Global rank
#20
All-time leaderboard
Total points
4,950
Across CTF seasons
Challenges solved
2
Distinct arenas
Captures solved
11
361h 36m total
Activity
Submission rhythm.
Monthly captures
Monthly Captures
Submissions
Public captures.
- VulnCorpWhat is the flag from the secrets vault accessed by exploiting the fail-open authentication bypass?450 ptsCompleted
- VulnCorpWhat is the flag returned by the exfiltration callback endpoint of the backdoored supply chain package?450 ptsCompleted
- VulnCorpWhat is the flag extracted from the AI assistant's internal configuration through prompt injection?450 ptsCompleted
- VulnCorpWhat is the flag retrieved from the internal cloud metadata service accessed via Server-Side Request Forgery?450 ptsCompleted
- VulnCorpWhat is the flag received after verifying the admin credentials obtained through SQL injection and password hash cracking?450 ptsCompleted
- VulnCorpWhat is the flag obtained from the debug admin panel accessed through secrets leaked in the exposed git commit history?450 ptsCompleted
- Droid-WardenIf you’ve made it through the last door, it’s time to search for the treasure hidden within.450 ptsCompleted
- Droid-WardenBroken authentication is an invitation to attackers to walk right in. You don’t need to break the front door, it’s already unlocked.450 ptsCompleted
- Droid-WardenFeeling unwell? A doctor uses an injection. Some systems react similarly when prodded the right way.450 ptsCompleted
- Droid-WardenUser “daniel” seems innocent enough, but not everyone takes security seriously, and he’s no exception.450 ptsCompleted
- Droid-WardenLook beyond what the app shows you to uncover the first flag.450 ptsCompleted