HackLab
XP: 0LVL: 0/36

Operator Check-In

Enter your callsign. No password is required — this is a lightweight guest session.

Welcome to HackLab

A purely client-side CTF dojo. Explore 20 real-world offensive security scenarios across Linux, Web, Crypto, and Active Directory.

Current Rank

Noob

Live Leaderboard

View all →

No scores yet. Sign in and capture a flag to be the first.

Categories

Training Missions

UNLOCKED

1. Linux Recon (Log Analysis)

Reconnaissance

A compromised application server has been writing authentication traces to /var/log/syslog. Use grep to hunt for leaked credentials and hidden flags.

START MISSION
LOCKED

2. Hidden Artifacts

Linux Privilege Escalation

Adversaries often hide secrets in dotfiles. Inspect /home/user thoroughly with ls -la and find.

LOCKED
LOCKED

3. Port Scanning

Network Reconnaissance

Reconnaissance begins with service discovery. Scan the target 10.0.0.1 to identify the vulnerable service.

LOCKED
LOCKED

4. Directory Brute-Force

Web Reconnaissance

The target web root may have an undocumented admin panel. Brute-force hidden directories.

LOCKED
LOCKED

5. SQL Injection

Web Exploitation

The login form at /login does not sanitize user input. Bypass authentication using a classic SQLi payload.

LOCKED
LOCKED

6. IDOR

Web Exploitation

The profile page at /profile?id=102 returns your data, but it does not enforce authorization. Access an admin account.

LOCKED
LOCKED

7. Cookie Tampering

Web Exploitation

The role cookie is base64 encoded. Decode it, change your privileges, and resubmit.

LOCKED
LOCKED

8. EXIF Metadata

Steganography

A suspicious image was uploaded to the server. Analyze its EXIF metadata for hidden GPS coordinates and comments.

LOCKED
LOCKED

9. Hash Cracking

Cryptography

You recovered an MD5 hash from the database dump. Use john to recover the plaintext.

LOCKED
LOCKED

10. SUID Privilege Escalation

Linux Privilege Escalation

A binary has the SUID bit set. Find it and abuse it to drop into a root shell.

LOCKED
LOCKED

11. Sudo Misconfiguration

Linux Privilege Escalation

The sudoers file allows a dangerous command to run as root without a password.

LOCKED
LOCKED

12. API Enumeration

Web API

An internal API endpoint is not listed in the documentation but still responds to requests.

LOCKED
LOCKED

13. FTP Anonymous Login

Network Exploitation

An FTP server accepts anonymous authentication and hosts a juicy backup archive.

LOCKED
LOCKED

14. Command Injection

Web Exploitation

A diagnostics page pings user-supplied IPs without validation. Inject a secondary command.

LOCKED
LOCKED

15. JWT None Algorithm

Web Exploitation

The admin endpoint trusts JWTs signed with the "none" algorithm. Forge a token.

LOCKED
LOCKED

16. Cloud Bucket Leakage

Cloud Security

A public S3 bucket is over-sharing assets. List its contents and find the exposed secret.

LOCKED
LOCKED

17. XSS Stealer

Web Exploitation

A comment box is vulnerable to stored XSS. Exfiltrate an admin cookie.

LOCKED
LOCKED

18. PCAP Analysis

Forensics

A packet capture contains a plaintext HTTP POST with an admin password.

LOCKED
LOCKED

19. SSH Key Hijack

Network Exploitation

An unencrypted SSH private key was left in /var/backups. Use it to authenticate as root.

LOCKED
LOCKED

20. Active Directory Kerberoasting

Active Directory

Request a TGS ticket for an SPN and crack it to recover a service account password.

LOCKED
LOCKED

21. SSRF - Cloud Metadata

Cloud Security

A stock-ticker proxy accepts arbitrary URLs. Force the backend to request the cloud metadata service.

LOCKED
LOCKED

22. XXE - XML External Entity

Web Exploitation

An API imports XML without disabling external entities. Read internal files through XML.

LOCKED
LOCKED

23. LFI - Local File Inclusion

Web Exploitation

A document viewer loads files based on a file parameter. Traverse directories to read system files.

LOCKED
LOCKED

24. NoSQL Injection

Web Exploitation

The NoSQL login query trusts JSON operators. Bypass authentication with a JSON payload.

LOCKED
LOCKED

25. Git Repository Exposure

Web Reconnaissance

The .git directory is left exposed on the web root. Inspect it to recover repository secrets.

LOCKED
LOCKED

26. Subdomain Enumeration

Reconnaissance

Discover hidden subdomains for target.com using a passive subdomain finder.

LOCKED
LOCKED

27. Cron Backdoor

Linux Privilege Escalation

A cron job runs as root and uses a wildcard in a writable directory, allowing command injection.

LOCKED
LOCKED

28. XOR Ciphertext

Cryptography

A secret message was encrypted with a single-byte XOR key. The key is hidden in the filename.

LOCKED
LOCKED

29. AS-REP Roasting

Active Directory

A user account does not require Kerberos pre-authentication. Request an AS-REP and crack it offline.

LOCKED
LOCKED

30. S3 Public Write

Cloud Security

A bucket policy allows public PutObject. Abuse it to overwrite an exposed config file.

LOCKED
LOCKED

31. Robots.txt Leak

Web Reconnaissance

The robots.txt file lists disallowed paths that should be hidden from crawlers.

LOCKED
LOCKED

32. Process Environment Leak

Linux Privilege Escalation

A running process inherited a secret from its parent. Read the process environment to find it.

LOCKED
LOCKED

33. Telnet Banner Grab

Network Exploitation

An old telnet service leaks a version banner and a hardcoded credential.

LOCKED
LOCKED

34. Hidden Admin Profile

Web Exploitation

The user profile endpoint is vulnerable to IDOR. The admin profile is hidden at an unexpected ID.

LOCKED
LOCKED

35. DNS Zone Transfer

Reconnaissance

The target DNS server is misconfigured and allows AXFR zone transfers, leaking every subdomain record.

LOCKED
LOCKED

36. Caesar Cipher

Cryptography

An ancient shift cipher was used to hide a message. The ciphertext is in /home/user/caesar.txt and uses a shift of 3.

LOCKED