elkhatebx22
Web & Infra

Official challenges and writeups for EYCC CTF 2026 — Egypt's national cybersecurity competition for students, organized in partnership with Hack Club of STEM Egypt and authored by Mont5ab El2hwa.
Egypt’s first cybersecurity competition created specifically for high school students returned for its highly anticipated Final Round. After proving themselves in the EYCC 2026 Qualifiers, 15 outstanding teams featuring 55 rising young hackers earned their place at the finals to compete, showcase their skills, connect with fellow talents, and take another step toward becoming Egypt’s future cybersecurity leaders.
Authoring every challenge from scratch across 8 categories (Web, Reverse, Pwn, Crypto, Forensics, OSINT, Mobile, and Misc)
Designing custom vulnerabilities, multi-step exploit chains, and verifying every solve path before launch
Publishing full writeups, source code, and step-by-step solutions to help players learn and level up
Handling live challenge hosting, infrastructure, and technical support across both qualifiers and the on-site finals
35+
Teams
~300
Players


Full source code, task files, and infrastructure for our authored challenges are available in the GitHub Repository.

Mall Albostan, Downtown Cairo's go-to spot for laptops, GPUs, and everything in between...

Welcome to Brew Bank. Do not bruteforce. Think like a hacker, not a bot.

Welcome to Brew Bank Again. Do not bruteforce...
try harder
Mr. Krabs finally put the Krusty Krab order boards online, and SpongeBob finally admitted what he really wants: the Krabby Patty secret formula. It is filed at `/verysecretrecipe`, and the fry cook account you can sign up for is not getting in there. Mr. Krabs is, though. He reads every link dropped in the complaint box himself, from his own logged-in browser. Get the formula out of the manager's session.
The challenge is fully solvable black-box. Source code is included only for convenience.
sql nosql sql nosql sql nosql sql nosql flag => EYCC{part1_part2_part3_part4}
JUST /flag.txt
JUST /flag.txt again
A cup of mint tea can be simple, but things aren't always what they seem. Think like a Bug Hunter. No brute force
Ever want to quickly peek at a webpage without leaving the office portal? shay blaban lets you do exactly that.
Canelo doesn't like shay blaban so he went to a coffee shop and they suggested for him 2hwa fat7 m7aweeg
Contributors across challenge authoring, infrastructure, mentoring, and event organization
Web & Infra
Web Exploitation
The Crypto Guy
Reverse Engineering
Web Exploitation
OSINT
Binary Exploitation
Web Exploitation
Web & Mobile
Digital Forensics
Forensics & Reverse
Web Exploitation
Mobile Security
Digital Forensics
Reverse Engineering
Reverse Engineering