DEF CON Hacking Conference

CTF Archive

Image of DEF CON logo pirate flag.

This page is devoted to collecting accounts, walk throughs and other resources of Capture the Flag at DEF CON over the years, not only for history's sake but so the uninformed can better grasp the epic journey that teams must face on the road to CTF victory!

If you know of a resource that should be included on this page, feel free to pass it along to neil ]at[ defcon [dot] org.

2016 DEF CON CTF Final Scores!

From the Legit BS blog:

We are pleased and honored to announce the results of DEF CON CTF 2016.

Team Final Score
PPP 113555
b1o0p 98891
DEFKOR 97468
HITCON 93539
KaisHack GoN 91331
LC↯BC 84412
Eat Sleep Pwn Repeat 80859
binja 80812
pasten 78518
Shellphish 78044
9447 77722
Dragon Sector 75320
!SpamAndHex 73993
Mayhem 72047

Congratulations to our top three teams PPP, b1o0p, and DEFKOR. We would also like to congratulate all competing teams for spectacular performances all around. This year’s game was a drastic departure from previous DEF CON CTF games, and we appreciate the sacrifices you made to compete in it. Finally, we would in particular like to congratulate Mayhem, from For All Secure, for their spectacular performance as the first autonomous computer system to play DEF CON CTF. While Mayhem did finish in last place, many times throughout the game it was able to pull ahead of human teams.


At DEF CON, we noticed that contrary to what was communicated to some teams, proofs-of-vulnerability (PoVs) were not being re-run in successive rounds after submission. Since this was an error on our part, we committed to fixing them up after the fact, which took longer than expected.


In the coming days, we have more data we will be releasing:

• Complete SQL dump of game state, both the during-DEF CON game run, and the post DEF CON game run that corrected some scoring issues
• Complete source code of the game engine
• Complete source code of challenges
• Additional infrastructure and tooling for running CGC challenges
• Packet captures from the rescoring run


Once again, thanks for everyone who helped make DEF CON CTF a reality this year: our fifteen finalist teams, everyone who played in qualifiers, DEF CON goons, DEF CON staff, and the CTF community around the world. See you in 2017!


Collection of write up links from epochfailctf:

BabyCmd Write-Up from sysexit:

BabyCmd and MathWhiz Write-up from Lockboxx:

Multiple challenge Write-up from piyolog (japanese):

ShitCpu Write-up from libmaru @ Blue-Lotus:

Mathwhiz Write-up from VulnHub CTF Team:

Babyecho Write-up from VulnHub CTF Team:

r0pbaby Write-up from SkullSecurity:

Access Control Write-up from SkullSecurity:

Coding 1 Write-up by Fritz’s Lair:

BabyEcho Write-up by GeekSpeak Team Blog:

Access Control Write-up from Capture the Swag:

BabyCmd Write-up from Boogy’s Binary Lifestyle:

Babyecho Write-up from Boogy’s Binary Lifestyle:

fuckup Write-up from badfood CTF:

cat western Write-up from blackcon:


Complete Packet Captures from DEF CON 22 CTF: Torrent Torrent Icon (~170 GB)

DEF CON 22 Capture the Flag Write-ups

Legitimate business syndicate recap:

PPP Blog 2014 Post-mortem:

Routards blog:

Stratum0 blog 2014 recap:

DEF CON 22 Quals Write-ups

Hack UCF:







DEF CON 21 Capture the Flag Pcaps, Binaries and Tools

Binaries and Tools: Torrent Torrent Logo

Friday Packet Captures: Torrent Torrent Logo
Saturday Packet Captures: Coming Soon!
Sunday Packet Captures: Coming Soon!

DEF CON 21 Capture the Flag Write-ups

CNBC Article - Cyberteams duke it out in the World Series of Hacking

LegitBS Blog - Final Writeup:

LegitBS Blog - Public Handout:

Routards Team Blog - Defcon 21 CTF:

Routards Team Blog - Defcon 21 CTF - Binaries and environment:

DEF CON 21 Quals Write-ups

If you'd like to re-live some of the excitement from the quals, you can check out a few of these write-ups from around the internetosphere:

Team Alternatives:

X-N2O's Blog:

Stalkr's Blog:

Blue Lotus:

Leet More CTF Team Blog:

Here's a great collection of write-ups:

DEF CON 20 Capture the Flag Write-ups

The Awesome Reddit Ask Me Anything thread from Samurai CTF

From the Routards Team Blog

Wireshark goodness from the NYU Poly ISIS Lab

Wireshark Exploit writeup from 0xDEADBEEF

From the SiBears Blog

Bonus writeup for those who can read Russian:

Results announcement for CTF at DEF CON 20 - YouTube

DEF CON 20 Capture the Flag Quals Write-ups

DC 20 Quals Writeups:

Quals Graph:

DDTek Quals Scoreboard

Defcon 20 - Quals Writeup Collection from CTF Central
Links below are from the above link.












binary l33tness










grab bag




Writeups Collection:

Quals files dumps:

urandom 200:

urandom 400:

DEF CON 19 Capture the Flag Write-ups

Plaid Parliament of Pwning write up

Routards Blog

DEF CON 19 Capture the Flag Quals Write-ups

Challenge repository at

Several write-ups at

Binary 100 (Espanol)

Forensics 100

Forensics 300

Grab Bag 100

Grab Bag 200 (Espanol)

Retro Revisited 300

Retro Revisited 500

Potent Pwnables 300

DEF CON 18 Capture the Flag Quals Wrap-up

Unofficial Results from DEF CON 18 CTF Quals:

Video - pwning binary 300 at DEF CON 18 CTF quals:

Write-ups for DEFCON 18 CTF Quals, including Trivia 500, Packet Madness 200, Binary L33tness 300, Pwtent Pwnables 200, Forensics 100, Forensics 400, and Forensics 500, and more to come:

PT400 Walkthrough:

Pwtent Pwnables 200 Write Up:

Packet 100 Write Up:

Forensics 200 Write Up

Crypto 400 Write Up: Team: gn00bz

Defcon ctf quals trivia 500 music remix version volume up plz!! from wowhacker

French Language Write Up: (en français)