It would be nice to have a better explanation of the types of problems being solved here, because the security space is so massive.
Is this websec? appsec? Reverse engineering?
Is this websec? appsec? Reverse engineering?
To answer your question directly though, it's a bit of a mix of mostly introductory concepts with the goal of introducing crypto and breaking/defensive programming to people who might not get much exposure to it. The first challenges are simple crypto-based challenges to get participants into the right frame of mind, and they culminate with exploiting a hash length extension vulnerability. Hopefully, we'd like to introduce more challenges like this in the future.