Skip to main content

What is Nebo CTF

Nebo CTF is a capture-the-flag platform for practicing cybersecurity skills through hands-on challenges, teams, competitions, and structured learning paths.

Overview

Nebo CTF helps players learn offensive and defensive security by solving challenges across categories like web, crypto, forensics, pwn, and OSINT. Points contribute to individual and team rankings.

Free tier: Access public challenges, the leaderboard, teams, events, and learning content at no cost.

Core features

  • Challenge library with difficulty ratings and categories
  • Team collaboration and team leaderboards
  • Timed competitions and events
  • Learning paths and labs
  • Progress tracking and notifications

Creating an Account

Register for a free Nebo CTF account to submit flags, join teams, and track your progress.

Step-by-step

  1. Sign up — Click Get Started and enter your name, username, email, country, and password.
  2. Verify email — Enter the 6-digit OTP sent to your inbox.
  3. Sign in — Use your email or username and password on the login page.
  4. Complete profile — Add a bio and avatar from your profile settings.
Your email is used for verification and important notifications only. See our Privacy Policy.

Requirements

  • Valid email address
  • Unique username (letters, numbers, underscores)
  • Password meeting minimum strength guidelines
  • Acceptance of Terms of Service and Privacy Policy

Completing Your Profile

A complete profile helps teammates and the community recognize you on leaderboards and team pages.

Profile fields

From Profile in the app menu, you can update:

  • Display name and bio
  • Profile avatar
  • Country (set at registration)
  • Public activity and solve history
Tip: Use a consistent username — it appears on the leaderboard and in team rosters.

Challenge Types

Challenges are grouped by category and difficulty to help you find appropriate practice.

Categories

CategoryTopics
WebSQLi, XSS, auth bypass, IDOR
CryptoEncoding, ciphers, hashing
ForensicsFiles, PCAPs, memory dumps
PwnBinary exploitation, buffers
OSINTOpen-source intelligence
ReverseDisassembly, deobfuscation

Difficulty levels

Easy, Medium, Hard, and Very Hard — each maps to a point range on the challenge card.

Solving Challenges

A practical workflow for approaching and completing CTF challenges on Nebo CTF.

Recommended workflow

  1. Browse — Open the challenge list and filter by category or difficulty.
  2. Read — Review the description, connection details, and attachments.
  3. Enumerate — Gather information before attempting exploitation.
  4. Solve — Work toward the flag; use hints if stuck.
  5. Submit — Submit via the flag form on the challenge page.
First solve? Start with Easy challenges in a category you want to learn.

Flag Submission

How challenge submissions work and how flags are validated.

Flag format

Flags use the standard wrapper (case-sensitive):

Flag
CTF{flag_content_here}
Important: Always include the CTF{} wrapper. Submissions without it are rejected.

Validation

Submitted flags are hashed and compared securely. On a correct first submission you receive points and the challenge is marked solved.

Examples

{% include "components/ui/code_block.html" with code="Correct: CTF{example_flag_123} Incorrect: example_flag_123 Incorrect: ctf{example_flag_123} Incorrect: CTF{ example_flag_123 }" language="Examples" %}

Hints

Hints guide you toward a solution without revealing the full answer.

Using hints

  • Some hints are available immediately on the challenge page
  • Additional hints may unlock after incorrect attempts
  • Hints do not reduce your points
  • Use hints to learn — not as a substitute for understanding

Points and Scoring

Points reflect challenge difficulty and contribute to leaderboard rankings.

Point ranges

DifficultyTypical points
Easy50–150
Medium200–350
Hard400–600
Very Hard600+
Dynamic scoring may adjust points based on solve count. Check the challenge page for current value.

Creating a Team

Create a team to collaborate on challenges and compete on team leaderboards.

Steps

  1. Go to Teams and click create
  2. Choose a team name and slug
  3. Invite members or approve join requests
  4. Compete together on team rankings

Joining a Team

Request to join an existing team or accept an invitation from a captain.

Join process

Browse teams from the Teams page, send a join request, and wait for captain approval. You'll receive a notification when approved or rejected.

Team Roles

Team captains manage membership; members contribute solves to the team score.

Roles

  • Captain — Approve/reject requests, manage roster, delete team
  • Member — Submit flags; solves count toward team score

Team Competitions

Some events support team registration and team-specific leaderboards.

Register your team for eligible events. Team scores aggregate member solves during the event window. See Participating for event details.

Participating in Competitions

Events are timed competitions with dedicated challenge sets and leaderboards.

How it works

  1. Browse Events
  2. Review format, schedule, and rules
  3. Register before the deadline
  4. Solve challenges during the active window
  5. Track standings on the event leaderboard

Event Registration

Register individually or as a team depending on event settings.

Open an event detail page and click Register. Some events cap participants or require verified accounts. Duplicate registrations are blocked.

Competition Rules

Follow event-specific rules and platform fair-play guidelines.

  • No sharing flags or solutions during active events
  • No attacks against platform infrastructure
  • Respect rate limits on submissions
  • Follow organizer announcements

Rankings

Leaderboards rank players and teams by points and solve count.

Global rankings live on the Leaderboard. Event rankings appear on each event page. Only users who have solved at least one challenge appear on the global board.

Learning Paths

Structured curricula of modules and topics for progressive skill building.

Browse paths from Learning. Each path contains modules, topics, notes, and linked challenges or labs.

Labs

Hands-on lab exercises with submission and review workflows.

Complete lab content, submit answers or files as instructed, and track review status from your lab submissions page.

Progress Tracking

Monitor solves, streaks, and learning completion from your dashboard.

Your dashboard shows recent activity, solve streak, and recommended next steps. Learning path progress is tracked per module and topic.

Profile

Your public profile displays solves, teams, and activity.

Access Profile from the app menu to edit your bio, avatar, and view your solve history and statistics.

Account Settings

Manage account preferences and personal information.

Update display preferences, country, and other account fields from Settings. Some fields require re-authentication for security.

Notifications

Stay informed about team requests, events, and platform updates.

Configure notification preferences from Notification Settings. In-app notifications appear in the header bell icon when logged in.

Security

Keep your account secure with strong passwords and verified email.

  • Use a unique, strong password
  • Keep your email verified and accessible
  • Sign out on shared devices
  • Report suspicious activity via Reporting Abuse

Reset your password anytime via Forgot Password.

Code of Conduct

Nebo CTF is a welcoming community. Treat all participants with respect.

  • Be respectful in teams and public channels
  • No harassment, hate speech, or discrimination
  • Give constructive feedback in discussions
  • Follow organizer and moderator directions

Fair Play

Play honestly — no flag sharing, brute-forcing, or attacking infrastructure.

  • Solve challenges yourself or with your registered team
  • Do not share flags during active competitions
  • Respect submission rate limits
  • Do not attempt to disrupt the platform

Eligibility

Some events may restrict eligibility by region, age, or affiliation.

Check individual event pages for eligibility requirements. Organizers may disqualify participants who violate rules.

Reporting Abuse

Report violations, cheating, or security concerns to platform staff.

Contact us via Support with details and evidence. We review reports confidentially.

Login Issues

Common sign-in problems and how to resolve them.

Common fixes

  • Verify email before signing in if required
  • Use email or username in the identifier field
  • Reset password via Forgot Password
  • Clear cookies or try a private window
  • Check caps lock for passwords

Submission Issues

When flag submissions fail or rate limits block you.

Checklist

  • Confirm CTF{} wrapper and exact casing
  • Remove trailing spaces
  • Wait if rate-limited (max ~10/min per challenge)
  • Ensure you're logged in
  • Refresh the challenge page and retry
Repeated incorrect submissions may trigger temporary locks. Analyze the challenge instead of guessing.

Team Issues

Join requests, captain approvals, and roster problems.

  • Pending requests — captain must approve from team page or notifications
  • Can't join — team may be full or request already pending
  • Leave team — use team settings; captains must transfer role first

Frequently Asked Questions

Quick answers to common platform questions.

General

Is Nebo CTF free?
Yes — the free tier includes public challenges, leaderboard, teams, and community features.
Do I need experience?
No. Start with Easy challenges and learning paths.
Can I practice offline?
Some challenges offer downloadable files; submissions require internet access.
Why can't I see the leaderboard?
Sign in to view rankings. Only players with at least one solve are ranked.
How do I reset my password?
Use Forgot Password on the login page.