Pwn CTF Challenges
Buffer overflows, ROP & modern exploit development.
Round duration
12 hours
Format
Jeopardy-style CTF
Team size
1–3 members
Pwn is exploit development. You are handed a binary running on a remote service, and your job is to give it input that makes it do something it should not — most often hand you a shell. Nothing here is a puzzle in the usual sense; it is a sequence of precise engineering decisions about memory layout, control flow and permissions.
The category is the steepest learning curve on the board, and it is worth being honest about that. Solving a mid-difficulty heap challenge on your first day is not realistic. What is realistic is that the easiest pwn challenges are approachable within a couple of weeks of preparation, and that the underlying skills transfer directly to vulnerability research and security engineering.
If you want a fast start, the entire discipline fits in one sentence: control the instruction pointer, then chain useful code you did not write. Everything else is detail.
What you’ll actually face
Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.
Stack overflows
Classic buffer overflows where a long input overwrites the saved return address. The foundation skill, and still the basis of most easy challenges.
ROP chains
Return-oriented programming to defeat non-executable stacks — chaining gadgets to call `execve("/bin/sh", NULL, NULL)` without ever executing injected shellcode.
Format string bugs
Unvalidated format specifiers in `printf` leaking stack memory or granting an arbitrary write through `%n`. Enormous information leak for comparatively little effort.
Heap exploitation
Use-after-free, double free and off-by-one bugs against `ptmalloc`, requiring careful reasoning about chunk metadata and allocator state.
Mitigation bypass
Defeating ASLR, stack canaries, NX and RELRO — by leaking a libc address, or by finding a function that discloses the canary for us.
Race conditions
TOCTOU bugs where a check and a use are separated in time, exploited with threads or by winning the scheduling window.
Tools you’ll reach for
- pwndbg (GDB)
- pwntools
- checksec
- ROPgadget / ropper
- Ghidra
- one_gadget
- strace / ltrace
- Docker (for local instances)
How to prepare
None of this is required to enter — it is simply the shortest path to scoring points in this discipline.
Complete the classic `pwn.college` or picoCTF reverse/exploit track. Both are free and structured.
Learn pwntools properly rather than scripting by hand — `remote`, `recvuntil` and the ROP builder save hours per challenge.
Run `checksec` on every binary before you analyse it. Knowing which mitigations are enabled decides your whole approach.
Write the full ret2libc chain at least five times by hand. Once you can do it without documentation, everything above it becomes approachable.
Set up Docker so you can pull the challenge binary locally and debug against your own instance instead of the shared server.
Quick facts
Everything about Ghost Protocol CTF 2.0 at a glance.
- Online qualifier
- 17 October 2026 · 12 hours · remote
- Grand finale
- 24 October 2026 · 12 hours · on-ground
- Format
- Jeopardy-style CTF
- Team size
- 1–3 members (solo entry allowed)
- Registration fee
- Free per team
- Prize pool
- Up to ₹51,000
- Challenge categories
- 10 disciplines
- Eligibility
- Any student in an undergraduate or postgraduate programme, any stream
- Venue
- NIET Greater Noida
- Organised by
- Cyber Invaders · NIET Greater Noida
Adjacent disciplines
Competitors in CTF teams tend to specialise — here is where the skills overlap.
Ready to prove it on the scoreboard?
Pwn is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.