AlpacaHack Logo
Sign InSign Up
Daily AlpacaHack

A daily CTF challenge with a fun new puzzle every day

What is Daily AlpacaHack?

We publish one simple, beginner-friendly or educational CTF challenge every day!

Join Anytime

Solve within 24 hours of release to appear on the leaderboard.

Not a Competition

Discussion with friends or AI is welcome (account sharing is prohibited).

Solution Sharing Rules

Sharing solutions is allowed only after 24 hours have passed since release.

Solve stats

0

/20

No solved challenges yet.

Sign In to view your player stats

Today's Challenge
tchentchen
Alpaca Blog
Web
Easy🌱
70 solves
Submissions (latest 3)
happykid

SOLVED!

Jul 20, 10:51 AM

apender

SOLVED!

Jul 20, 10:47 AM

Leaderboard

Try the first challenge

Is this your first CTF? Let's begin by tackling the first challenge released on Daily AlpacaHack.

View challenge
admin
AlpacaHack 2100
Misc
Welcome🌱
1,990 solves
Upcoming challenges reveal the , , and in advance.
Prev

Jul 2026

Next
Solved
Unsolved
Upcoming
Mon
Tue
Wed
Thu
Fri
Sat
Sun
29
tchentchen
Nano Services
Web
Medium
87 solves
30
minaminaominaminao
Super Short System Exit
Misc
Medium
82 solves
1
admin
Alpaca Nation
Misc
Welcome🌱
224 solves
2
hiikunzhiikunz
Flag is A+B
Crypto
Easy🌱
134 solves
3
tchentchen
Lucky Redirect
Web
Easy🌱
127 solves
4
hiikunzhiikunz
Renda
Rev
Medium
106 solves
5
tchentchen
IP Blocked Secret
Web
Hard
64 solves
6
minaminaominaminao
duplicate entry
Misc
Easy🌱
132 solves
7
hiikunzhiikunz
Lazy RSA
Crypto
Medium
101 solves
8
minaminaominaminao
Let's Poly1305!
Crypto
Medium
75 solves
9
shiragishiragi
private method
Misc
Easy🌱
126 solves
10
hiikunzhiikunz
secret-table-3
Web
Medium
82 solves
11
baumroll1234
A slight mistake
Pwn
Hard
69 solves
12
tan90909090tan90909090
13
baumroll1234
Redirecting to Login Page
Web
Easy🌱
135 solves
14
tchentchen
You've Got Shlex
Misc
Medium
83 solves
15
minaminaominaminao
Let's Poly1305! 2
Crypto
Hard
63 solves
16
tchentchen
Beat the Alpaca Lord
Web
Medium
87 solves
17
pppp4649pppp4649
biribiri
Crypto
Medium
82 solves
18
tchentchen
Greetings CGI
Web
Hard
66 solves
19
hiikunzhiikunz
no win func
Pwn
Hard
65 solves
20
tchentchen
Alpaca Blog
Web
Easy🌱
70 solves
21
tan90909090tan90909090
Planned topicx86
Rev
Misc
Medium
22
Coming soon
23
Coming soon
24
Coming soon
25
Planned topicCache
Web
Hard
26
Planned topicPython
Web
Hard
27
Coming soon
28
Coming soon
29
Coming soon
30
Coming soon
31
Coming soon
2
Coming soon

Want a harder challenge?

Go to B-SIDE

Writeups

ojun

Writeup for no win func

ojun

ja
no win func

19 hours ago

kurimochi

Writeup for You've Got Shlex (shlex only)

ja

2026/07/19 05:58

nitcelcius

Writeup for You've Got Shlex

ja

2026/07/18 12:59

edwowmath

Writeup for Compile time flag checker

tchen

Writeup for You've Got Shlex

author
en

2026/07/16 01:15

tchen

Writeup for IP Blocked Secret

author
en

2026/07/15 23:53

Rows:

Small Image Uploader

Topic: Client-SideReleased: Apr 26, 2026

74 solves
Web
Hard6.5

by

tchen

tchen

XSS with small image?

Beginner Hint1: About the Admin Bot
  • In this challenge, you are given not only the web application itself, but also an admin bot.
  • The admin bot has a cookie containing the flag, and it opens a specified path using Headless Chrome.
  • Therefore, your goal is to make the admin bot trigger your payload and send the cookie value to an external server.
  • You can prepare your own server as the destination, or use an existing service that lets you receive and inspect HTTP requests.
  • If you are still not familiar with how to use the admin bot or how to inspect incoming requests, it may help to first solve Fushigi Crawler and read its writeup.
Beginner Hint2: Overview of the Challenge
  • Using POST /api/upload, you can upload a file to the server. Try uploading the sample files included with the challenge distribution.
  • In /file, you can view the uploaded file. It uses GET /api/file/<file_id> to get the content of the file, and GET /api/filename/<file_id> to get the original filename of the file.
Beginner Hint3: Approach
  • original_filename looks like it is escaped using html.escape. This is because the value returned in /api/filename/<file_id> is directly inserted into HTML using innerHTML.
    • So the intended path is not to inject through a malformed filename.
  • Look carefully at how file_id is used in /file, and see how it can be abused.
small-image-uploader.tar.gz

Please sign in to submit the flag.

descriptionsolveswriteups