Compete

Competing is where the learning actually sticks. You can read about SQL injection for a week and forget it by Friday, or you can spend three hours finding one in a live challenge and never forget it again.

Showing up while clueless is the point. Nobody expects you to carry the team in your first competition. Watching how teammates think through a problem under time pressure teaches you more than a month of solo tutorials.


Two Tracks

Competing at this club splits into two different games. They test different skills and it helps to know which one you are walking into.

Defense — CCDC, CyberPatriot

You inherit a network you did not build, full of misconfigurations and planted vulnerabilities, and you have to find and fix them while a professional red team actively tries to break back in. This is blue team work: hardening, monitoring, incident response, keeping services up under attack.

It is closer to a real job than any other competition format. Sysadmin instincts and calm under pressure matter as much as technical depth.

Offense / Puzzle — CTFs

You are handed a broken thing — a website, a binary, a packet capture — and your job is to break it further until a hidden flag falls out. Jeopardy-style CTFs let you pick your own challenges and work at your own pace; they are the best low-stakes way to practice offensive skills.

See CTF for how to get started.


Both tracks are worth doing. Defense teaches you how systems actually fail in production. Offense teaches you how to find that failure before someone else does. Most people end up better at one, but you will not know which until you have tried both.

See the competition archive for what past teams built.

Next CTFWhat CTFs are, where to start, and how to approach a challenge.