whoamilab

a free capture the flag playground. 23 vulnerable machines you hack straight from Discord. run /welcome in #learn-hacking and climb the ranks.

546
hackers
2900
flags caught
23
live labs
23/23
first bloods

recent captures

how it works

choose a lab

23 labs, from "find a hidden file" to "turn this bug into full control." pick by difficulty or by topic.

/labs list

get your own server

the discord bot spins up a fresh server just for you. ssh in, or hack it right from the browser.

/start sqli

submit the flag

find the bug, exploit it, read the flag, post it. first one to solve gets the first blood.

/submit id:sqli FLAG{...}

the labs

01
Beginner
3 labs
First Steps
SSH Connect via SSH and find hidden files
โ˜…โ˜†โ˜†โ˜†โ˜†
Profile Hacker
WEB Exploit insecure direct object references
โ˜…โ˜†โ˜†โ˜†โ˜†
Cookie Monster
WEB Manipulate browser cookies for privilege escalation
โ˜…โ˜†โ˜†โ˜†โ˜†
02
Intermediate
10 labs
Command Injection
WEB+SSH Chain OS commands through a web interface
โ˜…โ˜…โ˜†โ˜†โ˜†
Database Bypass
WEB+SSH Bypass authentication with SQL injection
โ˜…โ˜…โ˜†โ˜†โ˜†
Malicious Upload
WEB+SSH Upload a web shell past file filters
โ˜…โ˜…โ˜†โ˜†โ˜†
XML Attack
WEB Read server files through XML entity injection
โ˜…โ˜…โ˜†โ˜†โ˜†
Path Traversal
WEB+SSH Traverse directories to read sensitive files
โ˜…โ˜…โ˜†โ˜†โ˜†
Script Kiddie
WEB+SSH Inject JavaScript to steal credentials
โ˜…โ˜…โ˜†โ˜†โ˜†
Vault Cracker
WEB+SSH Decode layered encoding to crack a vault
โ˜…โ˜…โ˜†โ˜†โ˜†
API Hacker
WEB+SSH Exploit broken API access controls
โ˜…โ˜…โ˜†โ˜†โ˜†
Source Code
WEB+SSH Find secrets in exposed version control history
โ˜…โ˜…โ˜†โ˜†โ˜†
Param Tampering
WEB+SSH Exploit hidden form fields to escalate privileges
โ˜…โ˜…โ˜†โ˜†โ˜†
03
Advanced
8 labs
Template Injection
WEB+SSH Execute code through template engines
โ˜…โ˜…โ˜…โ˜†โ˜†
Token Forger
WEB+SSH Forge authentication tokens
โ˜…โ˜…โ˜…โ˜†โ˜†
Root Access
SSH Escalate from user to root via SUID
โ˜…โ˜…โ˜…โ˜†โ˜†
Internal Access
WEB+SSH Access internal services through SSRF
โ˜…โ˜…โ˜…โ˜†โ˜†
Hash Cracker
WEB+SSH Crack weak password hashes from an exposed database
โ˜…โ˜…โ˜…โ˜†โ˜†
Blind Injection
WEB+SSH Extract data through boolean-based blind SQL injection
โ˜…โ˜…โ˜…โ˜†โ˜†
Race the Clock
WEB Exploit a race condition to bypass purchase limits
โ˜…โ˜…โ˜…โ˜†โ˜†
Cookie Heist
WEB Steal an admin session with reflected XSS and breach the dashboard
โ˜…โ˜…โ˜…โ˜†โ˜†
04
Expert
2 labs
Object Injection
WEB+SSH Exploit PHP deserialization for remote code execution
โ˜…โ˜…โ˜…โ˜…โ˜†
Sign of Weakness
WEB Forge signed URLs by extending an MD5-based MAC
โ˜…โ˜…โ˜…โ˜…โ˜†

the ranks

Unranked
no rank yet
Rookie
accept rules
Hacker
capture First Steps
Expert
any Hacker lab
Master
any Expert lab
Legend
any Master lab
Grandmaster
any Legend lab

run /welcome.
start hacking.