ARKX Ninja CTF Overview
Collection of ARKX Ninja CTF write-ups from the Beginner, Advanced, and Expert tracks.
Available Materials
Section titled “Available Materials”- 01 File Manager Hidden flag copied into the readable archive via import_file
- 02 Lost Archives Path traversal on list_files and read_file left the sandbox
- 03 Magic Door Passkey leaked through a base64 transform after plaintext refusals
- 04 Mailman Retrieved mail marked DECLASSIFIED and leaked the flag in metadata
- 05 Network Ninja Command injection in a ping tool, constrained to ls and cat
- 06 Scheduler Weekend-only maintenance enforced by the model, not the tool
- 07 Bad Robot Code injection through unsafe evaluation
- 08 Blind Network Ninja Blind OS command injection via newline, using a boolean oracle
- 09 Master of Resources Broken authorization on Model Context Protocol (MCP)
- 10 Mastermind PIN oracle with no rate limit
- 11 The Archivist A confidential document and a user ask overrode redaction
- 12 The Context Gateway (Advanced) Health-check debug dump leaked a hidden scan mode
- 13 The Enemy Within fetch_url followed user URLs onto loopback and read flag.txt
- 14 The Magic Door (Advanced) Supervisor role-play made the gatekeeper call open_sesame
- 15 The Silent Transmission DLP on flag- bypassed by stuffing the secret into an OAST hostname
- 16 Lost Archives: Part 1 WAF-style path filter bypassed with URL encoding after the check
- 17 Lost Archives: Part 2 copy_file reowned an admin flag as user and bypassed the vault
- 18 Manager Maintenance fallback let transfers skip check_approval
- 19 The Heist TOCTOU / race condition (double-spend) in agent tool execution
- 20 The Octopus Multi-agent broken authorization and cache poisoning
- 21 The Shape Shifter Insecure YAML deserialization leading to remote code execution
- 22 Trojan Horse A support ticket poisoned the knowledge base and leaked the flag
No matches
Try a different search term or category filter.
Showing 1–10 of 22
Page 1 of 3