
PENTEST-LAB
Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Pentesting lab with a Kali Linux instance accessible via ssh & wireguard VPN and with vulnerable instances in a private subnet

Technical Reference to multiple relay techniques

Analysis of two authentication bypass techniques for Apache Shiro (CVE-2020-17523) with a reproducible exploit environment and detailed root cause…

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

POC for CVE-2025-54918 and a technical demonstration.

Exploit for CVE-2024-27198 - TeamCity Server

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

An implementation of a vulnerable MCP server using mcp-go

CVE-2020-13933 靶场: shiro 认证绕过漏洞

Reproduction environment for CVE-2025-29927, demonstrating Next.js middleware authorization bypass via the x-middleware-subrequest header. Includes…

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.

The Demo for CVE-2017-11427

Proof-of-concept exploit for GNU Inetutils telnetd authentication bypass (CVE-2026-24061) with Docker lab setup and Go PoC. Exploits NEW-ENVIRON…