root@rwctf: ~

Real bugs.
Rebuilt to break.

Investigate safe, playable scenarios reconstructed from real product vulnerabilities.

24reconstructed scenarios
8vulnerability tracks
3difficulty tiers
DockerDisposable ranges
Express.jsAPI routing layers
Node.jsBackend runtime behavior
NginxReverse proxy layers
PostgreSQLRelational trust boundaries
RedisCaches and session state
MongoDBDocument data flows
GraphQLResolver attack surface
KubernetesCluster trust paths
ReactClient attack surface
Apache KafkaAsynchronous message flows
DockerDisposable ranges
Express.jsAPI routing layers
Node.jsBackend runtime behavior
NginxReverse proxy layers
PostgreSQLRelational trust boundaries
RedisCaches and session state
MongoDBDocument data flows
GraphQLResolver attack surface
KubernetesCluster trust paths
ReactClient attack surface
Apache KafkaAsynchronous message flows

We don't teach paths.
We build experiences.

Two hunters. Same starting signal.
Shared entry point/api/preview
Hunter 01

Traditional lab

ScriptedPredictableLimited
01Bug namedSSRF confirmed
02Route givenEndpoint exposed
03Payload copiedExpected flag found
DuplicatePath exhaustedThe script ends here.
Hunter 02

RealWorld range

Real-worldUnpredictableValuable
01Map productTrace the preview worker
02Notice signalRedirect behavior leaks
03PivotCross an internal boundary
04EscalateChain trusted services
Critical impactTrust boundary brokenHigh-value finding proven.
In the real world, there are no flags. Only impact.
Membership

Select your tier.

Access safe, reconstructed environments of real vulnerabilities.

Free

Free
  • Access to Basic & Medium scenarios
  • Community Support
  • Standard lab provisioning times
  • Limited labs per day
  • No access to Elite Scenarios
  • No official walkthroughs

Elite Hacker

$20$9.99/mo
  • Access to ALL Elite & Hard scenarios
  • Priority Lab Provisioning (Instant Access)
  • Official Step-by-Step Walkthroughs
  • Private Elite Discord Channel
  • Early Access to New Vulnerabilities