• Solves: 15
  • There is a fancy new cyber-enabled messaging service: nc 35.197.255.108 1338

    Recently, we have intercepted a message from that service. It seems to originate from Shia himself! So it must be important! Recover it!

    Luckily, cyberms is open-source. You will also find the intercepted message in that archive. Good luck!

  • Solves: 57
  • I implemented some crypto and encrypted my secret: 03_duCbr5e_i_rY_or cou14:L4G f313_Th_etrph00 Wh03UBl_oo?n07!_e

    Can you get it back?

  • Solves: 56
  • Check this out!!!!!!!!!!!\x80\x00....

    Update: Source

  • Solves: 166
  • Perfectly secure. That's for sure! Or can break it and reveal my secret?


  • Solves: 187
  • If you're a baby and know bash, try this:

    nc 35.189.118.225 1337

  • Solves: 9
  • I think I'm getting crazy! I see things in things. Like this: PDF

  • Solves: 2
  • This is a hard challenge :)

    I intercepted a message: 2FED5B7FEB81D3C44E39E4AEA346010240E0CBBB

    I know the hardware used. See schematic for an overview. Someone sent me this PRNG.

  • Solves: 18
  • This bonus track has an easteregg. Can you find it?

  • Solves: 2
  • My favorite song from my favorite movie. It has a hidden message inside. If you find it you can hack the planet!

  • Solves: 86
  • I used to be a hero. Now I can't even handle this: Mitschnitt

  • Hints:
    • We messed up, the flag starts with 34C4 not 34C3, sorry!


  • Solves: 268
  • We bought a new Digital Billboard for CTF advertisement:

    nc 35.198.185.193 1337

  • Solves: 8
  • As a new service¹ for our customers who are not satisfied with this year's christmas gifts, we launched the modern, state of the art Gift Shredder Plant:

    nc 35.198.185.193 1342

    (¹) Unfortunately we are not able to compensate for your financial loss.

  • Solves: 53
  • Have trouble wrapping your gifts nicely? Take a look at this new service:

    nc 35.198.185.193 1338

  • Solves: 22
  • To guarantee a constant supply of Mate we built our own Mate Bottling Plant:

    nc 35.198.185.193 1339

  • Solves: 8
  • There were some minor problems with the previous version of Mate Bottling Plant. We hired the world's best Mate specialists to improve usability, functionality and security in our new Mate Bottling Plant 2.0:

    nc 35.198.185.193 1340


  • Solves: 269
  • Can you reverse engineer this code and get the flag?

    This code is ARM Thumb 2 code which runs on an STM32F103CBT6. You should not need such a controller to solve this challenge.

    There are 5 stages in total which share all the same code base, so you are able to compare code from the first stage with all the other stages to see what code is actually relevant.

    If you should need a datasheet, you can get it here.

    In case you need to refresh your ARM assembly, check out Azeria's cool articles.

    Challenge binary

  • Solves: 30
  • Can you reverse engineer this code and get the flag?

    This code is ARM Thumb 2 code which runs on an STM32F103CBT6. You should not need such a controller to solve this challenge.

    There are 5 stages in total which share all the same code base, so you are able to compare code from the first stage with all the other stages to see what code is actually relevant.

    If you should need a datasheet, you can get it here.

    In case you need to refresh your ARM assembly, check out Azeria's cool articles.

    Challenge binary

  • Solves: 25
  • Can you reverse engineer this code and get the flag?

    This code is ARM Thumb 2 code which runs on an STM32F103CBT6. You should not need such a controller to solve this challenge.

    There are 5 stages in total which share all the same code base, so you are able to compare code from the first stage with all the other stages to see what code is actually relevant.

    If you should need a datasheet, you can get it here.

    In case you need to refresh your ARM assembly, check out Azeria's cool articles.

    Challenge binary

  • Solves: 11
  • Can you reverse engineer this code and get the flag?

    This code is ARM Thumb 2 code which runs on an STM32F103CBT6. You should not need such a controller to solve this challenge.

    There are 5 stages in total which share all the same code base, so you are able to compare code from the first stage with all the other stages to see what code is actually relevant.

    If you should need a datasheet, you can get it here.

    In case you need to refresh your ARM assembly, check out Azeria's cool articles.

    Challenge binary

  • Solves: 6
  • Can you reverse engineer this code and get the flag?

    This code is ARM Thumb 2 code which runs on an STM32F103CBT6. You should not need such a controller to solve this challenge.

    There are 5 stages in total which share all the same code base, so you are able to compare code from the first stage with all the other stages to see what code is actually relevant.

    If you should need a datasheet, you can get it here.

    In case you need to refresh your ARM assembly, check out Azeria's cool articles.

    Challenge binary

  • Solves: 14
  • My uncle told me not to stick my passwords to my monitor. So I started this cool Arduino project which could show me my most valuable passwords on demand.

    My uncle also gave me a wider display for even more secure passwords. As it is compatible with my previous one I could easily switch.

  • Solves: 87
  • We love snakes.

  • Hints:
    • $ cat flag | md5sum

      5a76c600c2ca0f179b643a4fcd4bc7ac

  • Solves: 34
  • Wanna go to saturn? Give me the launch codes from: nc 35.198.169.47 1337


  • Solves: 19
  • We found this pizza shop. It seems to be under construction currently, but we believe the whole shop is a just a front for some fishy business. Is the Italian Mafia behind all this?

    Grab your OWASP Top 10 list and investigate! We need to find out what's going on!

  • Hints:
    • For the basic authentication step: Have you checked out A1 in your list? And the HTTP response headers?

  • Solves: 13
  • If you don't trust Twitter, you might like Quaker!

  • Hints:
    • I like this site: https://html5sec.org quite useful sometimes. Maybe you will find it useful too?

  • Solves: 175
  • This is an useful service to unzip some files.

    We added a flag for your convenience.

Infrastructure sponsored by Google Cloud