ROUND 1 INFILTRATION GATEWAY: ONLINE â€ĸ 20 TEAMS ADVANCE

SLIIT CYBER SECURITY CTF 2026

Operation Zero-Gate — The elite Hack-to-Register qualification tournament for undergraduate security researchers. Registration is not given; it must be breached.

T-MINUS TO QUALIFICATION DEADLINE (NOV 15, 2026)
00 Days
00 Hours
00 Minutes
00 Seconds
Breach Gateway 🔑 Submit Token
Round 1 Contenders Live Stream 24 Teams Enlisted
terminal@sliit-secops:~ (Interactive CTF CLI)
[+] SLIIT CTF 2026 Core Gateway Daemon Initialized. [*] Tournament Name: Operation Zero-Gate (Round 1 Qualifiers) [*] Target Audience: SLIIT Faculty of Computing Undergraduate Cyber Security Students. [*] Qualification Mode: Hack-to-Register (Top 20 Teams Advance to Grand Finals). Type 'help' or click the command chips below to query the CTF gateway.
Quick:
root@zero-gate:~$
THE TOURNAMENT LORE

Why Fill a Form When You Can Breach the Gate?

Traditional capture-the-flag competitions begin with an open Google Form. Operation Zero-Gate redefines cybersecurity qualification at SLIIT. Built by the Department of Cyber Security, our registration portal is locked behind an impenetrable defensive architecture.

To register, your team must orchestrate a live 6-phase cyber kill-chain: decipher raw TCP port knocking, bypass proof-of-work rate limiters, exploit Blind SSRF in a corporate diagnostics utility, reconstruct corrupted binary headers, bypass Linux anti-debugging routines, and extract cryptographic keys hidden inside image pixels.

20 Slots for Finals
6 Progressive Stages
1–4 Members per Team
ARCHITECTURE TOPOLOGY ENCRYPTION: AES-256 / SHA-256
⚡ [Perimeter] Port Knocking Firewall
TCP 1337-7331-31337
đŸ›Ąī¸ [Gate] Raw TCP PoW Socket
Port 9001 (5s Timeout)
📡 [Web] Blind SSRF & Core Vault
HTTP Port 8080
🧩 [Binary] Anti-Debug ELF Reversing
x86_64 PTRACE & XOR
đŸ–ŧī¸ [Stego] Polyglot LSB Exfiltration
Blue/Alpha Channel Key
â„šī¸ Only teams who complete all 6 stages retrieve the Master Key to register.
THE 6-PHASE PRACTICAL KILL-CHAIN

Operation Zero-Gate Roadmap

Master modern offensive and defensive techniques across diverse domains to claim your ticket to the Grand Finals.

PHASE 01 Network Perimeter

Port Knocking Firewall Bypass

The challenge socket is invisible behind a dynamic firewall. Knock TCP ports 1337 -> 7331 -> 31337 sequentially within a 10-second threshold to unlock the handshake port.

Domain: Network Security Tools: Python, Netcat, Nmap
PHASE 02 Cryptographic Gate

Raw TCP Proof-of-Work Handshake

Connect to Port 9001 and solve a live SHA-256 PoW challenge with a 5-second strict reaction window. Writing a multi-threaded Python socket solver is essential.

Domain: Cryptography & Sockets Tools: Python asyncio, hashlib
PHASE 03 Web Application

Blind SSRF & Loopback Vault Pivot

Access the internal Diagnostics Suite on port 8080. Inspect HTML comments, exploit Server-Side Request Forgery, and pivot to loopback /internal-vault to leak secret crash dump download tokens.

Domain: Web Exploitation (SSRF) Tools: Burp Suite, DevTools, Curl
PHASE 04 Digital Forensics

Corrupted Dump Header Reconstruction

The downloaded crash_dump.bin binary has nullified header magic bytes. Inspect the file structure, patch the 3 Gzip signature bytes (1f 8b 08 00), and decompress the hidden archive.

Domain: Binary Forensics Tools: HxD, xxd, binwalk, tar
PHASE 05 Reverse Engineering

Anti-Debugging Linux ELF Disassembly

Reverse engineer gatekeeper.elf. Identify and patch ptrace(PTRACE_TRACEME) and timing traps. Reverse the XOR passcode algorithm (key: 0x5A) to execute the binary and drop flag_container.png.

Domain: Linux Reversing Tools: Ghidra, GDB, IDA Free, Radare2
PHASE 06 Steganography & Final Act

Deep Pixel Polyglot LSB Exfiltration

Examine the dropped PNG image. Write a bitwise extractor targeting the Least Significant Bits of alternating Blue and Alpha channels to recover the Master Token and unlock Round 2 registration!

Domain: Steganography Tools: PIL (Python), StegSolve, CyberChef
TOURNAMENT STRUCTURE

Road to the Championship

A multi-stage competition designed to identify the sharpest ethical hackers across SLIIT.

01
ROUND 1: LIVE NOW

Operation Zero-Gate Qualifiers

Deadline: November 15, 2026

Online Hack-to-Register kill-chain open to all SLIIT computing undergraduates. Complete all 6 phases to submit your team registration. First 20 validated teams earn a verified qualification slot.

02
ROUND 2: GRAND FINALS

On-Campus Root Arena

Date: Late November 2026

Top 20 qualified teams battle live at the SLIIT Malabe Main Campus Computing Labs. Real-time Jeopardy + Attack-Defense hybrid CTF with live scoreboard projection.

03
AWARDS & RECRUITMENT

SecOps Industry Gala

Date: Following Grand Finals

Trophy presentation, cash distributions, and direct networking with sponsor cybersecurity companies, SOC managers, and offensive security hiring teams.

PRIZE POOL & HONORS

Recognizing Elite Cyber Talent

Compete for prestige, cash bounties, hardware hacking tools, and career fast-tracks.

đŸĨˆ

First Runners-Up

LKR 50,000
  • ✓ Silver Trophy & Certificates
  • ✓ SecOps Lab Vouchers
  • ✓ Internship Interview Priority
CHAMPIONS
🏆

Grand Champions

LKR 100,000
  • ✓ SLIIT CTF 2026 Champion Trophy
  • ✓ Hardware Hacking Gear (Flipper Zero / Kit)
  • ✓ Top Tier Pentesting Partner Interviews
  • ✓ Official Faculty Merit Commendations
đŸĨ‰

Second Runners-Up

LKR 25,000
  • ✓ Bronze Trophy & Certificates
  • ✓ Official SLIIT Cyber Merchandise
  • ✓ Industry Partner Fast-Track
READY FOR INFILTRATION?

Enter Operation Zero-Gate Now

Execute the sequence below in your terminal to start Phase 1. Follow the kill-chain until you recover the Master Key.

PHASE 1 INSTRUCTION GUIDE PORT KNOCK SEQUENCE
# Step 1: Knock TCP Ports 1337 -> 7331 -> 31337 sequentially
nc -zv localhost 1337 && nc -zv localhost 7331 && nc -zv localhost 31337
# Step 2: Connect to the unlocked PoW Handshake Socket on port 9001
nc localhost 9001
# Step 3: Access the unlocked Phase 3 Web Diagnostics Suite
http://localhost:8080/diagnostics
RULES OF ENGAGEMENT

Fair Play & Ethical Guidelines

Violations of the rules below will lead to immediate team disqualification.

✕ NO INFRASTRUCTURE ATTACKS

Do not perform denial-of-service (DDoS) attacks, automated brute-force scripts against unrelated ports, or attack host infrastructure. All challenge vulnerabilities are contained within specified ports.

✕ NO FLAG SHARING

Sharing keys, tokens, or intermediate challenge outputs between competing teams is strictly prohibited. Solutions must be uniquely solved by your roster.

✓ ALLOWED TOOLS

You may freely use Wireshark, Ghidra, GDB, IDA Free, Radare2, Burp Suite Community, CyberChef, Python scripts, Netcat, and standard Linux utilities.

✓ TEAM COMPOSITION

Teams must consist of 1 to 4 current SLIIT undergraduates. All participants must provide their valid SLIIT Student IDs upon qualification.

FREQUENTLY ASKED QUESTIONS

Got Questions?

Who is eligible to participate? â–ŧ

All currently enrolled undergraduate students from SLIIT (all faculties, specializing in Cyber Security, Information Technology, Software Engineering, or Computer Systems & Network Engineering) are eligible.

Is there any registration fee? â–ŧ

No! Participation in SLIIT CTF 2026 is 100% free of charge. Your only admission ticket is solving Operation Zero-Gate.

Can I participate solo without a full team? â–ŧ

Yes! Team sizes range from 1 to 4 members. Solo competitors are welcome and evaluated on the same criteria.

What happens once my team submits the Master Key? â–ŧ

Once verified, your team claims an official Round 2 qualification slot (up to 20 total slots). The Team Leader will receive formal event instructions, venue lab allocations, and schedule briefings via email.