// ZONA CTF
🚩 CTF Zone · 47 challenges
Guided missions and CTF challenges, all in one place. Each one has a safe simulated environment where you capture a flag and score on the leaderboard.
0%
Solved0 / 47
XP0
Level1 RECRUIT
🏆 How to score: solve the challenge, then in the terminal (the
>_ button) submit submit <ID> <FLAG>. Scoring is validated on the server. Set an alias and compete on the Global Leaderboard.
Type
Difficulty
✓ DONE
Mission
📜 Logs
Log Analysis
submit OP-FOOTPRINT
✓ DONE
Mission
🧬 Forensics
Exfiltration Analysis
submit OP-GHOST-TRAFFIC
✓ DONE
Mission
🧑💻 Source audit
Audit: Logic Bomb
submit OP-SECURE-DEV
✓ DONE
Mission
🖼️ Steganography
Shadow Messages
submit OP-DEEP-STATE
✓ DONE
Mission
🔭 Recon
The First Step
submit OP-ROBOTS
✓ DONE
Mission
🌐 Web
Tasty Cookies
submit OP-COOKIE-MONSTER
✓ DONE
Mission
🔭 Recon
Can you see what is hidden?
submit OP-SOURCE
✓ DONE
Mission
🔐 Crypto
Decode this
submit OP-B64-DECODE
✓ DONE
Mission
🔐 Crypto
Double Cipher
submit OP-DOUBLE-CIPHER
✓ DONE
Mission
🌐 Web
Compromised Token
submit OP-JWT-TOKEN
✓ DONE
Mission
🔐 Crypto
Broken Hash
submit OP-BROKEN-HASH
✓ DONE
Mission
🔍 OSINT
The Digital Trail
submit OP-DIGITAL-TRAIL
✓ DONE
Mission
🌐 Web
Unauthorized Access
submit OP-IDOR-ACCESS
✓ DONE
Mission
🧬 Forensics
Hidden Data
submit OP-EXIF-DATA
✓ DONE
Mission
🔐 Crypto
XOR Operation
submit OP-XOR-CRYPTO
✓ DONE
Mission
🌐 Web / LFI
Shadow Path Operation
submit OP-SHADOW-PATH
✓ DONE
Mission
🛡️ Blue Team
SOC Simulator: Live Defense
submit OP-SOC-SIM
✓ DONE
Mission
🧑💻 DevSecOps
Repository Leak
submit OP-SECRET-LEAK
✓ DONE
Mission
🔐 Crypto
The Ghost Certificate
submit OP-X509
✓ DONE
Mission
🔭 Recon
The Treasure Map
submit OP-CRAWLER
✓ DONE
CTF
🌐 Web
Authentication Bypass
submit OP-SQL-BYPASS · OP-DEFAULT-CREDS
✓ DONE
CTF
⚔️ Offensive
Command Injection & RCE
submit OP-CMD-INJECTION · OP-RCE-ROOT
✓ DONE
CTF
🌐 Web
Reflected XSS
submit OP-XSS-ALERT · OP-XSS-COOKIE
✓ DONE
CTF
🌐 Web
CSRF Forgery
submit OP-CSRF
✓ DONE
CTF
🌐 Web
API XXE
submit OP-XXE
✓ DONE
CTF
🖥️ System
Sudo Privesc
submit OP-SUDO-ESCALATION
✓ DONE
CTF
🌐 Web
Fuzzing Mastery
submit OP-FFUF-FUZZING
✓ DONE
CTF
🛡️ Defense
SOC Triage
submit OP-IR-CONTAINMENT
✓ DONE
CTF
🛡️ Defense
Secure Code Review
submit OP-SECURE-CODE
✓ DONE
CTF
🔍 OSINT
Nmap Forensics
submit OP-NMAP-RECON
✓ DONE
CTF
⚔️ Offensive
Hydra Web Auth
submit OP-HYDRA-BRUTE
✓ DONE
CTF
⚔️ Offensive
Python Scanner Dev
submit OP-PYTHON-SCANNER
✓ DONE
CTF
🛡️ Defense
Iptables Defender
submit OP-IPTABLES
✓ DONE
CTF
🛡️ Defense
Snort Rule Engineer
submit OP-SNORT-RULES
✓ DONE
CTF
🔍 OSINT
Shodan Dorking
submit OP-SHODAN-OSINT
✓ DONE
CTF
🖥️ System
Docker Socket Escape
submit OP-DOCKER-SOCKET
✓ DONE
CTF
🔍 OSINT
Nikto Forensics
submit OP-NIKTO-SCAN
✓ DONE
CTF
🌐 Web
Burp Suite Mastery
submit OP-BURP-SUITE
✓ DONE
CTF
⚔️ Offensive
Hashcat Rig
submit OP-HASHCAT
✓ DONE
CTF
🛡️ Defense
PCAP Forensics
submit OP-WIRESHARK-PCAP
✓ DONE
CTF
⚔️ Offensive
Msfvenom Crafter
submit OP-MSFVENOM
✓ DONE
CTF
⚔️ Offensive
SQLMap WAF Evasion
submit OP-SQLMAP-TAMPER
✓ DONE
CTF
🛡️ Defense
Apache Hardening
submit OP-APACHE-HARDENING
✓ DONE
CTF
📱 Mobile
Android Activity Bypass
submit OP-ANDROID-ACTIVITY
✓ DONE
CTF
📱 Mobile
DIVA Audit
submit OP-DIVA-ANDROID
✓ DONE
CTF
📱 Mobile
IPC Exploiter
submit OP-ANDROID-IPC
✓ DONE
CTF
📱 Mobile
Smali Patching
submit OP-SMALI-PATCHING
No challenges match these filters.
| St. | Challenge | Type | Category | Difficulty | ID(s) |
|---|---|---|---|---|---|
| • | Log Analysis | Mission | 📜 Logs | Easy | OP-FOOTPRINT |
| • | Exfiltration Analysis | Mission | 🧬 Forensics | Insane | OP-GHOST-TRAFFIC |
| • | Audit: Logic Bomb | Mission | 🧑💻 Source audit | Medium | OP-SECURE-DEV |
| • | Shadow Messages | Mission | 🖼️ Steganography | Hard | OP-DEEP-STATE |
| • | The First Step | Mission | 🔭 Recon | Easy | OP-ROBOTS |
| • | Tasty Cookies | Mission | 🌐 Web | Easy | OP-COOKIE-MONSTER |
| • | Can you see what is hidden? | Mission | 🔭 Recon | Easy | OP-SOURCE |
| • | Decode this | Mission | 🔐 Crypto | Easy | OP-B64-DECODE |
| • | Double Cipher | Mission | 🔐 Crypto | Easy | OP-DOUBLE-CIPHER |
| • | Compromised Token | Mission | 🌐 Web | Easy | OP-JWT-TOKEN |
| • | Broken Hash | Mission | 🔐 Crypto | Easy | OP-BROKEN-HASH |
| • | The Digital Trail | Mission | 🔍 OSINT | Easy | OP-DIGITAL-TRAIL |
| • | Unauthorized Access | Mission | 🌐 Web | Medium | OP-IDOR-ACCESS |
| • | Hidden Data | Mission | 🧬 Forensics | Medium | OP-EXIF-DATA |
| • | XOR Operation | Mission | 🔐 Crypto | Hard | OP-XOR-CRYPTO |
| • | Shadow Path Operation | Mission | 🌐 Web / LFI | Medium | OP-SHADOW-PATH |
| • | SOC Simulator: Live Defense | Mission | 🛡️ Blue Team | Hard | OP-SOC-SIM |
| • | Repository Leak | Mission | 🧑💻 DevSecOps | Medium | OP-SECRET-LEAK |
| • | The Ghost Certificate | Mission | 🔐 Crypto | Easy | OP-X509 |
| • | The Treasure Map | Mission | 🔭 Recon | Easy | OP-CRAWLER |
| • | Authentication Bypass | CTF | 🌐 Web | Easy | OP-SQL-BYPASS · OP-DEFAULT-CREDS |
| • | Command Injection & RCE | CTF | ⚔️ Offensive | Medium | OP-CMD-INJECTION · OP-RCE-ROOT |
| • | Reflected XSS | CTF | 🌐 Web | Easy | OP-XSS-ALERT · OP-XSS-COOKIE |
| • | CSRF Forgery | CTF | 🌐 Web | Medium | OP-CSRF |
| • | API XXE | CTF | 🌐 Web | Medium | OP-XXE |
| • | Sudo Privesc | CTF | 🖥️ System | Medium | OP-SUDO-ESCALATION |
| • | Fuzzing Mastery | CTF | 🌐 Web | Medium | OP-FFUF-FUZZING |
| • | SOC Triage | CTF | 🛡️ Defense | Easy | OP-IR-CONTAINMENT |
| • | Secure Code Review | CTF | 🛡️ Defense | Medium | OP-SECURE-CODE |
| • | Nmap Forensics | CTF | 🔍 OSINT | Easy | OP-NMAP-RECON |
| • | Hydra Web Auth | CTF | ⚔️ Offensive | Medium | OP-HYDRA-BRUTE |
| • | Python Scanner Dev | CTF | ⚔️ Offensive | Medium | OP-PYTHON-SCANNER |
| • | Iptables Defender | CTF | 🛡️ Defense | Medium | OP-IPTABLES |
| • | Snort Rule Engineer | CTF | 🛡️ Defense | Medium | OP-SNORT-RULES |
| • | Shodan Dorking | CTF | 🔍 OSINT | Easy | OP-SHODAN-OSINT |
| • | Docker Socket Escape | CTF | 🖥️ System | Hard | OP-DOCKER-SOCKET |
| • | Nikto Forensics | CTF | 🔍 OSINT | Easy | OP-NIKTO-SCAN |
| • | Burp Suite Mastery | CTF | 🌐 Web | Medium | OP-BURP-SUITE |
| • | Hashcat Rig | CTF | ⚔️ Offensive | Medium | OP-HASHCAT |
| • | PCAP Forensics | CTF | 🛡️ Defense | Medium | OP-WIRESHARK-PCAP |
| • | Msfvenom Crafter | CTF | ⚔️ Offensive | Medium | OP-MSFVENOM |
| • | SQLMap WAF Evasion | CTF | ⚔️ Offensive | Hard | OP-SQLMAP-TAMPER |
| • | Apache Hardening | CTF | 🛡️ Defense | Medium | OP-APACHE-HARDENING |
| • | Android Activity Bypass | CTF | 📱 Mobile | Medium | OP-ANDROID-ACTIVITY |
| • | DIVA Audit | CTF | 📱 Mobile | Medium | OP-DIVA-ANDROID |
| • | IPC Exploiter | CTF | 📱 Mobile | Hard | OP-ANDROID-IPC |
| • | Smali Patching | CTF | 📱 Mobile | Hard | OP-SMALI-PATCHING |