# Hello-CTF: A Free Chinese-Language CTF Course You Can Self-Host

> Hello-CTF is an open, GPL-3.0 licensed MkDocs site that teaches CTF basics across five directions and ships the challenge files with each lesson. It is aimed at beginners, but the tutorial content is written in Chinese and the site is built for contributors as much as readers.

**ProbiusOfficial/Hello-CTF** — 【Hello CTF】题目配套，免费开源的CTF入门教程，针对0基础新手编写，同时兼顾信息差的填补，对各阶段的CTFer都友好的开源教程，致力于CTF和网络安全的开源生态！

- Repository: https://github.com/ProbiusOfficial/Hello-CTF
- Website: https://hello-ctf.com/
- Stars: 4,230 · Forks: 260
- Language: HTML
- License: GPL-3.0
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/probiusofficial-hello-ctf

## What Hello-CTF Actually Solves for a New CTF Player

The README is blunt about the problem: people hear about CTF, want to compete, and burn most of their energy just locating study material. The second motivation is repetition. Every recruitment season, experienced players answer the same beginner questions again. Hello-CTF is the maintainers' attempt to write those answers down once, as a free open book.

The intended reader is someone at zero. The README describes the project as a "夺旗赛 | CTF(Capture The Flag)" introductory tutorial written for newcomers, while also trying to close information gaps for players at later stages. That dual audience shows up in the structure: the main tutorial covers MISC, Web, Crypto, Reverse and Pwn, and the README lists extension directions including AWD, AI and Blockchain.

The distinguishing design choice is that lessons come with challenges. For each direction the project says it tries to supply the challenge attachment, the challenge source and a Dockerfile, so a reader can deploy the target locally or start it on the NSSCTF platform. That matters because reading about a vulnerability class and actually solving one are different activities. Most free tutorial sites stop at the first.

## How the Site Is Built: MkDocs Material, Python, and a Daily Events Job

The repository is a documentation site, not an application. It is built on Mkdocs-Material and deployed through GitHub Pages at hello-ctf.com. The README credits the 渊龙Sec security team and AabyssZG for CDN support, which tells you the public site is not served straight from GitHub Pages without help.

The layout is worth reading before you fork it. docs/ holds the site source: tutorial documents, a custom home page, sidebar feature pages and event data. overrides/ holds theme overrides for Mkdocs-Material. build.py and events_update.py are the event data update scripts, and the README states they run automatically every day through a GitHub Action. admin/ is a site management panel for events, home content, documents and deployment. collector/ is a message collector that receives event submissions and feedback.

The events feature is the most concrete piece of engineering in the project. According to the README, overseas events are updated daily from the CTFtime RSS feed, domestic events are maintained by hand, and the site offers ICS calendar subscription plus a submission entry point. That split is honest about its own limits: an RSS feed can be automated, a hand-maintained list cannot.

One detail in requirements.txt deserves attention. The file carries a comment stating that versions are locked because the theme modifications in overrides/ and the CSS variables are bound to the mkdocs-material version, and that upgrading requires deliberate regression testing. That is a real maintenance constraint, not boilerplate.

## Running Hello-CTF Locally with pip or Docker Compose

The README gives two paths. The Python path assumes you have cloned the repository and installed the pinned dependencies from requirements.txt, then starts the MkDocs development server.

```bash
pip install -r requirements.txt
mkdocs serve
```

After that command, MkDocs serves the site locally. The README points to http://127.0.0.1:8000 for preview. This is the path to use if you want live reload while editing pages under docs/.

The Docker path builds the image from the included Dockerfile and starts the same server through Compose.

```bash
docker compose up --build
```

The Compose file maps port 8000 to 8000 and names the container hello-ctf. The Dockerfile is based on python:3.12.12-alpine, installs build-base, copies requirements.txt, mkdocs.yml, overrides/ and docs/, exposes 8000, and runs mkdocs serve -a 0.0.0.0:8000. Note what is not copied: admin/, collector/ and the update scripts are absent from the image, so the container serves the documentation only. If you need the event updater or the management panel, the Docker path will not give them to you.

For a first real use, edit a page under docs/, save, and reload the browser. The change appears without restarting the server under mkdocs serve. That is the loop contributors work in.

## The Maintenance Cost Is the Theme Overrides, Not the Markdown

Adding a lesson to Hello-CTF is cheap: write Markdown in docs/ and MkDocs renders it. The expensive part is the fork's relationship to upstream Mkdocs-Material.

The requirements.txt comment says the overrides and CSS variables are tied to the theme version, and that an upgrade needs active regression checking. Practically, that means you cannot casually bump mkdocs-material and expect the site to look right. Every theme release becomes a small migration project. The pinned versions in the file (mkdocs 1.6.1, mkdocs-material 9.7.7, mkdocs-video 1.5.0, feedparser 6.0.12, requests 2.34.2) are the tested combination, and the file's own comment says so.

There is a second cost, and the README does not address it. The events pipeline depends on the CTFtime RSS feed and on manual updates for domestic events. RSS formats change, feeds go down, and a hand-maintained list needs a human every week. The daily GitHub Action keeps the overseas side moving, but nothing in the repository description suggests the domestic side is automated. If you fork this site for your own community, you inherit that manual chore.

Licensing adds a third consideration. The repository is GPL-3.0, and the README asks that anyone republishing the project carry the source address. There is also a separate LICENSE-doc file in the repository root, which suggests documentation content may be licensed differently from code. The README does not explain the distinction, so read both files before you republish anything. This is not legal advice; it is a pointer to the two files that matter.

## Where Hello-CTF Is the Wrong Tool

The largest limitation is language. The README, the site and the tutorial content are in Chinese. The repository description and the online reading badge are Chinese. If your team does not read Chinese, the main tutorial is not usable, and the project does not advertise an English edition.

Second, this is a CTF course, not a security reference. The topic list, the challenge attachments and the Dockerfile-per-challenge model are all built around competition preparation. Someone looking for a general application-security handbook, a threat modelling guide or a penetration-testing methodology will not find it here. The scope is deliberately narrow.

Third, the project is a documentation site with a small amount of supporting tooling. It is not a platform. There is no scoring server, no team management, no submission judging. The README points readers to NSSCTF to start challenges online, which is an external platform, not part of this repository. If what you actually need is a self-hosted CTF platform, Hello-CTF is the wrong layer.

Finally, the online reading experience depends on the deployed site and its CDN. The README thanks a third party for CDN support. A self-hosted copy removes that dependency, which is one reason to run it locally rather than only reading the public site.

## Hello-CTF Compared with CTF Wiki and Platform-Backed Tutorials

The natural alternative for a Chinese-reading audience is CTF Wiki, which appears in the related search terms alongside Hello-CTF. The difference in approach is structural. CTF Wiki is a reference wiki: topic pages you consult when you need to look something up. Hello-CTF is a course: ordered lessons with a stated progression from beginner to intermediate, and each knowledge point is meant to come with a challenge you can deploy and solve. If you want to look up how a class of vulnerability works, a wiki is faster. If you want a path through the material with exercises attached, Hello-CTF is built for that.

The other comparison is platform-backed tutorial content, the kind attached to NSSCTF, BUU CTF, QSNCTF or CTFshow. Those platforms pair challenges with writeups inside their own environment. Hello-CTF deliberately sits outside any single platform: the README says challenges can be deployed locally or opened on NSSCTF, and it ships the Dockerfiles so local deployment is real. The trade-off is that you provide the environment. A platform gives you a working challenge in one click; Hello-CTF gives you the files and expects you to run them.

A third reference point is Advent of CTF, which appears in the same search list. That is a time-boxed, daily-challenge format. Hello-CTF is not time-boxed; it is a book that keeps growing, and the README states the project is still being updated and welcomes pull requests.

## Who Should Adopt Hello-CTF, and What to Check First

Adopt it if you are a Chinese-reading beginner who wants a structured route into CTF with runnable challenges, or an instructor, student group or security team that wants to self-host a course site and point newcomers at it. The Docker path makes that cheap: one compose command and the site is on port 8000.

Do not adopt it as your primary resource if your audience reads only English, if you need general security material rather than competition preparation, or if you are shopping for a CTF platform rather than a course. In those cases the mismatch is at the level of what the project is, not how well it is done.

Before you commit to a fork, check three things in the repository. Read docs/ and confirm the directions you care about are covered at the depth you need, since the README describes the project as still incomplete. Read the requirements.txt comment and decide whether you will track mkdocs-material upgrades or freeze at the pinned versions, because the overrides are bound to the theme version. And read both LICENSE and LICENSE-doc, since the repository ships two licence files and the README does not explain how they divide.

## Conclusion

Adopt Hello-CTF if you are a Chinese-reading beginner who wants structured CTF lessons with runnable challenge files, or an instructor who needs a self-hosted course site. Skip it if you need English material or a general security reference; the content is CTF-specific and written in Chinese. Before committing, check the docs/ tree for the directions you care about, confirm the mkdocs-material version pin in requirements.txt, and decide whether your fork will track upstream or freeze.

## FAQ

### Is Hello-CTF free to use?

Yes. The repository is licensed under GPL-3.0 and the README describes the tutorial as free and open source. It also asks that anyone republishing the project include the original repository address.

### Do I need to install anything to read Hello-CTF?

No. The README points to hello-ctf.com for online reading. Installing locally is only necessary if you want to edit the content or run the site yourself.

### Which CTF directions does Hello-CTF cover?

The README lists MISC, Web, Crypto, Reverse and Pwn as the main tutorial directions, plus extension directions including AWD, AI and Blockchain. Each knowledge point is meant to come with a matching challenge.

### Can I run the Hello-CTF challenges on my own machine?

The README states that challenges come with attachments, source and Dockerfiles, and that they can be deployed locally or opened on the NSSCTF platform. The repository itself does not include a judging or scoring system.

### Is the Hello-CTF tutorial available in English?

The README, the site and the tutorial content are written in Chinese, and the project does not mention an English edition. Readers who do not read Chinese will not be able to use the main tutorial.

## Sources

- [Issues](https://github.com/ProbiusOfficial/Hello-CTF/issues)
- [License: GPL-3.0](https://github.com/ProbiusOfficial/Hello-CTF/blob/main/LICENSE)
- [ProbiusOfficial/Hello-CTF on GitHub](https://github.com/ProbiusOfficial/Hello-CTF)
- [Project website](https://hello-ctf.com/)
- [README](https://github.com/ProbiusOfficial/Hello-CTF/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/probiusofficial-hello-ctf
