Cereal – CTF

I’ve not created a new box for some time, so I spent my time today making a new one for you all!

This one is quite different from my normal machines. It’s probably more realistic and less like a CTF. I’m going to stop grading my boxes though because what’s difficult to one person is easy to another and vice versa. If you find this difficult, don’t be put off. This is simply a learning step which everyone at some point crosses. This box is probably hard though – it’s certainly not for beginners. I hope you learn something new.

Take your time. Have patience. And take time to learn about the environment once you pop the initial shell.

When I first published this CTF, I offered a prize for one three month TryHackMe voucher to the first person who successfully completed the box and submitted a valid walkthrough. This prize has now been claimed.


You can download Cereal here (version 1.1, fixed issue with DHCP in VMWare).

SHA-256: 9aa01288b184174ce70a81288d1f2eeb685ab34dbaba4d6efcfd843a18d86e66

How did you find Cereal?

Insanity – CTF

Welcome to Insanity – my fifth CTF. There is one flag on this CTF. Your objective is to gain root access.

Download Now

This CTF is rated as 5/5 for difficulty. What makes this CTF difficult is not necessarily the types of vulnerabilities you will find – instead, it’s the process of exploiting them. DHCP is enabled – this CTF has been tested on VirtualBox only, though I don’t think there’ll be issues if you run it with VMWare.


A web hosting provider has asked you to test their security. Can you find the vulnerabilities on their server and gain root access? If anyone wants to submit a written report for this, I’d give it a read and potentially publish it on this blog! 🙂

Note about hints

Please note, I will not be giving out hints for this CTF until at least the 30th August 2020. Try harder.

Edit: A few people have joined my Discord Server to share information (which is absolutely fine). Feel free to join and discuss ways to hack this CTF.

Download now

You can download Insanity here.

SHA-256: 75819bda88013d13465c9ec4145d56470378450e8c6c0c6faa8c72503a049850

How hard did you find Insanity?

