Challenge Category

Pwn CTF Challenges

Buffer overflows, ROP & modern exploit development.

Round duration

12 hours

Format

Jeopardy-style CTF

Team size

1–3 members

Pwn is exploit development. You are handed a binary running on a remote service, and your job is to give it input that makes it do something it should not — most often hand you a shell. Nothing here is a puzzle in the usual sense; it is a sequence of precise engineering decisions about memory layout, control flow and permissions.

The category is the steepest learning curve on the board, and it is worth being honest about that. Solving a mid-difficulty heap challenge on your first day is not realistic. What is realistic is that the easiest pwn challenges are approachable within a couple of weeks of preparation, and that the underlying skills transfer directly to vulnerability research and security engineering.

If you want a fast start, the entire discipline fits in one sentence: control the instruction pointer, then chain useful code you did not write. Everything else is detail.

What you’ll actually face

Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.

Stack overflows

Classic buffer overflows where a long input overwrites the saved return address. The foundation skill, and still the basis of most easy challenges.

ROP chains

Return-oriented programming to defeat non-executable stacks — chaining gadgets to call `execve("/bin/sh", NULL, NULL)` without ever executing injected shellcode.

Format string bugs

Unvalidated format specifiers in `printf` leaking stack memory or granting an arbitrary write through `%n`. Enormous information leak for comparatively little effort.

Heap exploitation

Use-after-free, double free and off-by-one bugs against `ptmalloc`, requiring careful reasoning about chunk metadata and allocator state.

Mitigation bypass

Defeating ASLR, stack canaries, NX and RELRO — by leaking a libc address, or by finding a function that discloses the canary for us.

Race conditions

TOCTOU bugs where a check and a use are separated in time, exploited with threads or by winning the scheduling window.

Tools you’ll reach for

  • pwndbg (GDB)
  • pwntools
  • checksec
  • ROPgadget / ropper
  • Ghidra
  • one_gadget
  • strace / ltrace
  • Docker (for local instances)

How to prepare

None of this is required to enter — it is simply the shortest path to scoring points in this discipline.

  1. Complete the classic `pwn.college` or picoCTF reverse/exploit track. Both are free and structured.

  2. Learn pwntools properly rather than scripting by hand — `remote`, `recvuntil` and the ROP builder save hours per challenge.

  3. Run `checksec` on every binary before you analyse it. Knowing which mitigations are enabled decides your whole approach.

  4. Write the full ret2libc chain at least five times by hand. Once you can do it without documentation, everything above it becomes approachable.

  5. Set up Docker so you can pull the challenge binary locally and debug against your own instance instead of the shared server.

Quick facts

Everything about Ghost Protocol CTF 2.0 at a glance.

Online qualifier
17 October 2026 · 12 hours · remote
Grand finale
24 October 2026 · 12 hours · on-ground
Format
Jeopardy-style CTF
Team size
1–3 members (solo entry allowed)
Registration fee
Free per team
Prize pool
Up to ₹51,000
Challenge categories
10 disciplines
Eligibility
Any student in an undergraduate or postgraduate programme, any stream
Venue
NIET Greater Noida
Organised by
Cyber Invaders · NIET Greater Noida

Ready to prove it on the scoreboard?

Pwn is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.