whoamilab

a free capture the flag playground. 23 vulnerable machines you hack straight from Discord. run /welcome in #learn-hacking and climb the ranks.

379
hackers
1999
flags caught
23
live labs
23/23
first bloods

recent captures

1h 6m
25m 9s
5m 7s

how it works

choose a lab

23 labs, from "find a hidden file" to "turn this bug into full control." pick by difficulty or by topic.

/labs list

get your own server

the discord bot spins up a fresh server just for you. ssh in, or hack it right from the browser.

/start sqli

submit the flag

find the bug, exploit it, read the flag, post it. first one to solve gets the first blood.

/submit id:sqli FLAG{...}

the labs

01
Beginner
3 labs
First Steps
SSH Connect via SSH and find hidden files
★☆☆☆☆
Profile Hacker
WEB Exploit insecure direct object references
★☆☆☆☆
Cookie Monster
WEB Manipulate browser cookies for privilege escalation
★☆☆☆☆
02
Intermediate
10 labs
Command Injection
WEB+SSH Chain OS commands through a web interface
★★☆☆☆
Database Bypass
WEB+SSH Bypass authentication with SQL injection
★★☆☆☆
Malicious Upload
WEB+SSH Upload a web shell past file filters
★★☆☆☆
XML Attack
WEB Read server files through XML entity injection
★★☆☆☆
Path Traversal
WEB+SSH Traverse directories to read sensitive files
★★☆☆☆
Script Kiddie
WEB+SSH Inject JavaScript to steal credentials
★★☆☆☆
Vault Cracker
WEB+SSH Decode layered encoding to crack a vault
★★☆☆☆
API Hacker
WEB+SSH Exploit broken API access controls
★★☆☆☆
Source Code
WEB+SSH Find secrets in exposed version control history
★★☆☆☆
Param Tampering
WEB+SSH Exploit hidden form fields to escalate privileges
★★☆☆☆
03
Advanced
8 labs
Template Injection
WEB+SSH Execute code through template engines
★★★☆☆
Token Forger
WEB+SSH Forge authentication tokens
★★★☆☆
Root Access
SSH Escalate from user to root via SUID
★★★☆☆
Internal Access
WEB+SSH Access internal services through SSRF
★★★☆☆
Hash Cracker
WEB+SSH Crack weak password hashes from an exposed database
★★★☆☆
Blind Injection
WEB+SSH Extract data through boolean-based blind SQL injection
★★★☆☆
Race the Clock
WEB Exploit a race condition to bypass purchase limits
★★★☆☆
Cookie Heist
WEB Steal an admin session with reflected XSS and breach the dashboard
★★★☆☆
04
Expert
2 labs
Object Injection
WEB+SSH Exploit PHP deserialization for remote code execution
★★★★☆
Sign of Weakness
WEB Forge signed URLs by extending an MD5-based MAC
★★★★☆

the ranks

Unranked
no rank yet
Rookie
accept rules
Hacker
capture First Steps
Expert
any Hacker lab
Master
any Expert lab
Legend
any Master lab
Grandmaster
any Legend lab

run /welcome.
start hacking.