Event Rules & Policies
The Hack4Bug CyberHackathon'26 is a high‑stakes, nation‑wide capture‑the‑flag competition designed to push the limits of your security expertise. Due to limited number of team we selecting team manually, If your team selected you have to just pay Rs.1500, Looking your team in Hack4Bug CyberHackathon'26
Teams will battle across diverse challenge categories, from web exploits to cryptographic puzzles.
Points are awarded based on challenge difficulty and speed of resolution, encouraging rapid, creative problem‑solving.
All participants must adhere to the strict code of conduct to ensure fair play and a safe competition environment.
- Each team may have a maximum of 3 members. Solo participants are welcome and will compete as a single-person team.
- Participants must operate strictly within the authorized challenge environment only.
- Any attempt to access or exploit infrastructure outside the intended scope will result in immediate disqualification.
- The competition will be conducted in a Jeopardy-style CTF format.
- Dynamic scoring is applied, where points decrease as more participants solve a challenge.
- Challenges can be solved in any order.
- DoS/DDoS attacks are strictly prohibited.
- Collaboration between different teams is not allowed.
- Sharing flags, solutions, or hints with other teams is strictly forbidden.
- Each participant must register using their own real identity or a consistent handle. Creating multiple accounts or sharing login credentials is strictly prohibited.
- Automated brute-force attacks against flags or infrastructure are not permitted.
- All challenge solutions, exploits, and methodologies must remain confidential during the competition.
- Public disclosure of any challenge-related information during the event will lead to disqualification.
- Discussing challenges, hints, or solutions on social media, forums, or external platforms is strictly prohibited.
- Getting external help from individuals who are not registered members of your team—such as asking for solutions on public forums, chat groups, or hiring external proxy solvers is strictly prohibited.
- Any violation of these guidelines will result in immediate disqualification from the competition without prior warning.
- Zero Tolerance Policy: Misbehavior toward Hack4Bug team members or participants will result in instant disqualification.
- No appeals or exceptions will be entertained after disqualification.
- Strict Non-Refundable Policy : Registration fees are strictly non-refundable If your team successfully completes the payment, but the team registration limit has already reached full capacity before your slot could be secured, Hack4Bug will issue a full refund.
- Once your team is officially selected, your payment is processed, and your slot is confirmed, no refunds will be provided if your team chooses not to participate or fails to play the CTF.
- For support or inquiries, reach out via Email (hack4bug@gmail.com), WhatsApp, or our Discord group.
- In case the CTF is suspended, it will be rescheduled and continued on the next available dates.
- All flags follow a specific format (e.g., Hack4Bug{YEAH_YOU_READS_RULES} unless otherwise specified). Modifying, fabricating, or attempting to brute-force flag strings on the scoreboard is prohibited.
- All decisions made by the Hack4Bug organizing team are final and binding.
CTF Categories
- Web Security
- Cryptography
- Reverse Engineering
- Digital Forensics
- OSINT (Open Source Intelligence)
- Boot2Root
- PWN & Binary Exploitation
- And much more....
Competition Rounds
Round 1 – Online: Open to all registered participants. Solve challenges remotely. T.B.D : Date will be reveal soon.
Round 2 – On‑site at ITCN Expo Karachi 2026 (23 September): Top teams from the online round compete live.
Sponsors
Hackathon partner
Community Partners & Collaborators
We thank our Community Partners & Collaborators for their support.