SHELLBREAK CTF ARENA
๐Ÿ“ Files Repository Go to Main CTF Platform โ†’

$ shellbreak --live-challenge-arena

Live target environments for practicing web application exploitation, memory corruption, and reverse engineering.

โ— Lab Active
Inactivity Auto-Sleep in: 20:00
๐ŸŒ Live Web Application Targets
Easy ยท 10 Pts Port 8001 / sqli
SQL Injection 101
Bypass administrative login authentication by abusing SQL comment and logical OR syntax.
Open Challenge Target โ†’
Easy ยท 15 Pts Port 8002 / xss
Reflected XSS
Inject malicious JavaScript into the search query parameter to steal the simulated administrator session cookie.
Open Challenge Target โ†’
Medium ยท 30 Pts Port 8003 / cmd
Command Injection
Exploit a ping diagnostic utility that executes shell commands without input sanitization to read /flag.txt.
Open Challenge Target โ†’
Medium ยท 40 Pts Port 8004 / idor
Insecure Direct Object Reference (IDOR)
Manipulate predictable employee IDs in the query parameters to access confidential executive salary and secret records.
Open Challenge Target โ†’
Hard ยท 80 Pts Port 8005 / lfi
Local File Inclusion (LFI)
Abuse path traversal to read system files from the root filesystem and poison web server logs for Remote Code Execution.
Open Challenge Target โ†’
Downloads Nginx / ctf-files
Downloadable Artifacts
All 60 downloadable challenge files (PCAP captures, Android APKs, memory dumps, disk images, stego images).
Browse All Files โ†’
๐Ÿ’ฅ Live Binary Exploitation (PWN) Targets
Buffer Overflow 101
nc 168.138.69.155 10001
Ret2Win (Stack Return)
nc 168.138.69.155 10002
Shellcode Runner (NX Disabled)
nc 168.138.69.155 10003
Format String Leak
nc 168.138.69.155 10004
Integer Overflow Store
nc 168.138.69.155 10005
Ret2Libc (Bypass NX)
nc 168.138.69.155 20001