Sandboxed CTF labs

Learn to exploit the bugs that shaped security.

A hands-on capture-the-flag built on real historical CVEs. Each challenge is a deliberately vulnerable app in its own isolated lab, so you learn to recognize and exploit a whole class of bug, safely.

Browse challenges
challenges
6

challenges

categories
4

categories

points on offer
1,800

points on offer

How it works

  1. 01

    Pick a challenge

    Each one wraps a real CVE from 2021 to 2022 in its own sandboxed, vulnerable app.

  2. 02

    Exploit the bug

    Reach the vulnerable endpoint, build the payload, and get code running or data leaking.

  3. 03

    Submit the flag

    Pull the flag off the box and submit it. Correct flags lock in your points once.

  4. 04

    Climb the board

    Points and solve times rank you against everyone else working the same labs.