A competition built by the people who needed it
CampusHack is independent and volunteer-run. It is not attached to any single institution — which is exactly what makes the leaderboard worth trusting.
Theory without hands
Computer science curricula across Cameroon are strong on theory and almost silent on practice. Students graduate having never exploited a vulnerability, read a packet capture, or reverse-engineered a binary. The few who teach themselves do it alone, with no local community and no way to measure how far they have come.
There is also no public record of which institutions produce capable security practitioners. Without one, students cannot choose well and employers cannot recruit well.
Three things, on purpose
Put a CTF on every campus
The qualifier phase means security practice happens inside institutions rather than only at a central event. Students who would never travel to a national final still get their first taste.
Make failure useful
Failing a challenge in a competition teaches more than passing an exam.
Keep the score, permanently
Every result feeds a public university leaderboard that never resets.
Six categories, and two machines
The board is built so that everyone solves something and nobody solves everything. Roughly half of a qualifier is written for people doing this for the first time.
Web exploitation
Injection, file inclusion, broken authentication, upload bypasses — the flaws that turn up most often in real applications.
Forensics
Packet captures, disk images and log files. Work out what happened from the evidence left behind.
Cryptography
Weak implementations, reused keys, bad randomness. Recognising the mistake matters more than the mathematics.
Reverse engineering
Compiled binaries with something hidden inside. Read the code that nobody meant for you to read.
OSINT
Everything findable from public sources. Every team should leave having solved at least one of these.
Miscellaneous
Logic, scripting and problems that fit nowhere else. Usually where the warm-up lives.
Two full machines open alongside the board — one Linux, one Windows. Getting in is the first half; becoming administrator is the second. Both flags score, so a partial break still counts.
The team behind it
Practitioners who organise CampusHack alongside their own work in security.
Common questions
Any team of three to four students currently registered at a Cameroonian university. You do not need prior CTF experience — a good share of the challenges are written specifically for people doing this for the first time.
No. Entry is free at both phases and it will stay that way. Sponsors cover the platform, venue, prizes and materials.
Get in touch. We are actively looking for institutions to host qualifiers, and adding one is mostly a matter of finding a room and a date.
Comfort with Linux, a browser's developer tools, and a scripting language will carry you a long way. Everything else you can learn on the day — that is rather the point.
A full virtual machine you have to break into and then escalate to administrator on. There are two at the finals, one Linux and one Windows, and they open alongside the jeopardy board.
Yes. Any documentation, search engine or tool you can reach is fair game. What you cannot do is ask a person outside your team, or share flags with another team.
Dynamic scoring: a challenge is worth fewer points as more teams solve it. The scoreboard freezes for the last thirty minutes, so the final standings are a surprise to everyone including us.
On this site, on the leaderboard, within a week of each event. Official writeups follow within two weeks.
Bring CampusHack to your campus.
If you run a club, a department, or just know the right person — talk to us.