Test your Linux command line skills with 18 progressive Capture The Flag challenges.
Important
Please complete Phase 1 Guide before attempting these challenges. Do not share solutions publicly - focus on sharing your learning journey instead.
You'll need: a cloud account (AWS, Azure, or GCP), Terraform, your provider's CLI, and about 3-4 hours.
-
Fork this repository to your GitHub account. Completion verification checks that you have a fork.
-
Deploy the lab with your provider's guide:
Provider Cost for ~4 hours Guide AWS ~$0.01 (Free Tier eligible) AWS Guide Azure ~$0.05 Azure Guide GCP ~$0.03 GCP Guide -
Play by connecting over SSH and solving challenges with the Playing the Lab guide. It covers the
verifycommand and exporting your completion token. -
Clean up with
terraform destroywhen you're done, after saving your token, so you aren't billed for a VM you've finished with.
Running into problems? See TROUBLESHOOTING.md.
⏱️ Expected time: 3-4 hours to complete all challenges
| # | Challenge | Description | Difficulty | Skills |
|---|---|---|---|---|
| 1 | The Hidden File | Find and read a hidden file in ctf_challenges |
⭐ | Hidden files, directory listing |
| 2 | The Secret File | Locate a regular file (not a directory) with "secret" in its name under your home directory | ⭐ | File searching |
| 3 | The Odd Log Entry | Thousands of failed logins hide a single successful one in a log under /var/log |
⭐⭐ | Log analysis, text filtering |
| 4 | The User Detective | Another user's account record carries a flag | ⭐⭐ | Users, account records |
| 5 | The Permissive File | Find a suspicious file with wide-open permissions under /opt, then follow where it leads |
⭐⭐ | Permissions, file ownership |
| 6 | The Hidden Service | Something is listening on port 8080. Connect to it | ⭐⭐ | Networking, ports |
| 7 | The Encoded Secret | Find and decode an encoded flag in ctf_challenges |
⭐⭐ | Encoding, decoding |
| 8 | SSH Key Authentication | Set up SSH key authentication to log in as the key-only vault user |
⭐⭐⭐ | SSH key authentication, users |
| 9 | DNS Inspection | Find the lab's custom search domain and resolve a host inside it | ⭐⭐ | DNS, name resolution |
| 10 | Remote Upload | From your own computer, upload a new file into ~/ctf_challenges on the VM to trigger the flag. It is broadcast to your open terminals |
⭐⭐ | File transfer |
| 11 | Web Configuration | nginx should serve the site on port 80 but is misconfigured. Find and fix it | ⭐⭐ | Web servers, services, config debugging |
| 12 | Network Traffic Analysis | Someone is sending secret messages via ping packets on the loopback interface (needs sudo) |
⭐⭐⭐ | Packet inspection |
| 13 | Cron Job Hunter | A scheduled job handles a secret. Find out what it runs and inspect the result | ⭐⭐ | Cron, scheduling |
| 14 | Process Environment | A running process has a secret in its environment. Extract it | ⭐⭐⭐ | Processes, environment variables |
| 15 | Archive Archaeologist | A flag is buried inside nested archives. Dig it out | ⭐⭐ | Archives, compression |
| 16 | Symbolic Sleuth | Start at follow_me in ~/ctf_challenges and follow the trail of symbolic links. The flag is where the trail ends |
⭐⭐ | Symbolic links |
| 17 | History Mystery | Someone typed a secret into their command line. Find it. Not every secret is the real one | ⭐⭐ | Shell history, text search |
| 18 | Disk Detective | A flag is hidden in filesystem metadata. Inspect the disk image | ⭐⭐⭐ | Disk images, filesystem metadata |
Difficulty: ⭐ Beginner | ⭐⭐ Intermediate | ⭐⭐⭐ Advanced
There are 18 challenges. verify progress reports /19 because it also counts the practice flag (challenge 0) that checks verify works.
The certificate and token from verify export work on the honor system. They record that you finished the lab, but they can't prove it. You control the VM and have root on it, and the token's signing key is in this public repository, so anyone determined to fake a token can.
That's a deliberate choice. The lab exists to build your skills, and a token you didn't earn gets you nothing. Anyone reviewing your work should treat the certificate as your own statement, not as proof.
Want to help improve the CTF? See our Contributing Guide.
Please only submit issues with the lab infrastructure, not for help completing challenges—struggling is part of learning!