Hacking Labs

137 hands-on labs + 75 AI-generated puzzles across 13 domains — web, AD, cloud, mobile, network, crypto, forensics, OSINT, RE, DevSecOps, AI/ML, hardware & blockchain. Capture the flag, earn XP.

// domain
New to hacking? Start with a Learning Path.
13 domains137 labs6 career trackscapstone examsreal CVEs
open academy
// filter by

Box: Legacy Admin Panel (chained)

Three chained vulns: info-disclosure → SQLi on /admin-old → path traversal to /root/flag. Persistent VFS per user.

hard+120xp· box

Box: Cloud Misconfig (S3 + IAM + SSRF)

SSRF the instance metadata service for IAM creds, then list a misconfigured S3 bucket to grab the flag.

hard+140xp· box

Box: GraphQL + Mass Assignment

Introspect a GraphQL schema, find a mutation that mass-assigns role=admin, claim the flag.

medium+100xp· box

Box: Active Directory — Kerberoasting

Enumerate SPNs, request a TGS, crack the offline hash, recover the service-account password.

hard+130xppro· box

Box: Mobile — Deeplink + JWT Replay

Abuse a permissive deep-link scheme to leak a stale JWT, then replay it to access the admin endpoint.

medium+110xp· box

Box: Pwn-the-Pipe (CI/CD secret leak)

Inject into a build YAML, exfiltrate the env, then use the leaked token to read the prod registry.

hard+140xppro· box

Box: AWS Lambda Privilege Escalation

Discover an over-privileged Lambda, invoke it via its API Gateway URL, escalate to read prod secrets.

hard+140xppro· box

Box: Kubernetes RBAC Escape

Steal the service-account token from a sidecar, then list cluster-wide secrets via the API server.

hard+135xppro· box

Box: iOS — Sideloaded Replay

An IPA leaks an embedded refresh-token. Replay it against the API to mint an admin access-token.

medium+110xp· box
// install app

Install hacking.community for fast access, offline reading, and push notifications. No app store needed.