Repository files navigation

CookieFarm Logo

VersionGitHub go.mod Go versionGitHub code size in bytesGitHub License

CookieFarm is an Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. Its strength lies in a hybrid Go + Python architecture and a zero-distraction philosophy:

🎯 Your only task is to write the exploit!

CookieFarm automates exploit distribution, flag submission, and result monitoring — allowing you to focus entirely on building powerful exploits.


⚙️ Installation

Server

bash -c "$(curl -sSL cookiefarm.bytethecookies.org/install.sh)"

Note

If you need a manual setup check out the official docs

Client

pip install --upgrade cookiefarm requests

Tip

Check if all is good with ckc --version


⚡️ Getting Started

Starting the Server

Automatic Setup

if you have already installed using the script do simple:

docker compose up --build -d

Manual Setup

  1. Clone the repository and navigate to the server directory:
git clone https://github.com/ByteTheCookies/CookieFarm.git
cd CookieFarm
  1. Create an .env file in the server directory to configure the environment settings:
# Server configurationDEBUG=false# Enable debug mode for verbose loggingPASSWORD=SuperSecret# Set a strong password for authenticationCONFIG_FILE=config.yml# Set if the server takes the config from config.yml in the filesystem; otherwise, do not set the variablePORT=8080# Define the port the server will listen on

Warning

For production environments, set DEBUG=false and use a strong, unique password

  1. Create the config.yml file in the server directory to configure the services and teams:
configured: trueserver:
url_flag_checker: "<ip_flagchecker>:<port_flagchecker>"team_token: "<your_team_token>"submit_flag_checker_time: 120max_flag_batch_size: 1000protocol: "cc_http"tick_time: 120start_time: <start_time>end_time: <end_time>flag_ttl: 5# in ticks (if the ttl is 0, the flag will never expire)shared:
services:
CookieService: 8081format_ip_teams: "10.10.{}.1"regex_flag: "[A-Z0-9]{31}="range_ip_teams: 29my_team_id: 1nop_team: 0url_flag_ids: "<address_of_flagIds>"flagids_format: "[service].[team].[id]"
  1. Start the server with Docker Compose:
docker compose -f compose.yml up --build

Note

For more configuration details, refer to the server documentation.


💻 Using the Client & Running Exploits

  1. Run the installation :
pip install --upgrade cookiefarm requests

Note

After installation, the ckc command is available globally in your terminal (or in your virtual environment if you are using one).

  1. Config the client by logging in with the server credentials:
ckc config edit -H 192.168.1.10 -p 8000
  1. Log in and configure the client:
ckc login -P SuperSecret -u your_username
  1. Install the Python helper module and create a new exploit template:
ckc exploit create -n your_exploit_name

This will generate your_exploit_name.py in ~/.cookiefarm/exploits/.

  1. Run your exploit:
ckc exploit run -e your_exploit_name.py -n CookieService -t 120 -W 40

Note

For more usage examples, check out the client documentation.


CookieFarm Architecture

🎯 Features

  • Go client and server core – High‑performance scheduler in Go handles exploit parallelism, flag collection, and timed execution cycles.
  • Python SDK – Simple client library: import, decorate/subclass, write your attack logic, done. [github]
  • Automatic flag detection – Flags printed by your exploit are automatically collected by CookieFarm.
  • Deduplication – Duplicate flags are filtered out before submission.
  • Tick-based submission – Flags are submitted to the scoreboard automatically every tick.
  • Scoreboard integration – End‑to‑end pipeline: exploit → Go server → scoreboard.
  • Live dashboard – Monitor exploit runs, flag counts, and errors in real time from a clean web UI.
  • Charts & analytics – Visualize performance with charts and analytics to understand how your exploits are doing over time.
  • Easy configuration UI – Configure everything in the dashboard and let CookieFarm handle the rest.
  • exploit_manager decorator – Wrap a plain function (e.g. def exploit(ip, port, name)) and let the SDK handle orchestration.
  • Target iteration handled for you – The SDK iterates over all targets/IPs, you just implement the exploit body.
  • Parallel execution – Exploits are executed in parallel across all IPs for each service.
  • Under‑10‑lines demo – A working exploit example fits in under 10 lines of Python using requests and @exploit_manager.
  • CLI integration – Run exploits easily with commands like ckc exploit run -e exploit -n service
  • Team‑ready design – Built for competition environments; deploys quickly and scales with your team.
  • Simple architecture – Clear separation: you write the Python exploit, CookieFarm runs the Go server, and flags land on the scoreboard.
  • Live monitoring during CTFs – Combine the dashboard and analytics to keep track of your farm mid‑competition.

🤖 Benchmaks

DestructiveFarm VS CookieFarm

benchmarks

See the full benchmark report here.

☕ Support

Reach out to the maintainer at one of the following places:

🤝 Contributing

We welcome contributions, suggestions, and bug reports! See CONTRIBUTING.md for details on how to get involved.

💻 Authors & contributors

The original setup of this repository is by ByteTheCookies.

For a full list of all authors and contributors, see the contributors page.

⭐️ Stargazers

Star History Chart

Security

CookieFarm follows good practices of security, but 100% security cannot be assured. CookieFarm is provided "as is" without any warranty. Use at your own risk.

For more information and to report security issues, please refer to our security documentation.

🧾 License

This project is licensed under the GNU General Public License v3.

See LICENSE for more information.

Built with ❤️ by ByteTheCookies

About

CookieFarm is a Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. What sets CookieFarm apart is its hybrid Go+Python architecture and "zero distraction" approach: Your only task: write the exploit logic!

Topics

Resources

Security policy

Stars

31 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

CookieFarm Logo

VersionGitHub go.mod Go versionGitHub code size in bytesGitHub License

CookieFarm is an Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. Its strength lies in a hybrid Go + Python architecture and a zero-distraction philosophy:

🎯 Your only task is to write the exploit!

CookieFarm automates exploit distribution, flag submission, and result monitoring — allowing you to focus entirely on building powerful exploits.


⚙️ Installation

Server

bash -c "$(curl -sSL cookiefarm.bytethecookies.org/install.sh)"

Note

If you need a manual setup check out the official docs

Client

pip install --upgrade cookiefarm requests

Tip

Check if all is good with ckc --version


⚡️ Getting Started

Starting the Server

Automatic Setup

if you have already installed using the script do simple:

docker compose up --build -d

Manual Setup

  1. Clone the repository and navigate to the server directory:
git clone https://github.com/ByteTheCookies/CookieFarm.git
cd CookieFarm
  1. Create an .env file in the server directory to configure the environment settings:
# Server configurationDEBUG=false# Enable debug mode for verbose loggingPASSWORD=SuperSecret# Set a strong password for authenticationCONFIG_FILE=config.yml# Set if the server takes the config from config.yml in the filesystem; otherwise, do not set the variablePORT=8080# Define the port the server will listen on

Warning

For production environments, set DEBUG=false and use a strong, unique password

  1. Create the config.yml file in the server directory to configure the services and teams:
configured: trueserver:
url_flag_checker: "<ip_flagchecker>:<port_flagchecker>"team_token: "<your_team_token>"submit_flag_checker_time: 120max_flag_batch_size: 1000protocol: "cc_http"tick_time: 120start_time: <start_time>end_time: <end_time>flag_ttl: 5# in ticks (if the ttl is 0, the flag will never expire)shared:
services:
CookieService: 8081format_ip_teams: "10.10.{}.1"regex_flag: "[A-Z0-9]{31}="range_ip_teams: 29my_team_id: 1nop_team: 0url_flag_ids: "<address_of_flagIds>"flagids_format: "[service].[team].[id]"
  1. Start the server with Docker Compose:
docker compose -f compose.yml up --build

Note

For more configuration details, refer to the server documentation.


💻 Using the Client & Running Exploits

  1. Run the installation :
pip install --upgrade cookiefarm requests

Note

After installation, the ckc command is available globally in your terminal (or in your virtual environment if you are using one).

  1. Config the client by logging in with the server credentials:
ckc config edit -H 192.168.1.10 -p 8000
  1. Log in and configure the client:
ckc login -P SuperSecret -u your_username
  1. Install the Python helper module and create a new exploit template:
ckc exploit create -n your_exploit_name

This will generate your_exploit_name.py in ~/.cookiefarm/exploits/.

  1. Run your exploit:
ckc exploit run -e your_exploit_name.py -n CookieService -t 120 -W 40

Note

For more usage examples, check out the client documentation.


CookieFarm Architecture

🎯 Features

  • Go client and server core – High‑performance scheduler in Go handles exploit parallelism, flag collection, and timed execution cycles.
  • Python SDK – Simple client library: import, decorate/subclass, write your attack logic, done. [github]
  • Automatic flag detection – Flags printed by your exploit are automatically collected by CookieFarm.
  • Deduplication – Duplicate flags are filtered out before submission.
  • Tick-based submission – Flags are submitted to the scoreboard automatically every tick.
  • Scoreboard integration – End‑to‑end pipeline: exploit → Go server → scoreboard.
  • Live dashboard – Monitor exploit runs, flag counts, and errors in real time from a clean web UI.
  • Charts & analytics – Visualize performance with charts and analytics to understand how your exploits are doing over time.
  • Easy configuration UI – Configure everything in the dashboard and let CookieFarm handle the rest.
  • exploit_manager decorator – Wrap a plain function (e.g. def exploit(ip, port, name)) and let the SDK handle orchestration.
  • Target iteration handled for you – The SDK iterates over all targets/IPs, you just implement the exploit body.
  • Parallel execution – Exploits are executed in parallel across all IPs for each service.
  • Under‑10‑lines demo – A working exploit example fits in under 10 lines of Python using requests and @exploit_manager.
  • CLI integration – Run exploits easily with commands like ckc exploit run -e exploit -n service
  • Team‑ready design – Built for competition environments; deploys quickly and scales with your team.
  • Simple architecture – Clear separation: you write the Python exploit, CookieFarm runs the Go server, and flags land on the scoreboard.
  • Live monitoring during CTFs – Combine the dashboard and analytics to keep track of your farm mid‑competition.

🤖 Benchmaks

DestructiveFarm VS CookieFarm

benchmarks

See the full benchmark report here.

☕ Support

Reach out to the maintainer at one of the following places:

🤝 Contributing

We welcome contributions, suggestions, and bug reports! See CONTRIBUTING.md for details on how to get involved.

💻 Authors & contributors

The original setup of this repository is by ByteTheCookies.

For a full list of all authors and contributors, see the contributors page.

⭐️ Stargazers

Star History Chart

Security

CookieFarm follows good practices of security, but 100% security cannot be assured. CookieFarm is provided "as is" without any warranty. Use at your own risk.

For more information and to report security issues, please refer to our security documentation.

🧾 License

This project is licensed under the GNU General Public License v3.

See LICENSE for more information.

Built with ❤️ by ByteTheCookies

About

CookieFarm is a Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. What sets CookieFarm apart is its hybrid Go+Python architecture and "zero distraction" approach: Your only task: write the exploit logic!

Topics

Resources

Security policy

Stars

31 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

CookieFarm Logo

VersionGitHub go.mod Go versionGitHub code size in bytesGitHub License

CookieFarm is an Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. Its strength lies in a hybrid Go + Python architecture and a zero-distraction philosophy:

🎯 Your only task is to write the exploit!

CookieFarm automates exploit distribution, flag submission, and result monitoring — allowing you to focus entirely on building powerful exploits.


⚙️ Installation

Server

bash -c "$(curl -sSL cookiefarm.bytethecookies.org/install.sh)"

Note

If you need a manual setup check out the official docs

Client

pip install --upgrade cookiefarm requests

Tip

Check if all is good with ckc --version


⚡️ Getting Started

Starting the Server

Automatic Setup

if you have already installed using the script do simple:

docker compose up --build -d

Manual Setup

  1. Clone the repository and navigate to the server directory:
git clone https://github.com/ByteTheCookies/CookieFarm.git
cd CookieFarm
  1. Create an .env file in the server directory to configure the environment settings:
# Server configurationDEBUG=false# Enable debug mode for verbose loggingPASSWORD=SuperSecret# Set a strong password for authenticationCONFIG_FILE=config.yml# Set if the server takes the config from config.yml in the filesystem; otherwise, do not set the variablePORT=8080# Define the port the server will listen on

Warning

For production environments, set DEBUG=false and use a strong, unique password

  1. Create the config.yml file in the server directory to configure the services and teams:
configured: trueserver:
url_flag_checker: "<ip_flagchecker>:<port_flagchecker>"team_token: "<your_team_token>"submit_flag_checker_time: 120max_flag_batch_size: 1000protocol: "cc_http"tick_time: 120start_time: <start_time>end_time: <end_time>flag_ttl: 5# in ticks (if the ttl is 0, the flag will never expire)shared:
services:
CookieService: 8081format_ip_teams: "10.10.{}.1"regex_flag: "[A-Z0-9]{31}="range_ip_teams: 29my_team_id: 1nop_team: 0url_flag_ids: "<address_of_flagIds>"flagids_format: "[service].[team].[id]"
  1. Start the server with Docker Compose:
docker compose -f compose.yml up --build

Note

For more configuration details, refer to the server documentation.


💻 Using the Client & Running Exploits

  1. Run the installation :
pip install --upgrade cookiefarm requests

Note

After installation, the ckc command is available globally in your terminal (or in your virtual environment if you are using one).

  1. Config the client by logging in with the server credentials:
ckc config edit -H 192.168.1.10 -p 8000
  1. Log in and configure the client:
ckc login -P SuperSecret -u your_username
  1. Install the Python helper module and create a new exploit template:
ckc exploit create -n your_exploit_name

This will generate your_exploit_name.py in ~/.cookiefarm/exploits/.

  1. Run your exploit:
ckc exploit run -e your_exploit_name.py -n CookieService -t 120 -W 40

Note

For more usage examples, check out the client documentation.


CookieFarm Architecture

🎯 Features

  • Go client and server core – High‑performance scheduler in Go handles exploit parallelism, flag collection, and timed execution cycles.
  • Python SDK – Simple client library: import, decorate/subclass, write your attack logic, done. [github]
  • Automatic flag detection – Flags printed by your exploit are automatically collected by CookieFarm.
  • Deduplication – Duplicate flags are filtered out before submission.
  • Tick-based submission – Flags are submitted to the scoreboard automatically every tick.
  • Scoreboard integration – End‑to‑end pipeline: exploit → Go server → scoreboard.
  • Live dashboard – Monitor exploit runs, flag counts, and errors in real time from a clean web UI.
  • Charts & analytics – Visualize performance with charts and analytics to understand how your exploits are doing over time.
  • Easy configuration UI – Configure everything in the dashboard and let CookieFarm handle the rest.
  • exploit_manager decorator – Wrap a plain function (e.g. def exploit(ip, port, name)) and let the SDK handle orchestration.
  • Target iteration handled for you – The SDK iterates over all targets/IPs, you just implement the exploit body.
  • Parallel execution – Exploits are executed in parallel across all IPs for each service.
  • Under‑10‑lines demo – A working exploit example fits in under 10 lines of Python using requests and @exploit_manager.
  • CLI integration – Run exploits easily with commands like ckc exploit run -e exploit -n service
  • Team‑ready design – Built for competition environments; deploys quickly and scales with your team.
  • Simple architecture – Clear separation: you write the Python exploit, CookieFarm runs the Go server, and flags land on the scoreboard.
  • Live monitoring during CTFs – Combine the dashboard and analytics to keep track of your farm mid‑competition.

🤖 Benchmaks

DestructiveFarm VS CookieFarm

benchmarks

See the full benchmark report here.

☕ Support

Reach out to the maintainer at one of the following places:

🤝 Contributing

We welcome contributions, suggestions, and bug reports! See CONTRIBUTING.md for details on how to get involved.

💻 Authors & contributors

The original setup of this repository is by ByteTheCookies.

For a full list of all authors and contributors, see the contributors page.

⭐️ Stargazers

Star History Chart

Security

CookieFarm follows good practices of security, but 100% security cannot be assured. CookieFarm is provided "as is" without any warranty. Use at your own risk.

For more information and to report security issues, please refer to our security documentation.

🧾 License

This project is licensed under the GNU General Public License v3.

See LICENSE for more information.

Built with ❤️ by ByteTheCookies

About

CookieFarm is a Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. What sets CookieFarm apart is its hybrid Go+Python architecture and "zero distraction" approach: Your only task: write the exploit logic!

Topics

Resources

Security policy

Stars

31 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

CookieFarm Logo

VersionGitHub go.mod Go versionGitHub code size in bytesGitHub License

CookieFarm is an Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. Its strength lies in a hybrid Go + Python architecture and a zero-distraction philosophy:

🎯 Your only task is to write the exploit!

CookieFarm automates exploit distribution, flag submission, and result monitoring — allowing you to focus entirely on building powerful exploits.


⚙️ Installation

Server

bash -c "$(curl -sSL cookiefarm.bytethecookies.org/install.sh)"

Note

If you need a manual setup check out the official docs

Client

pip install --upgrade cookiefarm requests

Tip

Check if all is good with ckc --version


⚡️ Getting Started

Starting the Server

Automatic Setup

if you have already installed using the script do simple:

docker compose up --build -d

Manual Setup

  1. Clone the repository and navigate to the server directory:
git clone https://github.com/ByteTheCookies/CookieFarm.git
cd CookieFarm
  1. Create an .env file in the server directory to configure the environment settings:
# Server configurationDEBUG=false# Enable debug mode for verbose loggingPASSWORD=SuperSecret# Set a strong password for authenticationCONFIG_FILE=config.yml# Set if the server takes the config from config.yml in the filesystem; otherwise, do not set the variablePORT=8080# Define the port the server will listen on

Warning

For production environments, set DEBUG=false and use a strong, unique password

  1. Create the config.yml file in the server directory to configure the services and teams:
configured: trueserver:
url_flag_checker: "<ip_flagchecker>:<port_flagchecker>"team_token: "<your_team_token>"submit_flag_checker_time: 120max_flag_batch_size: 1000protocol: "cc_http"tick_time: 120start_time: <start_time>end_time: <end_time>flag_ttl: 5# in ticks (if the ttl is 0, the flag will never expire)shared:
services:
CookieService: 8081format_ip_teams: "10.10.{}.1"regex_flag: "[A-Z0-9]{31}="range_ip_teams: 29my_team_id: 1nop_team: 0url_flag_ids: "<address_of_flagIds>"flagids_format: "[service].[team].[id]"
  1. Start the server with Docker Compose:
docker compose -f compose.yml up --build

Note

For more configuration details, refer to the server documentation.


💻 Using the Client & Running Exploits

  1. Run the installation :
pip install --upgrade cookiefarm requests

Note

After installation, the ckc command is available globally in your terminal (or in your virtual environment if you are using one).

  1. Config the client by logging in with the server credentials:
ckc config edit -H 192.168.1.10 -p 8000
  1. Log in and configure the client:
ckc login -P SuperSecret -u your_username
  1. Install the Python helper module and create a new exploit template:
ckc exploit create -n your_exploit_name

This will generate your_exploit_name.py in ~/.cookiefarm/exploits/.

  1. Run your exploit:
ckc exploit run -e your_exploit_name.py -n CookieService -t 120 -W 40

Note

For more usage examples, check out the client documentation.


CookieFarm Architecture

🎯 Features

  • Go client and server core – High‑performance scheduler in Go handles exploit parallelism, flag collection, and timed execution cycles.
  • Python SDK – Simple client library: import, decorate/subclass, write your attack logic, done. [github]
  • Automatic flag detection – Flags printed by your exploit are automatically collected by CookieFarm.
  • Deduplication – Duplicate flags are filtered out before submission.
  • Tick-based submission – Flags are submitted to the scoreboard automatically every tick.
  • Scoreboard integration – End‑to‑end pipeline: exploit → Go server → scoreboard.
  • Live dashboard – Monitor exploit runs, flag counts, and errors in real time from a clean web UI.
  • Charts & analytics – Visualize performance with charts and analytics to understand how your exploits are doing over time.
  • Easy configuration UI – Configure everything in the dashboard and let CookieFarm handle the rest.
  • exploit_manager decorator – Wrap a plain function (e.g. def exploit(ip, port, name)) and let the SDK handle orchestration.
  • Target iteration handled for you – The SDK iterates over all targets/IPs, you just implement the exploit body.
  • Parallel execution – Exploits are executed in parallel across all IPs for each service.
  • Under‑10‑lines demo – A working exploit example fits in under 10 lines of Python using requests and @exploit_manager.
  • CLI integration – Run exploits easily with commands like ckc exploit run -e exploit -n service
  • Team‑ready design – Built for competition environments; deploys quickly and scales with your team.
  • Simple architecture – Clear separation: you write the Python exploit, CookieFarm runs the Go server, and flags land on the scoreboard.
  • Live monitoring during CTFs – Combine the dashboard and analytics to keep track of your farm mid‑competition.

🤖 Benchmaks

DestructiveFarm VS CookieFarm

benchmarks

See the full benchmark report here.

☕ Support

Reach out to the maintainer at one of the following places:

🤝 Contributing

We welcome contributions, suggestions, and bug reports! See CONTRIBUTING.md for details on how to get involved.

💻 Authors & contributors

The original setup of this repository is by ByteTheCookies.

For a full list of all authors and contributors, see the contributors page.

⭐️ Stargazers

Star History Chart

Security

CookieFarm follows good practices of security, but 100% security cannot be assured. CookieFarm is provided "as is" without any warranty. Use at your own risk.

For more information and to report security issues, please refer to our security documentation.

🧾 License

This project is licensed under the GNU General Public License v3.

See LICENSE for more information.

Built with ❤️ by ByteTheCookies

About

CookieFarm is a Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. What sets CookieFarm apart is its hybrid Go+Python architecture and "zero distraction" approach: Your only task: write the exploit logic!

Topics

Resources

Security policy

Stars

31 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

CookieFarm Logo

VersionGitHub go.mod Go versionGitHub code size in bytesGitHub License

CookieFarm is an Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. Its strength lies in a hybrid Go + Python architecture and a zero-distraction philosophy:

🎯 Your only task is to write the exploit!

CookieFarm automates exploit distribution, flag submission, and result monitoring — allowing you to focus entirely on building powerful exploits.


⚙️ Installation

Server

bash -c "$(curl -sSL cookiefarm.bytethecookies.org/install.sh)"

Note

If you need a manual setup check out the official docs

Client

pip install --upgrade cookiefarm requests

Tip

Check if all is good with ckc --version


⚡️ Getting Started

Starting the Server

Automatic Setup

if you have already installed using the script do simple:

docker compose up --build -d

Manual Setup

  1. Clone the repository and navigate to the server directory:
git clone https://github.com/ByteTheCookies/CookieFarm.git
cd CookieFarm
  1. Create an .env file in the server directory to configure the environment settings:
# Server configurationDEBUG=false# Enable debug mode for verbose loggingPASSWORD=SuperSecret# Set a strong password for authenticationCONFIG_FILE=config.yml# Set if the server takes the config from config.yml in the filesystem; otherwise, do not set the variablePORT=8080# Define the port the server will listen on

Warning

For production environments, set DEBUG=false and use a strong, unique password

  1. Create the config.yml file in the server directory to configure the services and teams:
configured: trueserver:
url_flag_checker: "<ip_flagchecker>:<port_flagchecker>"team_token: "<your_team_token>"submit_flag_checker_time: 120max_flag_batch_size: 1000protocol: "cc_http"tick_time: 120start_time: <start_time>end_time: <end_time>flag_ttl: 5# in ticks (if the ttl is 0, the flag will never expire)shared:
services:
CookieService: 8081format_ip_teams: "10.10.{}.1"regex_flag: "[A-Z0-9]{31}="range_ip_teams: 29my_team_id: 1nop_team: 0url_flag_ids: "<address_of_flagIds>"flagids_format: "[service].[team].[id]"
  1. Start the server with Docker Compose:
docker compose -f compose.yml up --build

Note

For more configuration details, refer to the server documentation.


💻 Using the Client & Running Exploits

  1. Run the installation :
pip install --upgrade cookiefarm requests

Note

After installation, the ckc command is available globally in your terminal (or in your virtual environment if you are using one).

  1. Config the client by logging in with the server credentials:
ckc config edit -H 192.168.1.10 -p 8000
  1. Log in and configure the client:
ckc login -P SuperSecret -u your_username
  1. Install the Python helper module and create a new exploit template:
ckc exploit create -n your_exploit_name

This will generate your_exploit_name.py in ~/.cookiefarm/exploits/.

  1. Run your exploit:
ckc exploit run -e your_exploit_name.py -n CookieService -t 120 -W 40

Note

For more usage examples, check out the client documentation.


CookieFarm Architecture

🎯 Features

  • Go client and server core – High‑performance scheduler in Go handles exploit parallelism, flag collection, and timed execution cycles.
  • Python SDK – Simple client library: import, decorate/subclass, write your attack logic, done. [github]
  • Automatic flag detection – Flags printed by your exploit are automatically collected by CookieFarm.
  • Deduplication – Duplicate flags are filtered out before submission.
  • Tick-based submission – Flags are submitted to the scoreboard automatically every tick.
  • Scoreboard integration – End‑to‑end pipeline: exploit → Go server → scoreboard.
  • Live dashboard – Monitor exploit runs, flag counts, and errors in real time from a clean web UI.
  • Charts & analytics – Visualize performance with charts and analytics to understand how your exploits are doing over time.
  • Easy configuration UI – Configure everything in the dashboard and let CookieFarm handle the rest.
  • exploit_manager decorator – Wrap a plain function (e.g. def exploit(ip, port, name)) and let the SDK handle orchestration.
  • Target iteration handled for you – The SDK iterates over all targets/IPs, you just implement the exploit body.
  • Parallel execution – Exploits are executed in parallel across all IPs for each service.
  • Under‑10‑lines demo – A working exploit example fits in under 10 lines of Python using requests and @exploit_manager.
  • CLI integration – Run exploits easily with commands like ckc exploit run -e exploit -n service
  • Team‑ready design – Built for competition environments; deploys quickly and scales with your team.
  • Simple architecture – Clear separation: you write the Python exploit, CookieFarm runs the Go server, and flags land on the scoreboard.
  • Live monitoring during CTFs – Combine the dashboard and analytics to keep track of your farm mid‑competition.

🤖 Benchmaks

DestructiveFarm VS CookieFarm

benchmarks

See the full benchmark report here.

☕ Support

Reach out to the maintainer at one of the following places:

🤝 Contributing

We welcome contributions, suggestions, and bug reports! See CONTRIBUTING.md for details on how to get involved.

💻 Authors & contributors

The original setup of this repository is by ByteTheCookies.

For a full list of all authors and contributors, see the contributors page.

⭐️ Stargazers

Star History Chart

Security

CookieFarm follows good practices of security, but 100% security cannot be assured. CookieFarm is provided "as is" without any warranty. Use at your own risk.

For more information and to report security issues, please refer to our security documentation.

🧾 License

This project is licensed under the GNU General Public License v3.

See LICENSE for more information.

Built with ❤️ by ByteTheCookies

About

CookieFarm is a Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. What sets CookieFarm apart is its hybrid Go+Python architecture and "zero distraction" approach: Your only task: write the exploit logic!

Topics

Resources

Security policy

Stars

31 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

CookieFarm Logo

VersionGitHub go.mod Go versionGitHub code size in bytesGitHub License

CookieFarm is an Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. Its strength lies in a hybrid Go + Python architecture and a zero-distraction philosophy:

🎯 Your only task is to write the exploit!

CookieFarm automates exploit distribution, flag submission, and result monitoring — allowing you to focus entirely on building powerful exploits.


⚙️ Installation

Server

bash -c "$(curl -sSL cookiefarm.bytethecookies.org/install.sh)"

Note

If you need a manual setup check out the official docs

Client

pip install --upgrade cookiefarm requests

Tip

Check if all is good with ckc --version


⚡️ Getting Started

Starting the Server

Automatic Setup

if you have already installed using the script do simple:

docker compose up --build -d

Manual Setup

  1. Clone the repository and navigate to the server directory:
git clone https://github.com/ByteTheCookies/CookieFarm.git
cd CookieFarm
  1. Create an .env file in the server directory to configure the environment settings:
# Server configurationDEBUG=false# Enable debug mode for verbose loggingPASSWORD=SuperSecret# Set a strong password for authenticationCONFIG_FILE=config.yml# Set if the server takes the config from config.yml in the filesystem; otherwise, do not set the variablePORT=8080# Define the port the server will listen on

Warning

For production environments, set DEBUG=false and use a strong, unique password

  1. Create the config.yml file in the server directory to configure the services and teams:
configured: trueserver:
url_flag_checker: "<ip_flagchecker>:<port_flagchecker>"team_token: "<your_team_token>"submit_flag_checker_time: 120max_flag_batch_size: 1000protocol: "cc_http"tick_time: 120start_time: <start_time>end_time: <end_time>flag_ttl: 5# in ticks (if the ttl is 0, the flag will never expire)shared:
services:
CookieService: 8081format_ip_teams: "10.10.{}.1"regex_flag: "[A-Z0-9]{31}="range_ip_teams: 29my_team_id: 1nop_team: 0url_flag_ids: "<address_of_flagIds>"flagids_format: "[service].[team].[id]"
  1. Start the server with Docker Compose:
docker compose -f compose.yml up --build

Note

For more configuration details, refer to the server documentation.


💻 Using the Client & Running Exploits

  1. Run the installation :
pip install --upgrade cookiefarm requests

Note

After installation, the ckc command is available globally in your terminal (or in your virtual environment if you are using one).

  1. Config the client by logging in with the server credentials:
ckc config edit -H 192.168.1.10 -p 8000
  1. Log in and configure the client:
ckc login -P SuperSecret -u your_username
  1. Install the Python helper module and create a new exploit template:
ckc exploit create -n your_exploit_name

This will generate your_exploit_name.py in ~/.cookiefarm/exploits/.

  1. Run your exploit:
ckc exploit run -e your_exploit_name.py -n CookieService -t 120 -W 40

Note

For more usage examples, check out the client documentation.


CookieFarm Architecture

🎯 Features

  • Go client and server core – High‑performance scheduler in Go handles exploit parallelism, flag collection, and timed execution cycles.
  • Python SDK – Simple client library: import, decorate/subclass, write your attack logic, done. [github]
  • Automatic flag detection – Flags printed by your exploit are automatically collected by CookieFarm.
  • Deduplication – Duplicate flags are filtered out before submission.
  • Tick-based submission – Flags are submitted to the scoreboard automatically every tick.
  • Scoreboard integration – End‑to‑end pipeline: exploit → Go server → scoreboard.
  • Live dashboard – Monitor exploit runs, flag counts, and errors in real time from a clean web UI.
  • Charts & analytics – Visualize performance with charts and analytics to understand how your exploits are doing over time.
  • Easy configuration UI – Configure everything in the dashboard and let CookieFarm handle the rest.
  • exploit_manager decorator – Wrap a plain function (e.g. def exploit(ip, port, name)) and let the SDK handle orchestration.
  • Target iteration handled for you – The SDK iterates over all targets/IPs, you just implement the exploit body.
  • Parallel execution – Exploits are executed in parallel across all IPs for each service.
  • Under‑10‑lines demo – A working exploit example fits in under 10 lines of Python using requests and @exploit_manager.
  • CLI integration – Run exploits easily with commands like ckc exploit run -e exploit -n service
  • Team‑ready design – Built for competition environments; deploys quickly and scales with your team.
  • Simple architecture – Clear separation: you write the Python exploit, CookieFarm runs the Go server, and flags land on the scoreboard.
  • Live monitoring during CTFs – Combine the dashboard and analytics to keep track of your farm mid‑competition.

🤖 Benchmaks

DestructiveFarm VS CookieFarm

benchmarks

See the full benchmark report here.

☕ Support

Reach out to the maintainer at one of the following places:

🤝 Contributing

We welcome contributions, suggestions, and bug reports! See CONTRIBUTING.md for details on how to get involved.

💻 Authors & contributors

The original setup of this repository is by ByteTheCookies.

For a full list of all authors and contributors, see the contributors page.

⭐️ Stargazers

Star History Chart

Security

CookieFarm follows good practices of security, but 100% security cannot be assured. CookieFarm is provided "as is" without any warranty. Use at your own risk.

For more information and to report security issues, please refer to our security documentation.

🧾 License

This project is licensed under the GNU General Public License v3.

See LICENSE for more information.

Built with ❤️ by ByteTheCookies

About

CookieFarm is a Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. What sets CookieFarm apart is its hybrid Go+Python architecture and "zero distraction" approach: Your only task: write the exploit logic!

Topics

Resources

Security policy

Stars

31 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

CookieFarm Logo

VersionGitHub go.mod Go versionGitHub code size in bytesGitHub License

CookieFarm is an Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. Its strength lies in a hybrid Go + Python architecture and a zero-distraction philosophy:

🎯 Your only task is to write the exploit!

CookieFarm automates exploit distribution, flag submission, and result monitoring — allowing you to focus entirely on building powerful exploits.


⚙️ Installation

Server

bash -c "$(curl -sSL cookiefarm.bytethecookies.org/install.sh)"

Note

If you need a manual setup check out the official docs

Client

pip install --upgrade cookiefarm requests

Tip

Check if all is good with ckc --version


⚡️ Getting Started

Starting the Server

Automatic Setup

if you have already installed using the script do simple:

docker compose up --build -d

Manual Setup

  1. Clone the repository and navigate to the server directory:
git clone https://github.com/ByteTheCookies/CookieFarm.git
cd CookieFarm
  1. Create an .env file in the server directory to configure the environment settings:
# Server configurationDEBUG=false# Enable debug mode for verbose loggingPASSWORD=SuperSecret# Set a strong password for authenticationCONFIG_FILE=config.yml# Set if the server takes the config from config.yml in the filesystem; otherwise, do not set the variablePORT=8080# Define the port the server will listen on

Warning

For production environments, set DEBUG=false and use a strong, unique password

  1. Create the config.yml file in the server directory to configure the services and teams:
configured: trueserver:
url_flag_checker: "<ip_flagchecker>:<port_flagchecker>"team_token: "<your_team_token>"submit_flag_checker_time: 120max_flag_batch_size: 1000protocol: "cc_http"tick_time: 120start_time: <start_time>end_time: <end_time>flag_ttl: 5# in ticks (if the ttl is 0, the flag will never expire)shared:
services:
CookieService: 8081format_ip_teams: "10.10.{}.1"regex_flag: "[A-Z0-9]{31}="range_ip_teams: 29my_team_id: 1nop_team: 0url_flag_ids: "<address_of_flagIds>"flagids_format: "[service].[team].[id]"
  1. Start the server with Docker Compose:
docker compose -f compose.yml up --build

Note

For more configuration details, refer to the server documentation.


💻 Using the Client & Running Exploits

  1. Run the installation :
pip install --upgrade cookiefarm requests

Note

After installation, the ckc command is available globally in your terminal (or in your virtual environment if you are using one).

  1. Config the client by logging in with the server credentials:
ckc config edit -H 192.168.1.10 -p 8000
  1. Log in and configure the client:
ckc login -P SuperSecret -u your_username
  1. Install the Python helper module and create a new exploit template:
ckc exploit create -n your_exploit_name

This will generate your_exploit_name.py in ~/.cookiefarm/exploits/.

  1. Run your exploit:
ckc exploit run -e your_exploit_name.py -n CookieService -t 120 -W 40

Note

For more usage examples, check out the client documentation.


CookieFarm Architecture

🎯 Features

  • Go client and server core – High‑performance scheduler in Go handles exploit parallelism, flag collection, and timed execution cycles.
  • Python SDK – Simple client library: import, decorate/subclass, write your attack logic, done. [github]
  • Automatic flag detection – Flags printed by your exploit are automatically collected by CookieFarm.
  • Deduplication – Duplicate flags are filtered out before submission.
  • Tick-based submission – Flags are submitted to the scoreboard automatically every tick.
  • Scoreboard integration – End‑to‑end pipeline: exploit → Go server → scoreboard.
  • Live dashboard – Monitor exploit runs, flag counts, and errors in real time from a clean web UI.
  • Charts & analytics – Visualize performance with charts and analytics to understand how your exploits are doing over time.
  • Easy configuration UI – Configure everything in the dashboard and let CookieFarm handle the rest.
  • exploit_manager decorator – Wrap a plain function (e.g. def exploit(ip, port, name)) and let the SDK handle orchestration.
  • Target iteration handled for you – The SDK iterates over all targets/IPs, you just implement the exploit body.
  • Parallel execution – Exploits are executed in parallel across all IPs for each service.
  • Under‑10‑lines demo – A working exploit example fits in under 10 lines of Python using requests and @exploit_manager.
  • CLI integration – Run exploits easily with commands like ckc exploit run -e exploit -n service
  • Team‑ready design – Built for competition environments; deploys quickly and scales with your team.
  • Simple architecture – Clear separation: you write the Python exploit, CookieFarm runs the Go server, and flags land on the scoreboard.
  • Live monitoring during CTFs – Combine the dashboard and analytics to keep track of your farm mid‑competition.

🤖 Benchmaks

DestructiveFarm VS CookieFarm

benchmarks

See the full benchmark report here.

☕ Support

Reach out to the maintainer at one of the following places:

🤝 Contributing

We welcome contributions, suggestions, and bug reports! See CONTRIBUTING.md for details on how to get involved.

💻 Authors & contributors

The original setup of this repository is by ByteTheCookies.

For a full list of all authors and contributors, see the contributors page.

⭐️ Stargazers

Star History Chart

Security

CookieFarm follows good practices of security, but 100% security cannot be assured. CookieFarm is provided "as is" without any warranty. Use at your own risk.

For more information and to report security issues, please refer to our security documentation.

🧾 License

This project is licensed under the GNU General Public License v3.

See LICENSE for more information.

Built with ❤️ by ByteTheCookies

About

CookieFarm is a Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. What sets CookieFarm apart is its hybrid Go+Python architecture and "zero distraction" approach: Your only task: write the exploit logic!

Topics

Resources

Security policy

Stars

31 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

CookieFarm Logo

VersionGitHub go.mod Go versionGitHub code size in bytesGitHub License

CookieFarm is an Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. Its strength lies in a hybrid Go + Python architecture and a zero-distraction philosophy:

🎯 Your only task is to write the exploit!

CookieFarm automates exploit distribution, flag submission, and result monitoring — allowing you to focus entirely on building powerful exploits.


⚙️ Installation

Server

bash -c "$(curl -sSL cookiefarm.bytethecookies.org/install.sh)"

Note

If you need a manual setup check out the official docs

Client

pip install --upgrade cookiefarm requests

Tip

Check if all is good with ckc --version


⚡️ Getting Started

Starting the Server

Automatic Setup

if you have already installed using the script do simple:

docker compose up --build -d

Manual Setup

  1. Clone the repository and navigate to the server directory:
git clone https://github.com/ByteTheCookies/CookieFarm.git
cd CookieFarm
  1. Create an .env file in the server directory to configure the environment settings:
# Server configurationDEBUG=false# Enable debug mode for verbose loggingPASSWORD=SuperSecret# Set a strong password for authenticationCONFIG_FILE=config.yml# Set if the server takes the config from config.yml in the filesystem; otherwise, do not set the variablePORT=8080# Define the port the server will listen on

Warning

For production environments, set DEBUG=false and use a strong, unique password

  1. Create the config.yml file in the server directory to configure the services and teams:
configured: trueserver:
url_flag_checker: "<ip_flagchecker>:<port_flagchecker>"team_token: "<your_team_token>"submit_flag_checker_time: 120max_flag_batch_size: 1000protocol: "cc_http"tick_time: 120start_time: <start_time>end_time: <end_time>flag_ttl: 5# in ticks (if the ttl is 0, the flag will never expire)shared:
services:
CookieService: 8081format_ip_teams: "10.10.{}.1"regex_flag: "[A-Z0-9]{31}="range_ip_teams: 29my_team_id: 1nop_team: 0url_flag_ids: "<address_of_flagIds>"flagids_format: "[service].[team].[id]"
  1. Start the server with Docker Compose:
docker compose -f compose.yml up --build

Note

For more configuration details, refer to the server documentation.


💻 Using the Client & Running Exploits

  1. Run the installation :
pip install --upgrade cookiefarm requests

Note

After installation, the ckc command is available globally in your terminal (or in your virtual environment if you are using one).

  1. Config the client by logging in with the server credentials:
ckc config edit -H 192.168.1.10 -p 8000
  1. Log in and configure the client:
ckc login -P SuperSecret -u your_username
  1. Install the Python helper module and create a new exploit template:
ckc exploit create -n your_exploit_name

This will generate your_exploit_name.py in ~/.cookiefarm/exploits/.

  1. Run your exploit:
ckc exploit run -e your_exploit_name.py -n CookieService -t 120 -W 40

Note

For more usage examples, check out the client documentation.


CookieFarm Architecture

🎯 Features

  • Go client and server core – High‑performance scheduler in Go handles exploit parallelism, flag collection, and timed execution cycles.
  • Python SDK – Simple client library: import, decorate/subclass, write your attack logic, done. [github]
  • Automatic flag detection – Flags printed by your exploit are automatically collected by CookieFarm.
  • Deduplication – Duplicate flags are filtered out before submission.
  • Tick-based submission – Flags are submitted to the scoreboard automatically every tick.
  • Scoreboard integration – End‑to‑end pipeline: exploit → Go server → scoreboard.
  • Live dashboard – Monitor exploit runs, flag counts, and errors in real time from a clean web UI.
  • Charts & analytics – Visualize performance with charts and analytics to understand how your exploits are doing over time.
  • Easy configuration UI – Configure everything in the dashboard and let CookieFarm handle the rest.
  • exploit_manager decorator – Wrap a plain function (e.g. def exploit(ip, port, name)) and let the SDK handle orchestration.
  • Target iteration handled for you – The SDK iterates over all targets/IPs, you just implement the exploit body.
  • Parallel execution – Exploits are executed in parallel across all IPs for each service.
  • Under‑10‑lines demo – A working exploit example fits in under 10 lines of Python using requests and @exploit_manager.
  • CLI integration – Run exploits easily with commands like ckc exploit run -e exploit -n service
  • Team‑ready design – Built for competition environments; deploys quickly and scales with your team.
  • Simple architecture – Clear separation: you write the Python exploit, CookieFarm runs the Go server, and flags land on the scoreboard.
  • Live monitoring during CTFs – Combine the dashboard and analytics to keep track of your farm mid‑competition.

🤖 Benchmaks

DestructiveFarm VS CookieFarm

benchmarks

See the full benchmark report here.

☕ Support

Reach out to the maintainer at one of the following places:

🤝 Contributing

We welcome contributions, suggestions, and bug reports! See CONTRIBUTING.md for details on how to get involved.

💻 Authors & contributors

The original setup of this repository is by ByteTheCookies.

For a full list of all authors and contributors, see the contributors page.

⭐️ Stargazers

Star History Chart

Security

CookieFarm follows good practices of security, but 100% security cannot be assured. CookieFarm is provided "as is" without any warranty. Use at your own risk.

For more information and to report security issues, please refer to our security documentation.

🧾 License

This project is licensed under the GNU General Public License v3.

See LICENSE for more information.

Built with ❤️ by ByteTheCookies

About

CookieFarm is a Attack/Defense CTF framework inspired by DestructiveFarm, developed by the Italian team ByteTheCookies. What sets CookieFarm apart is its hybrid Go+Python architecture and "zero distraction" approach: Your only task: write the exploit logic!

Topics

Resources

Security policy

Stars

31 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages