Skip to contentExploitQuest

Security, taught by doing

Learn to disappear. Learn to break things. Ethically.

How people get found online and how to stay private. How attacks actually work, and how to run them yourself — in a sandbox built for it, never on anyone else. Read a lesson, practise in a real shell, solve a lab, then sit an exam and earn a credential anyone can verify.

you@sandbox
Practice shell — nothing here is real. Type 'help' to begin.

A real shell — type help, or ls. More at Practice.

  • No account needed to read anything
  • No email address, at any tier
  • No tracking, so no cookie banner

How it works

Where to start

Free1h

Introduction to ExploitQuest

Start here. In three short chapters you will meet everything the platform can do — a real terminal you type into, questions that pay XP, hands-on challenges, and the credential at the end — by using each one, not reading about it.

Free6h

Anonymity & OpSec

Practical self-defence for people who are not security professionals and do not intend to become them. Threat modelling first, tools second — because the tool you need depends entirely on who you are hiding from.

Free4h

The Attacker's Playbook

How people actually get hacked — the whole attack, from the reconnaissance before anyone touches you to the extortion at the end, told as one story through real breaches. Every stage is paired with the thing that stops it, usually early and cheaply.

Free6h

Linux Fundamentals

The operating system almost all of the internet runs on, taught from the first command. Free, and the ground every later course stands on.

Free8h

Web Application Security

How web applications actually break, and how to stop yours breaking the same way. Every attack is paired with its defence, and every attack is run against something genuinely vulnerable rather than described.

Free6h

VPS & Self-Hosting

You deployed something to a server. Now learn to defend it. SSH keys, a firewall that denies by default, fail2ban banning the ones who keep coming back, patching that actually happens, and backups you have really restored — each taught by watching an attack, then stopping it.

Free5h

Digital Forensics & Incident Response

Somebody is in your server, or your site is defaced, and the first thing you want to do is the thing that destroys the evidence. This is what to do instead: preserve, find the entry, build the timeline, find what they left to get back in, and answer honestly whether data was taken.

Free6h

Secure Coding

Not a vulnerability taxonomy. The habits that stop you writing the bug in the first place — parameterised queries, contextual encoding, authorization at the boundary, secrets with no fallbacks — each one taught with the check that enforces it and the incident that caused it to be written.

Free4h

AI Code Security

You are shipping code you did not write. This is how to review it: the bugs models actually produce, the packages they invent that attackers then register, what happens when a model with tools reads attacker-controlled text, and why the confident, idiomatic, plausible version gets reviewed least carefully.

Free4h

Reconnaissance

The four tools every assessment starts with, one module each. What each one actually asks, how to read its output rather than memorise its flags, and — for every one of them — what the scan looks like from the other end.

Free4h

Cracking & Brute Force

How passwords actually fall — offline against a stolen hash at a hundred billion guesses a second, online against a live login at four. Which hashes crack instantly and which never do, why the difference is the algorithm rather than the password, and what genuinely stops each attack.

Why this is different

Attack, then defend

You cannot defend against something you have never seen, so lessons show how the attack works before the countermeasure — in a sandbox, with the rules stated, and never pointed at anyone who did not ask for it.

Threat modelling first

Hiding from an advertiser and hiding from an abusive ex are different problems with different answers. Almost every guide skips this, which is why people buy things that do not help.

Nothing is for sale but access

No affiliate links in any lesson. When we score a tool, the rubric is published and you can run it yourself.