AlpacaHack Logo
Sign InSign Up
Daily AlpacaHack

A daily CTF challenge with a fun new puzzle every day

What is Daily AlpacaHack?

We publish one simple, beginner-friendly or educational CTF challenge every day!

Join Anytime

Solve within 24 hours of release to appear on the leaderboard.

Not a Competition

Discussion with friends or AI is welcome (account sharing is prohibited).

Solution Sharing Rules

Sharing solutions is allowed only after 24 hours have passed since release.

Solve stats

0

/27

No solved challenges yet.

Sign In to view your player stats

Today's Challenge
tchentchen
RFC100008
Web
Easy🌱
80 solves
Submissions (latest 3)
goroshirow

SOLVED!

Jul 27, 1:50 PM

Leaderboard

Try the first challenge

Is this your first CTF? Let's begin by tackling the first challenge released on Daily AlpacaHack.

View challenge
admin
AlpacaHack 2100
Misc
Welcome🌱
2,025 solves
Upcoming challenges reveal the , , and in advance.
Prev

Jul 2026

Next
Solved
Unsolved
Upcoming
Mon
Tue
Wed
Thu
Fri
Sat
Sun
29
tchentchen
Nano Services
Web
Medium
88 solves
30
minaminaominaminao
Super Short System Exit
Misc
Medium
83 solves
1
admin
Alpaca Nation
Misc
Welcome🌱
253 solves
2
hiikunzhiikunz
Flag is A+B
Crypto
Easy🌱
153 solves
3
tchentchen
Lucky Redirect
Web
Easy🌱
148 solves
4
hiikunzhiikunz
Renda
Rev
Medium
113 solves
5
tchentchen
IP Blocked Secret
Web
Hard
67 solves
6
minaminaominaminao
duplicate entry
Misc
Easy🌱
146 solves
7
hiikunzhiikunz
Lazy RSA
Crypto
Medium
105 solves
8
minaminaominaminao
Let's Poly1305!
Crypto
Medium
76 solves
9
shiragishiragi
private method
Misc
Easy🌱
142 solves
10
hiikunzhiikunz
secret-table-3
Web
Medium
86 solves
11
baumroll1234
A slight mistake
Pwn
Hard
71 solves
12
tan90909090tan90909090
13
baumroll1234
Redirecting to Login Page
Web
Easy🌱
157 solves
14
tchentchen
You've Got Shlex
Misc
Medium
88 solves
15
minaminaominaminao
Let's Poly1305! 2
Crypto
Hard
64 solves
16
tchentchen
Beat the Alpaca Lord
Web
Medium
91 solves
17
pppp4649pppp4649
biribiri
Crypto
Medium
86 solves
18
tchentchen
Greetings CGI
Web
Hard
71 solves
19
hiikunzhiikunz
no win func
Pwn
Hard
74 solves
20
tchentchen
Alpaca Blog
Web
Easy🌱
115 solves
21
tan90909090tan90909090
NOP Variant
Rev
Misc
Medium
65 solves
22
arkark
jinjail
Misc
Hard
43 solves
23
tchentchen
True or False
Misc
Medium
70 solves
24
minaminaominaminao
Cache Me If You Can 2
Web
Hard
52 solves
25
k0080k0080
what-is-my-pointer
Pwn
Hard
47 solves
26
tchentchen
Greetings i18n
Web
Hard
47 solves
27
tchentchen
RFC100008
Web
Easy🌱
80 solves
28
2501
Planned topicECDSA
Web
Medium
29
Coming soon
30
Coming soon
31
Coming soon
2
Coming soon

Want a harder challenge?

Go to B-SIDE

Writeups

Writeup for Leaked Flag Checker

haruhana

ja
Leaked Flag Checker

11 hours ago

nirvana

Writeup for no win func

ja

2026/07/26 12:18

nirvana

Writeup for what-is-my-pointer

ja

2026/07/26 00:24

nitcelcius

Writeup for Cache Me If You Can 2 (with PowerShell)

nirvana

Writeup for True or False

ja

2026/07/23 15:05

Daily AlpacaHackに挑戦するつくよみちゃん07/21/NOP Variant/tan90909090

ja

2026/07/21 16:33

nirvana

Writeup for Alpaca Blog

ja

2026/07/21 13:38

Rows:

Emojify

Topic: Server-SideReleased: Dec 3, 2025

693 solves
Web
Medium4.0

by

ark

ark

:pizza: -> 🍕

Beginner Hint 1: About Difficulty
  • This challenge is in the Web category, i.e., web applications.
  • Unlike yesterday's challenge, which was Easy, this one is Medium.
  • Daily AlpacaHack currently defines four difficulty levels: Easy, Medium, Hard, and Very Hard.
  • Medium is one step above Easy. If Daily AlpacaHack is your first exposure to CTF, solving it may be tough.
  • If you get stuck, feel free to lean on AI to find a starting point for the solution.
  • Even if you can't solve it, check other players' solutions (writeups) afterward to review and learn.
  • 24 hours after release, a writeup tab will appear in the tab bar below.
Beginner Hint 2: Running the Challenge Locally
  • After extracting the attachment, you'll find compose.yaml, Dockerfile, and directories for three services.
  • Modern CTFs often ship a Docker Compose file so players can reproduce the remote environment locally.
  • From the root of the distribution, run docker compose up.
  • With default settings, the challenge server will start at http://localhost:3000/.
  • Use this local server to investigate vulnerabilities and to test the solver you build.
Beginner Hint 3: Approach to Solving the Challenge (AI-translated)
  • Start by reading the source code to understand what kind of web service is running.
  • It will be easier to understand if you read the code while checking how the challenge server behaves locally.
  • Once you roughly understand the service's behavior, the next step is to identify the goal.
  • Think about where the flag is and what you need to be able to do to obtain it. Then you will see that achieving that "what you need to be able to do" is the point of this challenge.
  • The challenge server is written in JavaScript.
  • To check the detailed behavior of JavaScript functions, it is useful to have an interactive environment where you can run JavaScript.
  • Try running the node command in your local terminal and experimenting with it.
  • It is also useful to look up the specifications of the JavaScript functions used in the challenge.
  • MDN documentation (https://developer.mozilla.org/en-US/docs/Web) is accurate and comprehensive, so it is a useful information resource.
emojify.tar.gz

Please sign in to submit the flag.

descriptionsolveswriteups