picoCTF Solutions: Step-by-Step Writeups
513+ picoCTF solutions spanning 2019 through 2026 and the picoGym Exclusive practice set. Every writeup walks through the exact commands, the reasoning behind each step, and the relevant tools, so you can finish the challenge and actually understand it.
Browse by competition
- picoCTF 202670 writeups
- picoCTF 202541 writeups
- picoCTF 202447 writeups
- picoCTF 202342 writeups
- picoCTF 202265 writeups
- picoCTF 202186 writeups
- picoCTF 2020 Mini-Competition6 writeups
- picoCTF 201986 writeups
- Beginner picoMini 202214 writeups
- picoMini by CMU-Africa13 writeups
- picoMini by redpwn21 writeups
- picoGym Exclusive22 writeups
Technique guides
General skills
- How to Start Playing CTFs: A Complete Beginner's Guide
- The picoCTF General Skills Roadmap: The Category Everything Else Rests On
- Archive and Zip Password Cracking for CTF
- Git Forensics for CTF: What to Do When git log Returns Nothing
- The Complete picoCTF Beginner's Guide: Learning Path, Tools & Every Category
- Beginner's Guide to Netcat for CTFs
- Linux Command Line Basics for CTF Competitions
- How to Read and Analyze Hex Dumps
- Base64, Hex, and Common CTF Encodings Explained
Cryptography
- Modular Arithmetic for CTF Crypto: The Math Behind RSA, DH, and ECC
- XOR for CTF: Breaking XOR Encryption Without the Key
- Reversing Custom Ciphers for CTF: Breaking Homebrew Encryption
- The picoCTF Cryptography Roadmap: From Caesar to Elliptic Curves
- Diffie-Hellman and Discrete Log for CTF: Breaking Weak Key Exchanges
- Hash Length Extension Attacks for CTF: Forging a MAC Without the Secret
- Insecure Randomness for CTF: Predicting PRNGs and the Mersenne Twister
- Padding Oracle and CBC Bit-Flipping Attacks for CTF
- z3 for CTF: Constraint Solving from Keychecks to Crypto
- Elliptic Curves for CTF: The Discrete Log Is the Whole Game
- Classical Ciphers for CTF: Caesar, Vigenère, and Substitution
- Stream Ciphers in CTFs: LFSR, Vigenere, and Keystream Reuse
- AES for CTF: Read the Ciphertext, Not the Math
- Hash Cracking for CTF: MD5, SHA-1, SHA-256 and Beyond (picoCTF 2025)
- RSA Attacks for CTF Cryptography
Web exploitation
- HTTP for CTF: Requests, Headers, Status Codes, and DevTools
- JavaScript Deobfuscation for CTF: Hook the Sink, Not the Source
- The picoCTF Web Exploitation Roadmap: Recon to RCE
- CSRF for CTF: Forging Requests and Bypassing Tokens
- GraphQL Exploitation for CTF: From /graphql to the Flag
- Authentication Bypass and IDOR for CTF: The Broken Access Control Playbook
- XXE for CTF: XML External Entity Attacks
- Web Recon for CTF: robots.txt, Page Source, DevTools, and Hidden Endpoints
- SSRF for CTF: From localhost Pivots to Cloud Metadata
- Insecure Deserialization for CTF: Pickle, __reduce__, and RCE
- Server-Side Template Injection for CTF: Detection, Gadgets, and Filter Bypass
- Python Sandbox Bypass for CTF: The Filter-Breaker Playbook
- LFI for CTF: From /etc/passwd to RCE
- Burp Suite for picoCTF: From Proxy Setup to Repeater Tricks
- XSS for CTF: A Ladder from alert(1) to CSP Bypass
- Command Injection for CTF: From Ping Boxes to Blind Exfil
- What picoCTF Web Challenges Teach You About Real Bugs in Production
- Cookie and JWT Attacks for CTF Web Challenges (picoCTF Guide)
- SQL Injection for CTF: From Authentication Bypass to Data Extraction
- Networking Tools for CTF Challenges
Forensics
- The picoCTF Forensics Roadmap: file, strings, and Everything After
- USB and HID PCAP Forensics for CTF: Reconstructing Keystrokes
- Image Metadata and EXIF Forensics for CTF
- Audio Steganography and Spectrograms for CTF Forensics
- File Carving and Magic Bytes: Repairing Corrupted Files for CTF
- CTF Disk Forensics: What to Do When Strings Returns Nothing
- When strings Won't Cut It: Volatility 3 for CTF Memory Forensics
- Wireshark and pcap Analysis for CTF Forensics
- Steganography Techniques for CTF Competitions
- Introduction to Steganography Tools for CTF
Reverse engineering
- The picoCTF Reverse Engineering Roadmap: From Disassembly to Decompiler
- Go and Rust Binary Reversing for CTF: Taming the Fat Binary
- radare2 and rizin for CTF: A Beginner's Workflow
- ARM Assembly for CTF: The ARMssembly Series
- Java Reverse Engineering for CTF: Decompiling JARs and the Vault Door Series
- x86-64 Assembly for CTF: Reading Disassembly From Scratch
- Python Reversing for CTF: Bytecode, Frozen Binaries, and Obfuscated Scripts
- Android APK Reverse Engineering for CTF: From .apk to Flag
- angr from First Principles: A picoCTF Tutorial for Beginners Tired of Magic
- Frida and Binary Instrumentation for CTFs: A Beginner's Path
- Using GDB for CTF Reverse Engineering
- How to Use Ghidra for Reverse Engineering CTF Challenges
Binary exploitation
- The picoCTF Binary Exploitation Roadmap: Stack to Heap to ROP
- SROP and ret2dlresolve: Advanced ROP Without a libc Leak
- Use-After-Free for CTF: Dangling Pointers and tcache
- ret2libc for CTF: Leaking libc and Returning to system()
- Stack Canary Bypass for CTF: Leak It, Brute It, or Walk Around It
- Writing x86-64 Shellcode for CTF: From Syscall to Shell
- pwntools for CTF: A Foundational Guide from import to Shell
- Heap Exploitation for CTF: From heap Overflow to tcache Poisoning
- ROP Beyond ret2libc: The Gadget Ladder for CTF Exploitation
- Bypassing ASLR and PIE in CTF Binary Exploitation (picoCTF Guide)
- Format String Vulnerabilities for CTF Binary Exploitation
- Buffer Overflow and Binary Exploitation for CTF
Tooling and workflow
- Setting Up a CTF Environment: WSL, Linux, Docker, and the Core Toolkit
- Bash Scripting for CTF Automation: Loops, Pipes, and Brute-Force Harnesses
- NoSQL Injection for CTF: Bypassing Login Without SQL
- Recipe Chain: Decode Multi-Layer CTF Encodings Without CyberChef
- Linux Privilege Escalation for CTF
- Smart Contract CTF: Four Bugs That Already Drained Mainnet
- Python for CTF: Essential Scripting Techniques
- File Upload Exploitation