How I Conquered 27 CTF Challenges at a Professional Cybersecurity Conference (And Clapped for Every…
A story of binary, brute force, hex-encoded coins, and a lot of clapping.
How I Conquered 27 CTF Challenges at a Professional Cybersecurity Conference (And Clapped for Every Single Flag 🎉)
A story of binary, brute force, hex-encoded coins, and a lot of clapping.

At southeast birmingham cyebr security conference
It was 09:00 AM on April 16, 2026. I walked into the Birmingham Jefferson Convention Complex for the Southeast Cybersecurity Summit, badge around my neck, Kali Linux ready, and absolutely zero chill.
Surrounding me were professionals from IT companies I’m actively trying to work at. And in the corner of the exhibit hall? A glowing MetaCTF leaderboard. 35 challenges. Two days. One mission.
My teammate Drew Brasher was with me. We looked at each other. Let’s go.
By the end of it, I had personally solved 27 out of 29 challenges our team completed. Drew handled 2. Every single time I got a flag — and I mean every single time — I clapped. Once. Twice. The whole room started noticing. My teammates were laughing. This is the story of how that happened.
The Setup: Tools of War
Before I walk you through the challenges, here’s what I had loaded up:
- Kali Linux — my home base for everything
- Dencode.com — for encoding/decoding anything thrown at me
- CyberChef — the Swiss Army knife of CTF
- Wireshark — for packet analysis
- Burp Suite — web exploitation all day
- John the Ripper — cracking passwords like it’s nothing
- Wayback Machine + GitHub repos — for OSINT and research
- Claude + ChatGPT — yes, AI was in the toolkit. We use every weapon available.
Now let’s get into it.
Round 1: The Warmups (Because You Have to Start Somewhere)
🟢 What’s a CTF? — 25 pts
“In a typical CTF, Capture the Flag competitors use a computer to solve challenges…”
The meta challenge. They literally gave you points for knowing what a CTF is. I read it, smiled, submitted. First flag. First clap. 👏
🟡 Binary Gossip — 100 pts
“My coworkers started emailing each other with this weird looking code, can you figure out what they’re saying?”
They gave us a wall of binary:
01001101 01100101 01110100 01100001 01000011 01010100 01000110...
Binary to ASCII. Dencode.com. Done in under 2 minutes. The flag was hiding in plain sight inside the binary — literally MetaCTF{h3_h1t_th3_b4l1_4nd_g0t_t0_s3c0nd_b453}. A softball joke hidden in binary. Cheeky.
Clap. 👏
🟡 Online Solicitation — 100 pts
“My coworkers started teaching each other with this weird looking code…”
Another encoding challenge with a long block of numbers. Ran it through multiple decoders on Dencode. Decimal → ASCII. Flag extracted. Quick win.
Clap. 👏
🟡 Vulnerability Museum — 125 pts
CVEs. Common Vulnerabilities and Exposures. They wanted me to identify a specific CVE from a description. This is where my Security+ training kicked in hard. Looked it up, cross-referenced, got the flag format right.
Clap. 👏
Round 2: Web Exploitation — My Playground
🟠 Bank Heist — 175 pts
“You’ve been hired by a bank to test the security of their web app. Can you log in successfully? The correct password is the flag.”
I fired up Burp Suite. Intercepted the login request. Checked for SQL injection first — classic ' OR 1=1-- type stuff. Poked around the app structure. Found a way in. The password WAS the flag. Beautiful.
Clap. 👏
🟠 Server Sleuthing — 175 pts
“You’ve been tasked with testing the security of this Electricity Substation management portal. Can you figure out what programming language and version are used to run this app?”
HTTP headers. That’s it. Burp Suite, look at the server response headers, find the X-Powered-By or Server header. The programming language and version were sitting there in plain text. People overthink these. Sometimes the answer is right in the response.
Clap. 👏
🟠 Headerless — 200 pts
“During our forensic investigation, we found a corrupted file. It appears the header is completely missing. Can you repair it?”
This one was forensics meets web. Downloaded the file. Opened it in a hex editor. Identified what file type it was supposed to be by its partial structure. Added the correct magic bytes back at the start of the file. Opened it. Flag was inside.
Every file type has a signature — a “magic number” at the very beginning. JPEGs start with FF D8 FF. PNGs start with 89 50 4E 47. Once you know what you're looking for, corrupted files become puzzles, not problems.
Clap. 👏
🟠 No Flag Here — 250 pts
“Look, I’m telling you, there’s no flag here. See for yourself!”
Oh they were lying. They were absolutely lying.
View source. Check comments. Check metadata. Check hidden elements. Check image EXIF data. Somewhere in there was a flag pretending not to exist. This is the classic CTF “steganography meets web” challenge. Found it hiding where they said nothing would be.
Clap. 👏
🔴 Industrial Seals — 275 pts
“Can you pentest the webapp of this seal manufacturer, and break the seal on their confidential data? The source code is here.”
White box pentest. They gave me source code. I read through it carefully looking for authentication flaws, insecure direct object references, or improper authorization checks. Found a vulnerability in how the app handled user roles. Exploited it to access confidential data. Flag extracted.
Burp Suite + careful source code reading = this challenge cracked.
Clap. 👏
🔴 Mass Assignment — 300 pts
“Being an admin these days is much easier than before!”
Mass assignment vulnerability. This is where a web app blindly accepts all fields from user input and assigns them to an object — including fields like isAdmin: true that should never be user-controlled.
Sent a crafted POST request with the admin flag embedded. The app trusted me. It shouldn’t have. I was admin now. Flag retrieved.
Clap. 👏
Round 3: Cryptography — Cracking Codes
🟡 DES Moines — 275 pts
“Those long key lengths on modern ciphers are so annoying. Who has room for eight bytes, let alone 32 or more? Thankfully, this cipher’s key is just seven bytes long!”
DES (Data Encryption Standard) with a 7-byte key. They gave me:
- Key:
169d713d28c61b - Ciphertext:
2165969caff730acd03067ccd2af366a...
Decoded using DES decryption with the provided key. CyberChef handled this cleanly. The old cipher cracked open like it had no choice.
Clap. 👏
🔴 Nonceless — 300 pts
“I’ve encrypted the flag with AES-CTR and thrown away the nonce. Good luck decrypting it!”
AES-CTR without a nonce. This is actually exploitable because CTR mode turns a block cipher into a stream cipher — and stream ciphers reusing a nonce (or using a zero nonce) are vulnerable to known-plaintext attacks.
Analyzed the script they provided. Worked out the keystream. XOR’d my way to the flag. This one required actual cryptographic thinking, not just tool usage.
Clap. 👏
🟡 Tax Season — 200 pts
“I was in the process of filing my taxes and put a password to keep them protected. Unfortunately, I’ve forgotten the password! I know it’s 4 digits…”
John the Ripper. Password is 4 digits = maximum 9999 combinations. Generated a wordlist of all 4-digit numbers and fed it into JtR. The PDF cracked in seconds. Flag was inside the tax form.
This is why “1234” is not a password.
Clap. 👏
Round 4: Forensics — Finding What’s Hidden
🟠 Msg Packed — 250 pts
“I found this weird file, and have no idea how to read the message inside. I think it might have something to do with packing?”
MessagePack format. It’s a binary serialization format — like JSON but compressed. Unpacked it using the right Python library, read the contents. Flag was in the data structure.
Clap. 👏
🔴 Block in the Wall — 300 pts
“Can you take a look at this packet capture and see what was transferred? We were analyzing a strange program’s activity on a VM.”
Wireshark time. Opened the PCAP file, filtered through the traffic. Found suspicious data being transferred in what looked like encrypted or encoded blocks. Reassembled the stream, decoded the content. Flag reconstructed from the transferred data.
Clap. 👏
🔴 C2 Defaults — 325 pts
“A script kiddie exfiltrated a flag over the network using an open-source C2 server… Can you piece together the flag from the captured traffic?”
Another PCAP but this time with C2 (Command and Control) traffic. Identified the C2 framework being used from the traffic patterns and default configurations. Once I knew the C2 tool, I knew how it structured its communications. Pieced the flag together from the exfiltrated packets.
The irony of a “script kiddie” challenge requiring legitimate threat hunting skills was not lost on me.
Clap. 👏
🟡 Headerless (Bonus Forensics angle) & Hidden File Challenges
Multiple challenges across the event tested whether you could look beyond the obvious. Metadata in images, hidden data in files, steganography, EXIF data — I went through all of it methodically. Each one fell.
Round 5: Reverse Engineering — Reading Machine Language
🟠 Wow A Superb Machine — 250 pts
“I’m tired of all the flag checkers being done in ELF files, check out this new one here.”
Not an ELF. Something different. Downloaded the binary, ran file command on it, identified the architecture. Reverse engineered the flag checking logic. Understood what input would make it output success. Gave it exactly that.
Clap. 👏
🔴 Trojan — 275 pts
“I ran what seemed to be a safe app on my desktop… now my files are encrypted. Download the artifacts here.”
Ransomware reverse engineering. Decompressed the artifact (password: infected), analyzed the encryption routine. Understood how it encrypted files, reversed the process to decrypt them. Flag recovered from what was once "encrypted."
This one hit different as a cybersecurity student. Ransomware in the wild is no joke — but understanding it deeply is how you fight it.
Clap. 👏
🔴 Love Overflowing — 350 pts
“Welcome to the Love Confession Booth! Download the binary and confess your love with nc kubenode.mctf.io 31020”
Buffer overflow. The name literally told you. Downloaded the binary, analyzed the stack layout in Ghidra/GDB, found the overflow point, crafted the payload to overwrite the return address and redirect execution. Then connected to the live server and sent my “love confession.”
The server gave me the flag. Worth every byte.
Clap. 👏
🔴 Barry B. Benson — 450 pts (the boss fight)
“We ran bpftool prog on the control server for the Krelman…”
The highest point challenge. eBPF (extended Berkeley Packet Filter) reverse engineering. They gave me an XDP program dump and a live server at 3.91.247.250.
eBPF programs run inside the Linux kernel. This was kernel-level reverse engineering at a CTF. Read the prog dump, understood the XDP packet filtering logic, figured out how data was being exfiltrated through crafted network packets, and interacted with the live server to extract the flag.
This was the hardest challenge I solved. It required understanding Linux kernel internals, network packet structure, and eBPF bytecode — all at once.
When that flag came through? I didn’t just clap. I clapped twice.
👏👏
The OSINT Round: The Other Meta — 300 pts (Drew’s solve!)
“The other Meta uploaded this video to Instagram the other day, where exactly was it taken? The flag is the latitude and longitude.”
This is where my teammate Drew Brasher stepped up. Pure OSINT — analyze video metadata, look for location clues in the frame, cross-reference with Google Maps or Wayback Machine. He nailed the coordinates down to the required 4 decimal places of precision.
Drew’s moment. Deserved.
Final Score & What It Meant
My solves: 27 Drew’s solves: 2 Team total: 29 out of 35 Team placement: 2nd overall 🥈
We walked out with a Skillbit Challenge Coin — numbered 032, 2026. The back is encoded in hex. I haven’t decoded it yet. Maybe that’s the final challenge.

Top individual’s point breakdown
What This Experience Taught Me
1. Breadth beats depth in CTF — You need to know a little about everything. Binary, web, crypto, forensics, reverse engineering. Specialists get stuck. Generalists keep moving.
2. Tools are multipliers, not magic — Wireshark, Burp, John the Ripper, CyberChef — they only work if you understand what you’re looking for. I used AI too, as a thinking partner, not an answer machine.
3. Conference CTFs hit differently — Competing while surrounded by actual industry professionals adds a layer of pressure and motivation that online CTFs don’t have. Every flag felt earned.
4. Celebrate every win — Yes, I clapped every time I got a flag. My teammates laughed. But those claps kept the energy up across two full days of grinding. Never stop celebrating progress, no matter how small.

If you enjoyed this article and want more cybersecurity tips and hands-on labs, follow me for the latest guides and challenges! 🔒🖧
메타데이터
- post_id
- 0a1dd38ebbbc
- slug
- how-i-conquered-27-ctf-challenges-at-a-professional-cybersecurity-conference-and-clapped-for-every-0a1dd38ebbbc
- url
- https://medium.com/@chaitanyagarware/how-i-conquered-27-ctf-challenges-at-a-professional-cybersecurity-conference-and-clapped-for-every-0a1dd38ebbbc
- canonical_url
- https://medium.com/@chaitanyagarware/how-i-conquered-27-ctf-challenges-at-a-professional-cybersecurity-conference-and-clapped-for-every-0a1dd38ebbbc
- author_url
- https://medium.com/@chaitanyagarware
- status
- ok
- fetched_at
- 2026-07-11 03:42:06