Hands-on
Labs
Real challenges, not multiple choice. Each one drops you into a terminal on a small machine with a flag hidden somewhere in it — explore, find it, and submit it. Your flag is unique to you, so answers can't be shared. Solving earns XP.
First Contact
Your first mission. A fictional academy wants a connectivity check before it opens its records — so run one, and read what the tool actually tells you. The mission runs in the mission runtime, and finishing it is checked with the runtime rather than taken on trust.
Opens on HackerOS
Hidden in Plain Sight
The flag is sitting in your home directory right now — but a plain `ls` will not show it, because its name begins with a dot. Reveal the hidden files, then read the one that matters.
The Careless Backup
An admin left a secret in a backup file somewhere on this box. It is not in your home directory. Find it, and submit the flag.
Climbing Out Of The Log Folder
An ops console lets you tail a log file by name. Give it a name that climbs out of the log folder with `..`, and it reads the deploy secrets sitting next door. The token inside is yours to recover.
Opens a real site in its own tab
Needle in the Log
The flag leaked into a log file — thousands of ordinary lines, one that matters. Reading it all is hopeless. Find the line with grep.
One Password, Six Sites
A forum you forgot about leaked its passwords. Work out which of your other accounts that costs you, and which it does not.
Somebody Else's Statement
Log into a bank's back office as an ordinary analyst, open your own account, then change one number in the address bar and read the operating account you were never meant to see. The reference hiding in it is yours to recover.
Opens a real site in its own tab
The API Key In The History
The key was committed by mistake and removed the next day. It is still there, and the fix is not another commit.
The Honest Mistake
An internal staff directory with one line of bad code in it. The search box builds its SQL by gluing your text into the middle of a query. Find the row it is trying to keep from you.
The Moderator's Session
A forum shows post bodies exactly as they are typed, and a moderator reads every new post. Store a script in a post, wait for the moderator to open it, and read their session cookie out of your collector. The cookie is yours.
Opens a real site in its own tab
The Real Board
A real forum with a real SQL injection in its search. Union the private messages into the results, find the reviewer verification token that is yours alone, and submit it. The flag you recover is unique to you — a copied one is refused.
Opens a real site in its own tab
What The Photo Knows
A photo posted with no caption and no location. The file disagrees, and the disagreement is a street address.
Everything Is Encrypted
Every file has a new extension and there is a note in every folder. Work out what was hit, when it started, and which backup predates it.
Somebody Is Already Here
A defaced server, four hundred lines of log, and a way back in that survives a reboot. Find the entry point, follow it to what it dropped, and find what they left behind.
The Code That Looked Fine
Four handlers, one pull request, and one missing line. Everything reads correctly, which is the problem.
The Package That Wasn't
A build started failing audit. Somewhere in nine hundred packages is one nobody chose, and its name is almost right.
The Profile Picture
Two features that both work exactly as designed. Line up your logger against the visitor panel and name the person who has been careful about their name.
The Token That Signs Itself
A bank back office keeps your session in a signed token. Its verifier also accepts a token that says "no signature required" — so forge one that makes you the controller, set it, and open the vault. The reference inside is yours.
Opens a real site in its own tab
Two At Once
The check passes, the code is correct, and the balance still goes negative. The bug is in the gap between reading a value and writing it.