Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
cmdchamp — bash CLI trainer — 30 levels from ls to privilege escalation | Kitploit
Ferramentas/GitHubGitHub/mellen9999/cmdchamp
Password CrackingPrivilege EscalationWi-Fi AuditingHash AnalysisScripting & AutomationForensicsNetwork SecurityCTFPenetration TestingLearning & EducationLabs & Practice
12há 9h 18mAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
GitHub
mellen9999/cmdchamp

cmdchamp

bash CLI trainer — 30 levels from ls to privilege escalation

Ver Repositório
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

cmdchamp

Bash CLI trainer — 30 levels from ls to privilege escalation.

demo

Every question asks you to type a real command — get instant feedback, move on. Many run against real files in the sandbox, and all accept multiple valid syntaxes (sort -u or sort | uniq). Tab toggles the manpage when you need a reference — condensed pages for every command the answer runs, plus the shell syntax it leans on (x=$(cmd), ${var:-default}, ${path##*/}), so nothing in a question is left for you to guess. The order is randomized each run so you can't memorize it. Mastery tracks what you know: get a question right twice to master it, miss it and it demotes so it comes back sooner. A 5-answer streak triggers fire mode — a banner that runs until you miss.

Each level ends with a boss round — no manpages, 30s timer, 4/5 to pass. Fail and you can retry the boss immediately or go back to practice. Beat all 30 and challenge mode unlocks — the endgame gauntlet: multi-command chains that compose the tools from across the whole game into one pipeline. 30s each, one life, no manpages, your best score is the record. Every chain is graded on its real output in the sandbox, so any correct pipeline passes. Each run also builds a fresh randomized sandbox — different IPs, counts, hosts, and log data — and draws from 50+ chain templates with rotating delimiters, sort order, and aggregates, so the busiest IP, the top URL, the highest count are never the same twice. First run includes a short tutorial and a placement test that lets you skip levels you already know.

With bubblewrap, commands run in a real sandboxed filesystem and are graded on their actual output. The box inside is synthetic - user sandbox, host sandbox, its own /etc/passwd and kernel command line - so nothing you type can print your real username, machine name or disk layout to the screen, and id, whoami and hostname answer the same everywhere. This now reaches the forensics tier too: level 28 hands you a real sample binary (samples/target.bin) and grades whether you actually pulled the flag, the exfil domain, and the leaked API key out of it — same for the jq questions on real JSON. The endgame gauntlet composes those extractions into timed chains. Only the tools that genuinely can't run in a sandbox — live network/wifi/nmap and large memory/disk forensics — stay text-matched. Search levels (16-17) accept both rg/fd and grep/find syntax. Vi line editing is built in — motions, operators, counts, registers, undo and visual mode (/, to swap ends), with for the full map.

Install

Arch (AUR):

root@kitploit:~
paru -S cmdchamp   # or: yay -S cmdchamp

Anywhere (single file):

root@kitploit:~
mkdir -p ~/.local/bin && curl -sL https://raw.githubusercontent.com/mellen9999/cmdchamp/main/cmdchamp -o ~/.local/bin/cmdchamp && chmod +x ~/.local/bin/cmdchamp

Add ~/.local/bin to PATH if needed: echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc

Or clone:

root@kitploit:~
git clone https://github.com/mellen9999/cmdchamp.git
cd cmdchamp && make install

Requires: bash 4.4+, coreutils, awk

macOS: Ships with bash 3.2 — install bash 4.4+ first: brew install bash

Optional: bubblewrap (bwrap) for sandbox mode (Linux only) — most desktop distros include it. Without it, answers are text-matched only

Accessibility: Honors NO_COLOR and TERM=dumb. Layout adapts to COLUMNS / tput cols. Mastery bars carry both color and a ✓ / ~ / x symbol — readable without color.

Terminals: Runs on real serial terminals, not just emulators. cmdchamp probes what the terminal can actually display and picks one of three render tiers — unicode, DEC ACS line-drawing, or pure ASCII — so frames stay intact on a VT100/VT220/VT320/VT420 or Wyse. On a monochrome screen, color distinctions are re-encoded as bold/reverse. Force a tier with CMDCHAMP_ASCII=1 or CMDCHAMP_UNICODE=1. ./test_terminals.sh verifies it.

Usage

root@kitploit:~
cmdchamp                # Launch the game menu
cmdchamp daily          # Play today's daily gauntlet (same run for everyone)
cmdchamp daily 2026-02-16   # Replay a specific day's run (race a friend)
cmdchamp play           # Free-play sandbox: type any command, see it run
cmdchamp --no-sandbox   # Disable sandbox (text-match only)
cmdchamp reset          # Clear all progress
cmdchamp test           # Run self-tests
cmdchamp version        # Print version
cmdchamp help           # Show help

The menu holds continue, new game, scenarios, challenge, daily, practice, stats, options, help and quit on fixed hotkeys 1-9 and 0. A row you haven't unlocked is greyed rather than hidden, so the digit beside a label never moves as you progress. j/k or arrows move, Enter selects, and q (or Esc) quits. The playground lives at the top of the Scenarios list — it's the one entry that is never locked.

Daily (post-ROOT) is a date-seeded gauntlet run — the seed drives both the chains and the randomized sandbox, so everyone everywhere gets byte-identical questions and data that day, one scored attempt, a consecutive-day streak, and a copyable score you can share. Practice drills any reached level (shown with its mastery %) with hints and no timer, without touching your main progress. Playground is a compromised box you take apart with a real shell: someone got in, used it, then tried to tidy up, and every move left a mark on disk. Commands run for real in the sandbox and nothing is graded. Up to 8 flag{...} tokens are planted across the tree (more unlock as you clear levels), map lays the break-in out phase by phase, learn is the 8-module security syllabus behind it, hint goes a tier deeper each time you ask, and Tab explains what you typed.

Levels

Scenarios

Multi-step sandbox challenges — state persists between steps. Available from the Scenarios menu once you clear the unlock boss, which lists them in unlock order under the playground. The numbers below are scenario ids, which never change.

Scenarios 12–13 are exploit boxes: you plant a real tar-checkpoint injection / PATH hijack and are graded on the artifact it produces (a file appears, a secret gets exfiltrated). The exploit's effect runs for real in the sandbox; the privilege boundary is simulated — nothing runs as real root.

Placement test

After the first-run tutorial, you're asked if you want to take the placement test to skip ahead. Accept and it runs 2 questions per level, 30s each, no manpages. Miss one and that's your starting level.

Easter eggs

8 hidden achievements. The Stats screen shows how many you've found.

Controls

KeyAction
EnterSubmit answer
TabToggle manpage
Ctrl+dQuit (session summary)
EscVi normal mode

Data

Progress saves to ${XDG_DATA_HOME:-~/.local/share}/cmdchamp/.

License

MIT

Baixar ferramenta
v
V
o
?
#NameFocus
Fundamentals
1First Stepspwd, ls, echo, cd, mkdir
2File Basicscp, mv
3Save Your Work>, >>, tee
4Reading Filescat, head, tail, less
5Basic Pipespipes, grep, wc, sort, uniq
6Input & Here-Strings<, <<<, tr, cut, rev, bc
7Error Handling2>, 2>&1, &>, /dev/null
8Logic Gates&&, ||
9Variables$VAR, assignment, expansion
10Special Variables$$, $?, $!, $#, $@, $0
11Job Controlbg, fg, jobs, &, Ctrl+Z, nice, ulimit
12Test Conditions-f, -d, -z, -n, -eq, -lt
13Core File Toolscp, mv, ln, chmod, ACLs, du, tar, diff
14System Adminping, df, free, ss, systemctl, ip, sysctl, lsblk, getent
15Multiplexerstmux: sessions, windows, panes
16Text Searchgrep, ripgrep, regex
17File Findingfind, fd, by name/size/time/type
18Data Processingsort, uniq, cut, awk, tr, comm, join, numfmt
19String & Arraysparameter expansion, arrays
20Control Flowif/else, loops, case, functions
21Batch Opsfind -exec, xargs, sed -i, crontab
22Advanced Regexlookahead, sed, awk
DevOps & Security
23Gitbranches, remotes, rebasing, stashing, bisect
24Network Toolstshark, curl, jq, ssh tunnels, openssl, SMB
25Network Scanningnmap, service detection, scripts
26WiFi & RFaircrack-ng, netcat, tcpdump, wireless recon
27Hash Crackinghashcat, john, hydra, encoding
28Forensicsstrings, readelf, binwalk, volatility, exiftool
29Privilege EscalationSUID, capabilities, GTFOBins, enumeration
30ROOTemergency recovery, chroot, offline survival
#NameUnlocks atSteps
1Permission LockoutL13 boss6
2Archive & ExtractL13 boss6
3Find the NeedleL16 boss7
4Messy CSVL18 boss4
5The IncidentL18 boss5
6The Broken DeployL21 boss7
7Log EmergencyL21 boss5
8Config SurgeryL21 boss5
9Git RescueL23 boss6
10Batch RefactorL21 boss6
11Forensic SweepL22 boss6
12Wildcard BackupL29 boss4
13PATH HijackL29 boss4
?All keybindings (normal mode)