THCON 2026 RULES / INFO PAGE writeup — CTF challenge breakdown

THCON 2026 Rules: Flag Hidden on the CTF Platform's Own /info Page

Platform THCON 2026 (Toulouse Hacking Convention) Difficulty Easy OS OSINT Tags Reading prompts literally, CTF platform recon Most “find the hidden flag on a webpage” challenges teach you to look harder. This one teaches the opposite — that the most-obvious destination in the prompt is a decoy, and the answer is whatever a literal reading of the wording actually points at. The trick is recognising the misdirection before sinking thirty minutes into the wrong target. ...

May 16, 2026 · 3 min · 593 words · CyberSecurity Elite Team
THCON 2026 SOCIALS writeup — CTF challenge breakdown

THCON 2026 Socials: Half-Flag Each on LinkedIn and X

Platform THCON 2026 (Toulouse Hacking Convention) Difficulty Easy OS OSINT Tags Social media OSINT, leetspeak THCON’s Socials is the kind of warm-up OSINT challenge that’s not about tooling — it’s about reading the prompt twice and noticing the CTF authors have done something cute with their social media presence. The flag is split between two posts on two platforms, with each post hiding the other half behind an ellipsis. Visit both, stitch the halves, done. ...

May 16, 2026 · 3 min · 447 words · CyberSecurity Elite Team
BKISC 2026 BORING APK writeup — CTF challenge breakdown

BKISC 2026 Boring APK: Android NDK Reverse + Graph-Walk MitM

Platform BKISC CTF 2026 Difficulty Hard OS Android (arm64-v8a) Points 250 Tags APK extraction, AES-GCM, ELF patching, qemu-aarch64, NDK basic_string, meet-in-the-middle Boring APK was the 250-point reverse engineering challenge of BKISC CTF 2026. The hook is the title’s bait — Android is “boring” until you realise the flag check has been moved out of the Java/Kotlin layer into a native library, the assets it depends on are AES-GCM-encrypted, and the check itself is a 27-step graph walk with three running state words whose final values are all that the verifier compares. None of those stages is hard in isolation; stacking them is what makes the challenge. ...

May 16, 2026 · 8 min · 1624 words · CyberSecurity Elite Team
BKISC 2026 CRYPTOGRAFIE writeup — CTF challenge breakdown

BKISC 2026 Cryptografie: Java AltBase64 over UTF-16 BE

Platform BKISC CTF 2026 Difficulty Easy OS Encoding Points 50 Tags JDK source reading, custom Base64 alphabet, UTF-16 BE Cryptografie is a 50-point crypto challenge from BKISC CTF 2026 that hangs off a single, very specific hint: FileSystemPreferences.dirName(). If you’ve never had to look at the OpenJDK source before, this challenge is a tour of an internal Base64-like helper that almost nobody outside the JDK uses — and the decoder only takes about ten lines once you know where to look. ...

May 16, 2026 · 4 min · 768 words · CyberSecurity Elite Team
BtSCTF 2026 POKECOLLECTOR writeup — CTF challenge breakdown

BtSCTF 2026: Pokecollector Writeup — IDOR Through a Self-Issuing JWT

Platform BreakTheSyntax CTF 2026 Difficulty Easy OS Web Tags IDOR, JWT, OWASP API1:2023 Broken Object Level Authorization Pokecollector is the kind of web challenge that sits right inside the OWASP API Top 10’s number one slot — API1:2023 Broken Object Level Authorization. The application enforces its access rules in the UI and forgets to enforce them on the API. The fix is a single server-side validation; the cost of missing it is a leaked flag. ...

May 16, 2026 · 5 min · 906 words · CyberSecurity Elite Team
BtSCTF 2026 FCP writeup — CTF challenge breakdown

BtSCTF 2026 FCP: Recover In-Memory RSA Key, Decrypt Resumed TLS

Platform BreakTheSyntax CTF 2026 Difficulty Hard OS Linux Tags TLS, RSA, Go memory forensics, EMS PRF, session resumption FCP was a multi-step reverse-engineering and network-forensics challenge. You get a Go MCP (“Model Context Protocol”) server binary plus a PCAP of someone using it earlier. Buried in the capture is a get_flag call — but the live server’s get_flag endpoint has been rewritten to just return "no", so re-running it is useless. The challenge is to decrypt the historical traffic. Two specific design choices make this both possible and nontrivial. ...

May 16, 2026 · 8 min · 1498 words · CyberSecurity Elite Team
HTB vs THM WHICH TO CHOOSE IN 2026 writeup — CTF challenge breakdown

Hack The Box Academy vs TryHackMe: Which Should You Choose in 2026?

If you’re new to offensive security, the choice between HackTheBox Academy and TryHackMe is the first major one you’ll make. Both are excellent. They are not interchangeable. TL;DR TryHackMe: gentler learning curve, broader topic coverage, lower cost. Best for beginners and breadth. HackTheBox Academy: deeper technical content, more rigorous assessments, structured paths to industry certs. Best for intermediate to advanced and depth. For most learners: start with TryHackMe, transition to HTB once you’re comfortable with the fundamentals. ...

May 6, 2026 · 3 min · 617 words · CyberSecurity Elite Team
CTF CRYPTO SOLVING STRATEGIES writeup — CTF challenge breakdown

CTF Crypto Challenges: Solving Strategies That Actually Work

Crypto categories in CTFs intimidate more newcomers than any other. The barrier isn’t math — it’s pattern recognition. Almost every CTF crypto challenge is a known weakness applied to slightly different parameters. The First Pass — Identify the Family When a challenge drops, classify it in under 30 seconds: ...

April 23, 2026 · 4 min · 699 words · CyberSecurity Elite Team
HTB SAUNA WALKTHROUGH writeup — CTF challenge breakdown

Hack The Box: Sauna Walkthrough — AS-REP Roasting to DCSync

Platform Hack The Box Difficulty Easy OS Windows Points 20 Release 2020-02-22 Tags AD, AS-REP Roasting, DCSync Sauna is a deceptively rich Active Directory box. Despite its Easy rating, it walks you through three classic AD attack primitives — AS-REP Roasting, credential reuse via AutoLogon, and DCSync — making it one of the best beginner boxes for anyone preparing for OSCP, CRTP, or AD-heavy red team interviews. ...

April 22, 2026 · 3 min · 520 words · CyberSecurity Elite Team
THM PICKLE RICK WALKTHROUGH writeup — CTF challenge breakdown

TryHackMe: Pickle Rick Walkthrough — Web Exploitation for Beginners

Platform TryHackMe Difficulty Easy OS Linux Points 10 Release 2019-08-29 Tags Web enum, command injection, sudo abuse Pickle Rick is the room every new TryHackMe user solves first. It’s a perfect introduction to the full pentest loop on a single host — enumeration, exploitation, and post-exploitation — with a forgiving difficulty curve. ...

April 18, 2026 · 2 min · 377 words · CyberSecurity Elite Team
Educational content for authorized testing only. · Disclaimer · Editorial Policy · Sitemap