CTF Challenges — PlainlySec Arena

CAPTURE THE FLAG

PlainlySec CTF Arena

15 hands-on cybersecurity challenges across forensics, web security, cryptography, steganography and network analysis. All challenges use real downloadable files.

🟢 6 EASY 🟡 7 MEDIUM 🔴 2 HARD 🏆 1450 Total Points

🟢 Easy Challenges

🟡 Medium Challenges

MEDIUM 100 pts

Challenge #5: Packet Detective

Network Forensics — Analyze PCAP for DNS tunneling data

pcap wireshark dns
MEDIUM 125 pts

Challenge #7: SQL Injection 101

Web Security — Bypass authentication using SQL injection

web sqli database
MEDIUM 150 pts

Challenge #8: What Did the Malware Say?

Malware Forensics — Extract strings from a binary executable

forensics strings malware
MEDIUM 150 pts

Challenge #9: Hash Cracking Challenge

Cryptography — Identify and crack multiple password hashes

hashcat hashing passwords
MEDIUM 150 pts

Challenge #11: Certificate of Deception

Forensics / Crypto — Extract hidden data from an X.509 certificate

certificate x509 openssl
MEDIUM 175 pts

Challenge #12: The Silent Signal

Steganography — Extract hidden data from audio LSB encoding

audio steganography wav
MEDIUM 175 pts

Challenge #14: DNS Tunnel Vision

Network Forensics — Decode data exfiltrated via DNS tunneling

network dns hex

🔴 Hard Challenges

All challenges are offline — download the file, analyze locally. No internet access to external services required.

Progress is saved locally in your browser. View Scoreboard