← Back to Home
CTF Competitor
Learning roadmap untuk menguasai CTF competitions
Phase 1
Getting Started
Linux & Command Line
Bash, file manipulation, permissions, piping, grep/awk/sed
Python Scripting
Scripting for automation, pwntools, requests library, socket programming
Number Systems & Encoding
Hex, binary, octal, Base64, URL encoding, ASCII table
Basic Networking
TCP/IP, DNS, HTTP, Wireshark packet analysis fundamentals
CTF Platforms & Format
Jeopardy-style vs Attack-Defense, flag formats, scoring, team dynamics
Phase 2
Web Exploitation
SQL Injection
Union, blind, error-based SQLi, filter evasion, NoSQL injection
Cross-Site Scripting (XSS)
Reflected, stored, DOM XSS, cookie stealing, CSP bypass
Server-Side Vulnerabilities
SSTI, SSRF, LFI/RFI, command injection, path traversal
Authentication Attacks
Session fixation, JWT cracking, cookie manipulation, brute force
Deserialization & Advanced
PHP/Python/Java deserialization, prototype pollution, race conditions
Phase 3
Cryptography
Classical Ciphers
Caesar, Vigenere, substitution, transposition, frequency analysis
Modern Symmetric Crypto
AES (ECB/CBC/CTR), DES, block cipher attacks, padding oracle
Asymmetric Cryptography
RSA attacks (small e, Wiener, Hastad), Diffie-Hellman, ECC basics
Hashing
MD5/SHA collisions, length extension, hash cracking, rainbow tables
Crypto Implementation Flaws
Weak RNG, timing attacks, reused nonces, custom crypto analysis
Phase 4
Binary Exploitation (Pwn)
x86/x64 Assembly
Registers, instructions, calling conventions, stack frames
Buffer Overflow
Stack smashing, return address overwrite, NOP sled, shellcode
Return Oriented Programming
ROP chains, gadget finding, ret2libc, ret2plt, GOT overwrite
Format String Attacks
Arbitrary read/write, GOT overwrite via format strings
Heap Exploitation
Use-after-free, double free, tcache poisoning, heap feng shui
Protections & Bypass
ASLR, NX, Stack canaries, PIE, RELRO -- bypass techniques
Phase 5
Reverse Engineering
Static Analysis
IDA Pro, Ghidra, Binary Ninja -- disassembly and decompilation
Dynamic Analysis
GDB, ltrace, strace, debugging techniques, breakpoints
Anti-Reverse Techniques
Obfuscation, packing (UPX), anti-debug, VM detection
Binary Formats
ELF, PE structure, sections, imports/exports, symbol resolution
Advanced RE
.NET/Java decompilation, Android APK reversing, firmware analysis
Phase 6
Forensics & Misc
File Analysis
Magic bytes, binwalk, file carving, steganography, metadata
Memory & Disk Forensics
Volatility, Autopsy, file system analysis, deleted file recovery
Network Forensics
PCAP analysis, protocol reconstruction, traffic pattern analysis
Steganography
LSB encoding, image/audio stego, zsteg, stegsolve, spectrograms
OSINT
Metadata extraction, social media recon, geolocation, Wayback Machine
Essential Tools
Explore our tools for your research
tools.redlimit.id
