag?
Login to play!
It's free!
2021-06-09 09:26:16Peace-Maker30 days, 1:34:5210 days, 6:19:553.08/5.0941
Our web server was compromised again and we aren't really sure what the attacker was doing. Luckily, we only use HTTP and managed to capture network traffic during the attack! Can you figure out what the attacker was up to?
Login to play!
It's free!
2020-03-15 01:40:30Peace-Maker2 days, 13:54:2817 days, 20:43:153.13/5.0592Thice
Our WiFi keeps disconnecting. We captured wireless traffic to try and figure out what’s happening, but it’s all temporal zeros to us! I think someone is trying to exploit a WiFi vulnerability.. Can you decrypt the traffic and gain access to the flag?
Login to play!
It's free!
2019-11-23 05:16:22jusb316:00:4616 days, 21:15:353.22/5.0292346
We are working on our own custom command and control protocol. Can you identify any hidden features in the service? We also included a packet capture of some old sessions so you can learn how it works.
Login to play!
It's free!
2020-01-11 23:16:02Peace-Maker31 days, 16:14:1517 days, 20:38:563.55/5.0342
We have a honey pot running on one of our internal networks. We received an alert today that the machine was compromised, but we can’t figure out what the attacker did. Can you find the flag hidden in the attacker's payload?
Login to play!
It's free!
2019-11-06 20:51:02jusb30:44:331:15:342.42/5.01,3911,271
Can you control this applications flow to gain access to the hidden flag function with the correct parameters?
Login to play!
It's free!
2019-10-30 06:51:14hashkitten1:15:060:32:562.54/5.01,440
Can you abuse our confused environment service to read flag data hidden in an environment variable?
Unlock Hint
Login to play!
It's free!
2019-11-05 21:02:32naver0:20:596 days, 1:32:432.44/5.02,7122,438
Can you control this applications flow to gain access to the hidden flag function?
Login to play!
It's free!
2020-01-01 05:58:33Peace-Maker30 days, 3:22:124 days, 9:40:032.5/5.0606444
Can you abuse our heaped notes service to create 3 identical notes?
Login to play!
It's free!
2019-11-07 20:56:36jusb30:20:012 days, 23:25:182.78/5.0771792
There are no hidden flag functions in this binary. Can you make your own using the stack?
Login to play!
It's free!
2019-11-10 04:28:08jusb32:07:484 days, 4:27:023.01/5.0515553
There are no hidden flag functions in this binary. Can you make your own without executing from the stack?
Login to play!
It's free!
2020-07-07 23:11:07jusb39:35:4416 days, 20:10:013.38/5.0347239razvioverflow
To protect against overflow attacks, we are limiting the number of bytes our applications will read. Is there still enough space to do something useful?
Login to play!
It's free!
2019-11-14 09:46:49elklepo4:49:4710 days, 3:08:323.68/5.0392437
We might not be able to write secure code, but at least we are starting to learn about secure compilation flags. Can you beat the cookie monster?
Login to play!
It's free!
2021-12-01 03:55:21pottm8:51:3410 days, 2:56:253.8/5.0191156
We are working on a simple service to store email addresses. Currently you can only store 10 addresses, but that should be enough for now. One of our beta testers complained about a few bugs, but we think they were just reading too much into it.
Login to play!
It's free!
2019-10-31 06:27:21jusb321:57:1610 days, 1:19:564.23/5.0496
Can you abuse our confused environment service to obtain a write primitive?
Unlock Hint
Login to play!
It's free!
2020-06-20 11:08:29Peace-Maker30 days, 4:19:3310 days, 1:01:064.25/5.0253234
We created a custom application to store challenge flags. Can you abuse the implementation to access the flag stored on the application server?
Login to play!
It's free!
2019-11-03 00:30:20jusb30:51:129 days, 23:51:344.11/5.0229
Can you abuse our less confused environment service to obtain a write primitive?
Unlock Hint
Login to play!
It's free!
2021-07-09 09:26:18Peace-Maker31 days, 1:47:519 days, 22:39:204.0/5.0158170
We created a custom application to store challenge flags. Can you abuse the implementation to access the flag stored on the application server? To prevent abuse, we spent some time researching secure compilation flags.
Login to play!
It's free!
2019-09-11 06:45:29MSC13:14:073 days, 0:54:171.98/5.03,299
One byte is great. But what if you need more? Can you find the flag hidden in this binary?
Login to play!
It's free!
2019-11-19 06:02:17jusb30:11:111 day, 11:19:362.36/5.02,244
You won't find the admin's secret password in this binary. We even encrypted it with a secure one-time-pad. Can you still recover the password?
Login to play!
It's free!
2022-10-08 05:11:48pottm3:19:4617 days, 21:16:002.78/5.0793
An important USB drive containing sensitive information has been encrypted by some new ransomware variant. Can you reverse the ransomware encryption function and recover the files?
Login to play!
It's free!
2021-01-16 01:29:57TheAwoo23 days, 21:03:1217 days, 22:04:512.85/5.0693
We stored the flag within this binary, but made a few errors when trying to print it. Can you make use of these errors to recover the flag?
Login to play!
It's free!
2021-08-08 09:26:19pottm20 days, 1:23:1417 days, 22:09:312.94/5.0532323
Why waste time creating multiple functions, when you can just use one? Can you find the path to the flag in this angr-y binary?
Login to play!
It's free!
2020-06-01 07:49:34Layle2 days, 2:46:2917 days, 22:16:002.97/5.0928
Can you unlock the secret boot sequence hidden within our flag bootloader to recover the flag?
Login to play!
It's free!
2019-09-06 07:02:47sebastianpc4 days, 2:33:0217 days, 22:18:183.01/5.0782
Can you reverse the secret combination to open the lock and recover the flag?
Login to play!
It's free!
2020-02-05 09:13:11Peace-Maker30 days, 1:08:4317 days, 22:27:513.05/5.0696528
We created a service which can read and print the flag for you. To use the application, you first need to enter a valid product key. Can you reverse the algorithm and generate a valid key?
Login to play!
It's free!
2021-09-07 09:26:16pottm0:51:5917 days, 22:32:473.25/5.0374
A secret flag is safely hidden away within client side scripts. We were told JavaScript is an insecure medium for secret storage, so we decided to use C++ instead.
Login to play!
It's free!
2019-08-18 22:14:30jorrit7 days, 12:31:471 day, 21:43:162.58/5.09,064
If you can guess our random secret key, we will tell you the flag securely stored in your session.
Unlock Hint
Login to play!
It's free!
2020-03-06 08:05:51Koori8 days, 0:53:261 day, 21:24:142.57/5.05,724
Developers don't always have time to setup a backend service when prototyping code. Storing credentials on the client side should be fine as long as it's obfuscated right?
Unlock Hint
Login to play!
It's free!
2019-08-06 11:46:02shang15 days, 20:21:091 day, 20:08:452.96/5.04,757YT
Can you identify a way to bypass our login logic? MD5 is supposed to be a one-way function right?
Unlock Hint
Login to play!
It's free!
2021-05-10 09:51:50alsacchi3 days, 8:22:495 days, 19:57:413.06/5.03,131
Can you forge a new identity to upgrade your access from an anonymous user to an admin?
Unlock Hint
Login to play!
It's free!
2019-09-29 21:56:39gynvael2 days, 0:18:029 days, 21:18:263.24/5.02,746YT
We have opened the flag, but forgot to read and print it. Can you access it anyway?
Unlock Hint
Login to play!
It's free!
2020-08-19 09:22:31b4d15 days, 9:42:155 days, 13:53:023.21/5.01,861YT
You can purchase a flag directly from the ACID flag bank, however there aren't enough funds in the entire bank to complete that transaction! Can you identify any vulnerabilities within the ACID flag bank which enable you to increase the total available funds?
Unlock Hint
Login to play!
It's free!
2021-02-15 00:33:10TheAwoo15:37:011 day, 16:05:143.22/5.01,028
Can you abuse the Twig injector service to gain access to the flag hidden in the $_SERVER array?
Unlock Hint
Login to play!
It's free!
2020-04-05 08:16:48kkapitan30 days, 8:05:005 days, 13:40:423.32/5.02,248
Can you abuse the zip upload and extraction service to gain code execution on the server?
Unlock Hint
Login to play!
It's free!
2019-10-22 06:54:31jusb32:30:074 days, 0:01:533.57/5.01,643
We started building a custom ORM for user management. Can you find any bugs before we push to production?
Unlock Hint
Login to play!
It's free!
2022-02-01 08:24:58blablub30 days, 7:07:234 days, 0:05:533.8/5.0898
We created an API service which has a few endpoints. Can you use the API to figure out the admin user’s password? The admin user’s password uses the same character set and length as the flag (32-HEX).
Unlock Hint
Login to play!
It's free!
2020-05-19 11:59:42JorgeCTF5:03:444 days, 0:09:153.85/5.0798chivato
Using a specially crafted cookie, you can write data to /dev/null. Can you abuse the write and read the flag?
Unlock Hint
Login to play!
It's free!
2019-10-08 07:23:31zert7:52:594 days, 0:13:194.1/5.01,062
If you can solve our custom CAPTCHA addition equation 100 times in 30 seconds you will be rewarded with a flag.
Unlock Hint
Login to play!
It's free!
2019-09-22 21:50:33owling1 day, 0:17:454 days, 0:20:184.15/5.01,384YT
This applications administrators are very aggressive. They will immediately view any page you report. Can you trick them into disclosing data they shouldn't?
Unlock Hint
Login to play!
It's free!
2021-04-14 10:52:37jusb32 days, 5:57:124 days, 0:33:064.37/5.0853bmdyy
We are working on a meme upload and messaging service. The service only allows users to upload images and currently only writes messages to a local directory. Can you find any bugs before we enable outbound Internet access and functionality to send the messages?
Unlock Hint
Login to play!
It's free!