40 challenges live · 6 domains · new challenges added on an ongoing basis

Learn to break things properly, then learn to stop them.

Hands-on labs built the way real engagements actually run — live targets, real tools, and evidence you have to go find, not a quiz with four multiple-choice answers.

40hands-on challenges
6security domains
1payment, lifetime access

Six domains, built around the skills real security roles need first.

Reconnaissance

Read a target the way a real engagement starts: full port sweeps, service fingerprinting, subnet discovery.

Web application security

SQL injection, CSRF, SSRF, JWT forgery, and a full six-vulnerability marketplace app to take apart.

Password attacks

Dictionary attacks, offline hash cracking, lockout-aware spraying, and credential reuse across systems.

Cloud security

Real aws-cli against purpose-built AWS-shaped targets: public buckets, IAM escalation, a full kill chain.

API security

The OWASP API Top 10 as things you actually break — broken auth, mass assignment, excessive data exposure.

Digital forensics & incident response

No live target — real evidence. Logs, packet captures, and a suspicious file, investigated start to finish.

Difficulty: Easy Medium Hard Mad Capstone — Capstones chain every skill in their track into one full compromise.
40 challenges

Reconnaissance & Networking Fundamentals

Map a target before you touch it. Port scanning, service fingerprinting, and subnet sweeps with real nmap output, not a quiz about it.

5 challenges

Basic Port Scanning

Easy

Find a service nmap's default scan doesn't show you

Terminal 1 flag

Banner Grabbing & Service Versions

Medium

Fingerprint an outdated service by its version banner

Terminal 1 flag

Subnet & Host Discovery

Hard

Sweep a /28 to find the one host that matters

Terminal 1 flag

UDP Scanning

Mad

Scan the transport protocol most tools skip

Terminal 1 flag

Full Network Recon

Capstone

Chain TCP and UDP recon into one full sweep

Terminal 1 flag

Web Application Security

The bugs that show up in every real pentest report. Injection, broken auth, and a six-vulnerability marketplace app built to be taken apart.

14 challenges

SQLi Login Bypass

Easy

Bypass authentication with a single crafted login

Browser 1 flag

Advanced UNION-based SQLi

Medium

Extract hidden data past a keyword filter

Browser 1 flag

Blind Boolean-based SQLi

Hard

Pull data out one true/false answer at a time

Browser 1 flag

Time-based Blind SQLi

Mad

Read the database through response delays alone

Browser 1 flag

CSRF: Silent Account Takeover

Medium*

Force an admin's browser to act without their consent

Browser 1 flag

SSRF: Reach the Internal Network

Hard*

Turn a URL fetcher into a pivot to internal services

Browser 1 flag

JWT Algorithm Confusion

Mad*

Forge an admin token by abusing a signing mix-up

Browser 1 flag

Exposed .git Folder

Easy*

Recover deleted secrets straight from commit history

Browser 1 flag

Marketplace: Stored XSS

Medium*

Hijack an admin session through a product review

Browser 1 flag

Marketplace: IDOR

Easy*

Read another shopper's order history by changing an ID

Browser 1 flag

Marketplace: Price Manipulation

Medium*

Checkout with a price the server never agreed to

Browser 1 flag

Marketplace: Privilege Escalation

Hard*

Grant yourself admin through an unprotected field

Browser 1 flag

Marketplace: Path Traversal

Hard*

Escape the uploads folder to read arbitrary files

Browser 1 flag

Marketplace: Open Redirect

Easy*

Weaponize a trusted domain's own login flow

Browser 1 flag

Password Attacks

Cracking and spraying, the way they actually happen: wordlists, offline hashes, lockout-aware attacks, and credential reuse across systems.

5 challenges

Basic Dictionary Attack

Easy

Automate a wordlist attack against a live FTP login

Terminal 1 flag

Hash Cracking Basics

Medium

Identify and crack a leaked password hash offline

Terminal 1 flag

Password Spraying

Hard

Beat a lockout policy by inverting the usual attack

Browser 1 flag

Weak Salting Exploitation

Mad

Break a homemade salting scheme with the right tool

Terminal 1 flag

Crack, Then Reuse

Capstone

Turn one cracked password into a second system breach

Browser 1 flag

Cloud Security Attacks

Real aws-cli, pointed at purpose-built AWS-shaped targets. Public buckets, metadata theft, IAM privilege escalation, and a four-stage kill chain.

5 challenges

Misconfigured S3 Bucket

Easy

Pull data from a bucket that needed no credentials

Terminal 1 flag

SSRF to Cloud Metadata

Medium

Steal instance credentials through a server-side fetch

Terminal 1 flag

IAM Privilege Escalation

Hard

Attach an admin policy to your own low-priv user

Terminal 1 flag

Serverless Function Exploitation

Mad

Turn command injection into a stolen execution role

Terminal 1 flag

Full Cloud Kill Chain

Capstone

Bucket to SSRF to IAM to serverless, in one sitting

Terminal 1 flag

API Security

The OWASP API Top 10, built as things you actually break: raw responses, swapped IDs, extra JSON fields, and endpoints nobody gated.

5 challenges

Excessive Data Exposure

Easy

Find what the raw API response leaks past the UI

Browser 1 flag

BOLA / IDOR

Medium

Read someone else's private messages by swapping an ID

Browser 1 flag

Mass Assignment

Hard

Grant yourself a role the form was never meant to expose

Terminal 1 flag

Broken Function-Level Authorization

Mad

Call an admin endpoint your account was never checked against

Terminal 1 flag

Full API Compromise Chain

Capstone

Chain exposure, IDOR, and escalation into full compromise

Browser 1 flag

Digital Forensics & Incident Response

No live target to exploit — real evidence to read. Logs, packet captures, and a suspicious file, the way an actual investigation runs.

6 challenges

Log Analysis

Easy

Isolate a brute-force attacker from 200 lines of noise

Terminal 1 flag

Alert Triage

Medium

Find the one real alert among five explainable false positives

Browser 1 flag

Network Traffic Analysis

Hard

Follow a TCP stream to catch data leaving the network

Terminal 1 flag

Malware/File Analysis

Mad

Unmask a file that isn't what its extension claims

Terminal 1 flag

Full Incident Investigation

Capstone

Run a complete investigation, start to finish

Browser 1 flag

Multi-Source Log Correlation

Hard

Prove an intrusion by correlating two separate logs

Terminal 1 flag
No challenges match your search. Try a different term or clear the filter.

Already have access?

Stop scrolling, start hacking. Jump straight into the labs!

Launch HackPreps →

One payment. Every lab, for as long as HackPreps exists.

No subscriptions, no per-track add-ons. Buy once and you're in — including every challenge we ship after today.

  • All 40 current challenges across all 6 domains
  • Every future challenge we add, at no extra cost
  • Real tools against real, purpose-built targets — not simulations
  • A pre-configured attack box terminal — nothing to install locally
  • Hints on every challenge, tiered so you can self-pace
Lifetime access
$35.50
One-time payment
Get lifetime access →
Replace the price and this link with your CertPreps checkout URL before publishing.