Skip to contentExploitQuest

Every subject, on its own

Chapters

A chapter is one subject, taught properly, in about half an hour. If you came here to learn a specific thing rather than to take a whole course, start here — every one is readable without an account.

60 chapters across 11 courses

  1. What This Is

    The promise the platform makes, and how a lesson actually works.

    Introduction to ExploitQuest

    Foundation3 lessons · 6 min
  2. The Shell Is Real

    Not a screenshot of a terminal — a terminal. Watch one, build a command, then do it yourself.

    Introduction to ExploitQuest

    Foundation2 lessons · 3 min
  3. Earning Your Place

    XP, streaks and shields, and the labs, exams and signed credential the whole platform builds toward.

    Introduction to ExploitQuest

    Foundation2 lessons · 4 min
  4. Foundations

    The question every other decision depends on, and the vocabulary to answer it honestly.

    Anonymity & OpSec · Anonymity & OpSec

    Foundation4 lessons · 16 min
  5. Who Is Actually Attacking You

    "Hackers" is not one thing. An automated scanner, a ransomware crew and a nation-state want different things, can do wildly different things, and are stopped by wildly different things. Knowing which one is aimed at you is where every sensible decision starts.

    The Attacker's Playbook

    Foundation1 lesson · 4 min
  6. Reconnaissance

    Before anyone touches your systems, they read. Attackers assemble a picture of you from what is already public — your domains, your staff, your leaked passwords, the metadata in your own documents — and most of it, you gave away without noticing.

    The Attacker's Playbook

    Foundation1 lesson · 3 min
  7. The Browser

    The single application that leaks the most about you, and the handful of choices that decide how much.

    Anonymity & OpSec · Anonymity & OpSec

    Foundation4 lessons · 16 min
  8. Accounts & Identity

    How people are actually found — not by broken encryption, but by the account they forgot and the password they reused.

    Anonymity & OpSec · Anonymity & OpSec

    Foundation4 lessons · 13 min
  9. Initial Access

    The way in is almost never the dramatic one. Ranked by how often each actually starts a breach, the front doors are a phished click, a reused password, an unpatched box, and a trusted supplier — in roughly that order, which is not the order the films taught you.

    The Attacker's Playbook

    Foundation1 lesson · 4 min
  10. Persistence

    Getting in is the expensive part, so a serious attacker makes sure they never have to do it again. Persistence is the quiet business of leaving a way back — a new account, a scheduled task, a stolen token — that survives a reboot, a password change, and often the clean-up itself.

    The Attacker's Playbook

    Foundation1 lesson · 3 min
  11. Private Messaging

    The most practical privacy decision most people make daily — which app carries their conversations, and what "encrypted" actually buys them.

    Anonymity & OpSec · Anonymity & OpSec

    Foundation3 lessons · 12 min
  12. Privilege Escalation

    Attackers rarely land where they want to be. They land as a nobody — a single low-privilege account — and climb. Privilege escalation is that climb, and it usually runs on the things a tired administrator left lying around, not on a clever exploit.

    The Attacker's Playbook

    Foundation1 lesson · 3 min
  13. The Bug Between Two Features

    A real forum, two features that both worked exactly as designed, and a person who became locatable.

    Anonymity & OpSec · Anonymity & OpSec

    Foundation4 lessons · 10 min
  14. Lateral Movement

    One compromised laptop is not one compromised laptop. It is a place to stand while reaching for the next machine, and the next, until the attacker holds the whole network. Lateral movement is why a small foothold becomes an organisation-wide emergency.

    The Attacker's Playbook

    Foundation1 lesson · 3 min
  15. Exfiltration And Extortion

    The end of the story is where the attacker gets paid. They take the data out, and then they turn it into leverage — sold, ransomed, or held over you with the threat of a leak. Understanding the payday is how you make yourself a bad investment.

    The Attacker's Playbook

    Foundation1 lesson · 3 min
  16. The Whole Chain, Defended

    Walk back through the whole attack and something hopeful appears: the attacker had to win every round, and you only have to win one. The links break earliest and cheapest near the start — which is where a handful of ordinary habits stop most of the story before it begins.

    The Attacker's Playbook

    Foundation1 lesson · 4 min
  17. The Terminal

    The text prompt that looks intimidating and turns out to be the most honest interface a computer has.

    Linux Fundamentals · Linux & Systems

    Easy3 lessons · 10 min
  18. Pipes and Filters

    The idea that makes the command line more than a list of commands — small tools that each do one thing, joined into something none of them could do alone.

    Linux Fundamentals · Linux & Systems

    Easy3 lessons · 12 min
  19. Permissions

    Who is allowed to read, change, or run each file — the model that keeps a multi-user system from being a free-for-all, and the power that comes with root.

    Linux Fundamentals · Linux & Systems

    Easy3 lessons · 12 min
  20. Processes

    Everything the computer is doing right now is a process. Seeing them, and starting and stopping them deliberately, is the last piece of a working footing.

    Linux Fundamentals · Linux & Systems

    Easy3 lessons · 11 min
  21. SQL Injection

    The bug that comes from building a query out of string pieces. Where it comes from, what it lets somebody do, and the one-line habit that ends it.

    Web Application Security · Web Security

    Medium6 lessons · 15 min
  22. Broken Access Control

    The application checks that you are logged in and forgets to check that the thing you asked for is yours. Where that gap comes from, what it hands over, and the check that has to happen on every object, every time.

    Web Application Security · Web Security

    Medium3 lessons · 8 min
  23. Path Traversal

    A filename is a path, and a path can climb. When an application builds a file path out of something you typed, `..` walks it out of the folder it was meant to stay in — and reads whatever the process can.

    Web Application Security · Web Security

    Medium3 lessons · 6 min
  24. Broken Authentication

    A session token is only as strong as the check that verifies it. When the verifier accepts a token that declares its own signature unnecessary, anyone can write themselves a token that says whatever they like.

    Web Application Security · Web Security

    Medium3 lessons · 7 min
  25. Cross-Site Scripting

    The other four bugs let you break the server. This one lets you run code in somebody else's browser, with their session, from a value the page rendered without escaping it. A comment field becomes a way to become the moderator.

    Web Application Security · Web Security

    Medium3 lessons · 9 min
  26. The First Box

    The minute a server has a public address, it is being tried — not by someone who chose you, but by machines trying everyone. The first hour of a box is about closing the doors those machines rattle: a real user, a key instead of a password, and an SSH daemon told to stop accepting the easy way in.

    VPS & Self-Hosting · Linux & Systems

    Medium1 lesson · 3 min
  27. Default Deny

    A firewall you can trust is one that blocks everything and then opens only the doors you can name out loud. The dangerous port is never the one you meant to open — it is the database, the admin panel, the debug server you forgot was listening.

    VPS & Self-Hosting · Linux & Systems

    Medium1 lesson · 3 min
  28. The Ones Who Come Back

    You cannot stop the internet from knocking, but you can make it expensive. A few failed logins is noise; the same address failing a hundred times is an attacker, and fail2ban reads that in the log and shuts the door on them — for an hour, and for the ones who keep coming back, for weeks.

    VPS & Self-Hosting · Linux & Systems

    Medium3 lessons · 6 min
  29. Patching That Happens

    The vulnerability that takes your box is almost never a new one — it is an old, known, already-patched one that nobody applied. Patching that depends on you remembering is patching that does not happen, so you make it automatic, and you make sure it finishes the job by rebooting.

    VPS & Self-Hosting · Linux & Systems

    Medium1 lesson · 2 min
  30. The Edge And Its Secrets

    Two ways a well-run box gives itself away: a reverse proxy that leaks the real server behind it, and a secrets file sitting in the one place every scanner looks. Both are small, both are common, and both are closed by knowing where the edge of your box actually is.

    VPS & Self-Hosting · Linux & Systems

    Medium1 lesson · 3 min
  31. Restore, Then Watch

    A backup you have never restored is a hope, not a backup — the restore is the exercise, not the copy. And a box nobody watches is one where the bad day is discovered by a customer. Both are about the day something goes wrong, prepared for on a day it has not.

    VPS & Self-Hosting · Linux & Systems

    Medium1 lesson · 3 min
  32. Locked Out

    Everything at once, on a box that is being scanned as you work. The log fills with attempts; you close the doors one by one; and by the end the same stream of attackers is hitting a box that has nothing left to give them. Graded on what the box is, not what you remember.

    VPS & Self-Hosting · Linux & Systems

    Medium1 lesson · 2 min
  33. Do Not Destroy the Evidence

    The first thing you want to do is the thing that makes the rest impossible.

    Digital Forensics & Incident Response · Forensics & IR

    Medium2 lessons · 7 min
  34. The First Hour

    Is it still happening, what is exposed, and what comes down before anything else.

    Digital Forensics & Incident Response · Forensics & IR

    Medium1 lesson · 3 min
  35. The One Request That Worked

    Finding the single line that mattered among a million that did not.

    Digital Forensics & Incident Response · Forensics & IR

    Medium1 lesson · 2 min
  36. Building the Timeline

    When it started, what happened in order, and what has been cleaned.

    Digital Forensics & Incident Response · Forensics & IR

    Medium1 lesson · 3 min
  37. Where They Hid To Come Back

    Cleaning the defacement and not the persistence means it happens again on Thursday.

    Digital Forensics & Incident Response · Forensics & IR

    Medium1 lesson · 3 min
  38. Was Data Taken

    The hardest question, and how to answer it honestly rather than reassuringly.

    Digital Forensics & Incident Response · Forensics & IR

    Medium1 lesson · 3 min
  39. Getting Back, and Writing It Down

    Which backup is safe, what to rebuild rather than clean, and the report that is the actual deliverable.

    Digital Forensics & Incident Response · Forensics & IR

    Medium1 lesson · 3 min
  40. Never Build a Query as a String

    The one rule with no exceptions, and why every escaping-by-hand approach has failed.

    Secure Coding · Secure Coding

    Medium1 lesson · 3 min
  41. Encoding Is Contextual

    HTML, attribute, JavaScript and URL are four different problems with four different answers.

    Secure Coding · Secure Coding

    Medium1 lesson · 3 min
  42. Authorization at the Boundary

    Decided in one place, never in the interface. A hidden button is not an access control.

    Secure Coding · Secure Coding

    Medium1 lesson · 3 min
  43. Secrets Have No Fallbacks

    A default secret is the same as no secret, and it is the one that ships.

    Secure Coding · Secure Coding

    Medium1 lesson · 3 min
  44. The Packages You Did Not Choose

    Lockfiles, audits, typosquats, and the transitive dependency nobody read.

    Secure Coding · Secure Coding

    Medium1 lesson · 2 min
  45. Cryptography You Should Not Write

    Passwords, comparisons, and the difference between an identifier and a secret.

    Secure Coding · Secure Coding

    Medium1 lesson · 3 min
  46. What Your Errors and Uploads Give Away

    What the user sees against what the log holds, and why a filename is not a name.

    Secure Coding · Secure Coding

    Medium1 lesson · 3 min
  47. Reading Your Own Code

    What to look for, in what order, and why rate limiting is a security control.

    Secure Coding · Secure Coding

    Medium1 lesson · 3 min
  48. Reviewing Code You Did Not Write

    What to check first, and why "it passes the tests" is the weakest signal you have.

    AI Code Security · Secure Coding

    Medium1 lesson · 3 min
  49. The Package That Was Never Real

    Models invent package names. Attackers read the same models and register them.

    AI Code Security · Secure Coding

    Medium1 lesson · 3 min
  50. When the Model Has Tools

    Injection stops being a text problem the moment the reader can act.

    AI Code Security · Secure Coding

    Medium1 lesson · 3 min
  51. What You Pasted Into the Box

    A context window is a place your secrets can go, and it is not one you control.

    AI Code Security · Secure Coding

    Medium1 lesson · 3 min
  52. The Confident Wrong Answer

    Plausible, idiomatic, subtly broken — and reviewed less carefully because it looks good.

    AI Code Security · Secure Coding

    Medium1 lesson · 3 min
  53. nmap

    Host discovery, port states, and what "filtered" actually means.

    Reconnaissance · Network Security

    Easy2 lessons · 3 min
  54. dig

    Record types, delegation, and what a zone gives away for free.

    Reconnaissance · Network Security

    Easy1 lesson · 2 min
  55. whois

    What a registry holds, how stale it is, and why it is not the machine.

    Reconnaissance · Network Security

    Easy1 lesson · 3 min
  56. ffuf

    Content discovery, filtering by response, and why the interesting result is the anomaly.

    Reconnaissance · Network Security

    Easy2 lessons · 5 min
  57. hashcat

    Offline cracking against a stolen hash, and why the algorithm decides everything.

    Cracking & Brute Force · Network Security

    Medium1 lesson · 2 min
  58. john

    When a tiny list built from the account beats a million generic words.

    Cracking & Brute Force · Network Security

    Medium1 lesson · 2 min
  59. hydra

    Online brute force, and why it is mostly a way to get rate-limited.

    Cracking & Brute Force · Network Security

    Medium1 lesson · 2 min
  60. What Actually Stops Them

    A memory-hard hash, rate limiting on both axes, and a constant-time comparison.

    Cracking & Brute Force · Network Security

    Medium1 lesson · 3 min