CTF Write-ups

CTF Write-ups

Solutions and walk-throughs from Capture the Flag challenges. Filter by category or difficulty, or search by title, event, or tag.

web Sample CTF 2026 100 pts 2026-05-18

A classic authentication bypass — the login form builds its query with unsanitised string concatenation, so a crafted username logs us in as admin.

sql-injectionauthenticationweb
read write-up →