SLIIT CYBER SECURITY
CTF 2026
Operation Zero-Gate â The elite Hack-to-Register qualification tournament for undergraduate security researchers. Registration is not given; it must be breached.
đ Round 1 Participant Roster (Open Qualifier Entry)
Showing all verified teams competing in the preliminary hacking phase. Top 20 advance to Round 2.
Preliminary Registration Closed âĸ The Zero-Gate 20 Finalists
Tier 1 preliminary registration has officially concluded. All contender streams are archived. Below are the elite Top 20 Qualified Champions who cracked the gateway and secured advancement to the Round 2 Grand Finals.
Top 20 Finalists advance to the In-Person Grand Finals at SLIIT Main Campus. Portal Access
Why Fill a Form When You Can Breach the Gate?
Traditional capture-the-flag competitions begin with an open Google Form. Operation Zero-Gate redefines cybersecurity qualification at SLIIT. Built by the Department of Cyber Security, our registration portal is locked behind an impenetrable defensive architecture.
To register, your team must orchestrate a live 6-phase cyber kill-chain: decipher raw TCP port knocking, bypass proof-of-work rate limiters, exploit Blind SSRF in a corporate diagnostics utility, reconstruct corrupted binary headers, bypass Linux anti-debugging routines, and extract cryptographic keys hidden inside image pixels.
Operation Zero-Gate Roadmap
Master modern offensive and defensive techniques across diverse domains to claim your ticket to the Grand Finals.
Port Knocking Firewall Bypass
The challenge socket is invisible behind a dynamic firewall. Knock TCP ports 1337 -> 7331 -> 31337 sequentially within a 10-second threshold to unlock the handshake port.
Raw TCP Proof-of-Work Handshake
Connect to Port 9001 and solve a live SHA-256 PoW challenge with a 5-second strict reaction window. Writing a multi-threaded Python socket solver is essential.
Blind SSRF & Loopback Vault Pivot
Access the internal Diagnostics Suite on port 8080. Inspect HTML comments, exploit Server-Side Request Forgery, and pivot to loopback /internal-vault to leak secret crash dump download tokens.
Corrupted Dump Header Reconstruction
The downloaded crash_dump.bin binary has nullified header magic bytes. Inspect the file structure, patch the 3 Gzip signature bytes (1f 8b 08 00), and decompress the hidden archive.
Anti-Debugging Linux ELF Disassembly
Reverse engineer gatekeeper.elf. Identify and patch ptrace(PTRACE_TRACEME) and timing traps. Reverse the XOR passcode algorithm (key: 0x5A) to execute the binary and drop flag_container.png.
Deep Pixel Polyglot LSB Exfiltration
Examine the dropped PNG image. Write a bitwise extractor targeting the Least Significant Bits of alternating Blue and Alpha channels to recover the Master Token and unlock Round 2 registration!
Road to the Championship
A multi-stage competition designed to identify the sharpest ethical hackers across SLIIT.
Operation Zero-Gate Qualifiers
Deadline: November 15, 2026
Online Hack-to-Register kill-chain open to all SLIIT computing undergraduates. Complete all 6 phases to submit your team registration. First 20 validated teams earn a verified qualification slot.
On-Campus Root Arena
Date: Late November 2026
Top 20 qualified teams battle live at the SLIIT Malabe Main Campus Computing Labs. Real-time Jeopardy + Attack-Defense hybrid CTF with live scoreboard projection.
SecOps Industry Gala
Date: Following Grand Finals
Trophy presentation, cash distributions, and direct networking with sponsor cybersecurity companies, SOC managers, and offensive security hiring teams.
Recognizing Elite Cyber Talent
Compete for prestige, cash bounties, hardware hacking tools, and career fast-tracks.
First Runners-Up
- â Silver Trophy & Certificates
- â SecOps Lab Vouchers
- â Internship Interview Priority
Grand Champions
- â SLIIT CTF 2026 Champion Trophy
- â Hardware Hacking Gear (Flipper Zero / Kit)
- â Top Tier Pentesting Partner Interviews
- â Official Faculty Merit Commendations
Second Runners-Up
- â Bronze Trophy & Certificates
- â Official SLIIT Cyber Merchandise
- â Industry Partner Fast-Track
Enter Operation Zero-Gate Now
Execute the sequence below in your terminal to start Phase 1. Follow the kill-chain until you recover the Master Key.
Fair Play & Ethical Guidelines
Violations of the rules below will lead to immediate team disqualification.
â NO INFRASTRUCTURE ATTACKS
Do not perform denial-of-service (DDoS) attacks, automated brute-force scripts against unrelated ports, or attack host infrastructure. All challenge vulnerabilities are contained within specified ports.
â NO FLAG SHARING
Sharing keys, tokens, or intermediate challenge outputs between competing teams is strictly prohibited. Solutions must be uniquely solved by your roster.
â ALLOWED TOOLS
You may freely use Wireshark, Ghidra, GDB, IDA Free, Radare2, Burp Suite Community, CyberChef, Python scripts, Netcat, and standard Linux utilities.
â TEAM COMPOSITION
Teams must consist of 1 to 4 current SLIIT undergraduates. All participants must provide their valid SLIIT Student IDs upon qualification.
Got Questions?
Who is eligible to participate? âŧ
All currently enrolled undergraduate students from SLIIT (all faculties, specializing in Cyber Security, Information Technology, Software Engineering, or Computer Systems & Network Engineering) are eligible.
Is there any registration fee? âŧ
No! Participation in SLIIT CTF 2026 is 100% free of charge. Your only admission ticket is solving Operation Zero-Gate.
Can I participate solo without a full team? âŧ
Yes! Team sizes range from 1 to 4 members. Solo competitors are welcome and evaluated on the same criteria.
What happens once my team submits the Master Key? âŧ
Once verified, your team claims an official Round 2 qualification slot (up to 20 total slots). The Team Leader will receive formal event instructions, venue lab allocations, and schedule briefings via email.
Register Your Contender Team
Fill in all required (*) fields. Email + Contact required for Leader only.