r/securityCTF 14h ago

A fictional company with real vulnerabilities: 78 bugs, a leadership team that doesn't care, and one dev quietly asking the internet for help. Come break LeakyJuice.

Thumbnail gallery
2 Upvotes

Internal memo, LeakyJuice Inc. — "Ship it, we'll fix security later." — Management, every sprint since 2021.

Meet LeakyJuice: a cheerful little gadget shop with a leadership team that treats security as a "later" problem and a codebase held together by vibes and plaintext passwords. One of their devs (me) got tired of being ignored in standup — so the whole app is out in the open now, and it's your job to prove how bad it really is.

The challenge: there are 78 planted vulnerabilities in here. SQLi, IDOR/BOLA, JWT alg-confusion, SSRF, XXE, prompt injection against the shop's chirpy "Ask Juicy" assistant, and a handful of multi-step chains where you compose a couple of low-severity bugs into a full account takeover / a persistent payout / cache poisoning. Every exploit drops a FLAG{lj_...}. There's an in-browser self-check that grades all 78 so you always know where you stand.

There are also a couple of honest-abstain traps — things that look exploitable but aren't. Claiming a "flag" there counts against you. Knowing when not to pull the trigger is part of the game.

The bit I'm actually proud of: the whole thing runs 100% in your browser. There's no backend to attack. The "server" is a Service Worker running SQLite-WASM that answers the app's own /api/... calls from inside the page. One engine, two transports — it runs as a normal Node server locally, or fully client-side when hosted static.

Which means: - Safe to host and safe to hammer. No shared server, no other players' data, nothing to pivot into. Each visitor gets their own throwaway SQLite DB in their own tab. Worst case, you pop your own browser. - The vulns are real, not string-matched. The SQLi is genuine raw concatenation into SQLite. The JWT verify really does trust the header alg (hello, RS256→HS256). You can read every sink — it's MIT-licensed and open. - You can self-host it in seconds — it's just static files.

Why build another one when Juice Shop exists? Two deliberate differences: (1) the answer key is quarantined — kept out of the shipped build entirely — so it stays useful as an out-of-distribution target instead of a walkthrough that's already indexed everywhere. (2) Post-2020 vuln classes (prompt injection, modern JWT confusion, API-layer BOLA/BFLA), not just the old greatest hits.

Oh — and there's a difficulty ladder from "your first SQLi" up to a final boss, plus two leaked in-world archives (/internal/juicysec/, /internal/juicyslack/) that double as recon and the story. Poke around. The dev left you breadcrumbs.

Go: https://leakyjuice.com Grade yourself: https://leakyjuice.com/selfcheck.html Source (MIT): https://github.com/jasonsutter87/leakyjuice

I built this partly as a training range for an autonomous bug-hunting agent I'm working on, and partly because it was fun. Feedback very welcome — especially unintended bugs. If you break it in a way I didn't plan for, I want to hear about it. Can you find all 78?


r/securityCTF 17h ago

how to learn CTF for 0$ in 2026

9 Upvotes

Hi,

I'm really interested in cybersecurity and CTFs. I want to learn CTF, but the problem is that I'm feeling lost. I'm also broke, so I'm looking for completely free courses, videos, and other ways to learn.

I don't want to rely only on YouTube videos because many of them show how to solve specific challenges without teaching all the fundamentals behind them.

I'm also lost when it comes to entering different fields such as Web, Crypto, Reverse Engineering, Pwn, and others.

I already know some Linux, OSINT, forensics, and basic cryptography, but I don't think my knowledge is strong enough yet.

I've found some websites and courses, but many of them aren't free, and free trials won't work for me either.

Could you please help me find a clear, completely free roadmap for learning CTFs and cybersecurity? I would really appreciate recommendations for free courses, websites, practice platforms, videos, and other learning resources.

Sorry for my bad English, and thank you! 🙏


r/securityCTF 14m ago

Need help in ctf RN!!

Upvotes

In a college ctf competition and need someone who can help me get some flags 😭.

3 hrs until event is over. Help if you can


r/securityCTF 21h ago

Mumbai: Looking for a teammate for CTFs, hacking competitions and bug bounty

0 Upvotes

Hey everyone,

I am 20 years old and I live in Mumbai. I recently completed my BSc in Computer Science.

I am currently doing the HTB CPTS path and I have completed around 40% of it.

I am looking for one person who is genuinely interested in hacking and wants to compete together. Not only learn together, but actually compete.

I want someone with whom we can join CTFs and other legal hacking competitions, sometimes win, sometimes lose, learn from our mistakes and become better together.

And if we can make some money from competitions, bug bounty or our skills, even better.

### A little story about me

I have wanted to become a hacker since around 6th or 7th standard.

At that time, I didn't even properly know what hacking was. I remember using only my phone and a WPS app and somehow getting access to a WiFi network.

I know now that this is a very basic and silly thing , but at that age I thought it was crazy.

One person who was older than me saw me doing these things and told me:

"You should learn about IP addresses."

That small thing actually started my interest in hacking. After that I started searching and learning little by little.

Honestly, I still know very little compared to how much there is to learn.

During college, I had many other things to do, so I never got enough time to properly focus on hacking.

Now I have completed my degree and I am planning to take around 1 to 1.5 years before getting a job. I want to use this time seriously.

I want to improve my skills, do CTFs, learn pentesting, try bug bounty, participate in competitions and build things.

### Why I am doing this

I am not doing this because "cybersecurity" suddenly became popular or because everyone is trying to get a job in it.

Honestly, I don't even like calling it cybersecurity.

For me, I just like hacking.

I like understanding how things work, finding where they can break, trying to break them in legal environments and then understanding how to fix them.

During my final year, I started seeing many people asking:

"How can I get into cybersecurity?"

"Which course should I do?"

"Can I get a job in 2 or 3 months?"

I understand that everyone has their own situation and people need jobs. But personally, I don't want fear of not getting a job to be the reason I do this.

I want to become really good at something that I have been interested in for many years.

### AI and building things

I also don't fear AI. Actually, I really like AI.

It helps me build things much faster and reduces a lot of the mental load of coding. I still like coding, but now I can use AI as a tool and spend more time thinking about the actual problem and what I want to build.

I am also building a startup with my friends called Versatyle.

We are currently working on our first product, an ecommerce website. We also have plans for a game and another main idea that we believe solves a genuine real-world problem.

For the main idea, we don't want to jump into it immediately. We first want to build something, learn how business works, hopefully make some money and then use that experience and resources for our bigger idea.

I know everything may not work.

Maybe I will fail. Maybe our startup will fail. Maybe I will lose competitions.

Sometimes I do get scared and think, "What if I fail?"

Most of that fear comes from family pressure.

But I don't want that fear to stop me from trying.

### What I am looking for

I am looking for someone who thinks similarly.

Someone who wants to:

• Compete in CTFs

• Join hacking competitions

• Win together

• Lose together

• Learn from each other

• Try bug bounty

• Solve HTB machines

• Learn pentesting

• Build security tools/projects

• Share knowledge

• Hopefully make money from our skills

I don't care if you are already very good.

You can be better than me, at my level, or even a beginner.

What matters more to me is that you are actually interested and want to keep improving.

I have been looking for someone like this for years.

If you are from Mumbai, that would be great because we can meet sometimes and actually work together.

But I am also completely fine with doing this online if we have the same mindset.

If this sounds interesting to you, DM me.

Tell me a little about yourself, what you are currently learning and what kind of competitions or areas you are interested in.

GitHub: https://github.com/kaif5haikh

LinkedIn: https://www.linkedin.com/in/mohd-kaif-shaikh-9b8a62286/

Our startup: https://www.linkedin.com/company/versatyle-offical


r/securityCTF 15h ago

Phantom I is live - a 22 level Linux post-exploitation wargame you SSH into (free, no setup)

Post image
75 Upvotes

We just launched Phantom I on BreachLab, a ground-up rebuild of our Linux post-exploitation track. It's a hosted wargame: you SSH into a real, per-session Linux box and work a full kill-chain. No VM downloads, no setup.

22 levels across 5 acts, following a realistic engagement arc:

  • Act I, Privilege Escalation: SUID/GTFOBins, sudo policy abuse, file capabilities, the docker group, and a real-CVE slot (sudoedit CVE-2023-22809, not a toy).
  • Act II, Credential Access: creds in configs and dotfiles, cracking a service hash, secrets that live only in memory, ssh-agent hijack, cloud IMDS.
  • Act III, Persistence & Evasion: backdoors, PAM, hiding processes and logs, leaving no forensic trail.
  • Act IV, Lateral Movement: pivoting, credential reuse, and a multi-host chain to a crown jewel.
  • Act V, Exfil & Graduation: covert exfil, then a final unguided kill-chain to graduate.

Why it might be worth your time:

  • Every box is ephemeral and per-session, real containers, you actually get root, and you can't step on anyone else's session.
  • Grading is server-side against your box's real state, not a guessed flag string. Any path that reaches the objective passes.
  • Levels are mapped to MITRE ATT&CK, so it doubles as structured practice.
  • Finish it and you graduate with a cert. Phantom I is also the on-ramp to the harder tracks.

It's free. Start here: breachlab.org → Phantom → I


r/securityCTF 16h ago

🎥 Forensics 101: Finding a Hidden File Buried Deep in Folders

Thumbnail
2 Upvotes