Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
cmdchamp — bash CLI trainer — 30 levels from ls to privilege escalation | Kitploit
도구/GitHubGitHub/mellen9999/cmdchamp
Password CrackingPrivilege EscalationWi-Fi AuditingHash AnalysisScripting & AutomationForensicsNetwork SecurityCTFPenetration TestingLearning & EducationLabs & Practice
127시간 24분 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
GitHub
mellen9999/cmdchamp

cmdchamp

bash CLI trainer — 30 levels from ls to privilege escalation

저장소 보기
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

cmdchamp

Bash CLI trainer — 30 levels from ls to privilege escalation.

demo

Every question asks you to type a real command — get instant feedback, move on. Many run against real files in the sandbox, and all accept multiple valid syntaxes (sort -u or sort | uniq). Tab toggles the manpage when you need a reference — condensed pages for every command the answer runs, plus the shell syntax it leans on (x=$(cmd), ${var:-default}, ${path##*/}), so nothing in a question is left for you to guess. The order is randomized each run so you can't memorize it. Mastery tracks what you know: get a question right twice to master it, miss it and it demotes so it comes back sooner. A 5-answer streak triggers fire mode — a banner that runs until you miss.

Each level ends with a boss round — no manpages, 30s timer, 4/5 to pass. Fail and you can retry the boss immediately or go back to practice. Beat all 30 and challenge mode unlocks — the endgame gauntlet: multi-command chains that compose the tools from across the whole game into one pipeline. 30s each, one life, no manpages, your best score is the record. Every chain is graded on its real output in the sandbox, so any correct pipeline passes. Each run also builds a fresh randomized sandbox — different IPs, counts, hosts, and log data — and draws from 50+ chain templates with rotating delimiters, sort order, and aggregates, so the busiest IP, the top URL, the highest count are never the same twice. First run includes a short tutorial and a placement test that lets you skip levels you already know.

With bubblewrap, commands run in a real sandboxed filesystem and are graded on their actual output. The box inside is synthetic - user sandbox, host sandbox, its own /etc/passwd and kernel command line - so nothing you type can print your real username, machine name or disk layout to the screen, and id, whoami and hostname answer the same everywhere. This now reaches the forensics tier too: level 28 hands you a real sample binary (samples/target.bin) and grades whether you actually pulled the flag, the exfil domain, and the leaked API key out of it — same for the jq questions on real JSON. The endgame gauntlet composes those extractions into timed chains. Only the tools that genuinely can't run in a sandbox — live network/wifi/nmap and large memory/disk forensics — stay text-matched. Search levels (16-17) accept both rg/fd and grep/find syntax. Vi line editing is built in — motions, operators, counts, registers, undo and visual mode (/, to swap ends), with for the full map.

Install

Arch (AUR):

root@kitploit:~
paru -S cmdchamp   # or: yay -S cmdchamp

Anywhere (single file):

root@kitploit:~
mkdir -p ~/.local/bin && curl -sL https://raw.githubusercontent.com/mellen9999/cmdchamp/main/cmdchamp -o ~/.local/bin/cmdchamp && chmod +x ~/.local/bin/cmdchamp

Add ~/.local/bin to PATH if needed: echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc

Or clone:

root@kitploit:~
git clone https://github.com/mellen9999/cmdchamp.git
cd cmdchamp && make install

Requires: bash 4.4+, coreutils, awk

macOS: Ships with bash 3.2 — install bash 4.4+ first: brew install bash

Optional: bubblewrap (bwrap) for sandbox mode (Linux only) — most desktop distros include it. Without it, answers are text-matched only

Accessibility: Honors NO_COLOR and TERM=dumb. Layout adapts to COLUMNS / tput cols. Mastery bars carry both color and a ✓ / ~ / x symbol — readable without color.

Terminals: Runs on real serial terminals, not just emulators. cmdchamp probes what the terminal can actually display and picks one of three render tiers — unicode, DEC ACS line-drawing, or pure ASCII — so frames stay intact on a VT100/VT220/VT320/VT420 or Wyse. On a monochrome screen, color distinctions are re-encoded as bold/reverse. Force a tier with CMDCHAMP_ASCII=1 or CMDCHAMP_UNICODE=1. ./test_terminals.sh verifies it.

Usage

root@kitploit:~
cmdchamp                # Launch the game menu
cmdchamp daily          # Play today's daily gauntlet (same run for everyone)
cmdchamp daily 2026-02-16   # Replay a specific day's run (race a friend)
cmdchamp play           # Free-play sandbox: type any command, see it run
cmdchamp --no-sandbox   # Disable sandbox (text-match only)
cmdchamp reset          # Clear all progress
cmdchamp test           # Run self-tests
cmdchamp version        # Print version
cmdchamp help           # Show help

The menu holds continue, new game, scenarios, challenge, daily, practice, stats, options, help and quit on fixed hotkeys 1-9 and 0. A row you haven't unlocked is greyed rather than hidden, so the digit beside a label never moves as you progress. j/k or arrows move, Enter selects, and q (or Esc) quits. The playground lives at the top of the Scenarios list — it's the one entry that is never locked.

Daily (post-ROOT) is a date-seeded gauntlet run — the seed drives both the chains and the randomized sandbox, so everyone everywhere gets byte-identical questions and data that day, one scored attempt, a consecutive-day streak, and a copyable score you can share. Practice drills any reached level (shown with its mastery %) with hints and no timer, without touching your main progress. Playground is a compromised box you take apart with a real shell: someone got in, used it, then tried to tidy up, and every move left a mark on disk. Commands run for real in the sandbox and nothing is graded. Up to 8 flag{...} tokens are planted across the tree (more unlock as you clear levels), map lays the break-in out phase by phase, learn is the 8-module security syllabus behind it, hint goes a tier deeper each time you ask, and Tab explains what you typed.

Levels

Scenarios

Multi-step sandbox challenges — state persists between steps. Available from the Scenarios menu once you clear the unlock boss, which lists them in unlock order under the playground. The numbers below are scenario ids, which never change.

Scenarios 12–13 are exploit boxes: you plant a real tar-checkpoint injection / PATH hijack and are graded on the artifact it produces (a file appears, a secret gets exfiltrated). The exploit's effect runs for real in the sandbox; the privilege boundary is simulated — nothing runs as real root.

Placement test

After the first-run tutorial, you're asked if you want to take the placement test to skip ahead. Accept and it runs 2 questions per level, 30s each, no manpages. Miss one and that's your starting level.

Easter eggs

8 hidden achievements. The Stats screen shows how many you've found.

Controls

KeyAction
EnterSubmit answer
TabToggle manpage
Ctrl+dQuit (session summary)
EscVi normal mode

Data

Progress saves to ${XDG_DATA_HOME:-~/.local/share}/cmdchamp/.

License

MIT

도구 다운로드
v
V
o
?
#NameFocus
Fundamentals
1First Stepspwd, ls, echo, cd, mkdir
2File Basicscp, mv
3Save Your Work>, >>, tee
4Reading Filescat, head, tail, less
5Basic Pipespipes, grep, wc, sort, uniq
6Input & Here-Strings<, <<<, tr, cut, rev, bc
7Error Handling2>, 2>&1, &>, /dev/null
8Logic Gates&&, ||
9Variables$VAR, assignment, expansion
10Special Variables$$, $?, $!, $#, $@, $0
11Job Controlbg, fg, jobs, &, Ctrl+Z, nice, ulimit
12Test Conditions-f, -d, -z, -n, -eq, -lt
13Core File Toolscp, mv, ln, chmod, ACLs, du, tar, diff
14System Adminping, df, free, ss, systemctl, ip, sysctl, lsblk, getent
15Multiplexerstmux: sessions, windows, panes
16Text Searchgrep, ripgrep, regex
17File Findingfind, fd, by name/size/time/type
18Data Processingsort, uniq, cut, awk, tr, comm, join, numfmt
19String & Arraysparameter expansion, arrays
20Control Flowif/else, loops, case, functions
21Batch Opsfind -exec, xargs, sed -i, crontab
22Advanced Regexlookahead, sed, awk
DevOps & Security
23Gitbranches, remotes, rebasing, stashing, bisect
24Network Toolstshark, curl, jq, ssh tunnels, openssl, SMB
25Network Scanningnmap, service detection, scripts
26WiFi & RFaircrack-ng, netcat, tcpdump, wireless recon
27Hash Crackinghashcat, john, hydra, encoding
28Forensicsstrings, readelf, binwalk, volatility, exiftool
29Privilege EscalationSUID, capabilities, GTFOBins, enumeration
30ROOTemergency recovery, chroot, offline survival
#NameUnlocks atSteps
1Permission LockoutL13 boss6
2Archive & ExtractL13 boss6
3Find the NeedleL16 boss7
4Messy CSVL18 boss4
5The IncidentL18 boss5
6The Broken DeployL21 boss7
7Log EmergencyL21 boss5
8Config SurgeryL21 boss5
9Git RescueL23 boss6
10Batch RefactorL21 boss6
11Forensic SweepL22 boss6
12Wildcard BackupL29 boss4
13PATH HijackL29 boss4
?All keybindings (normal mode)