Learn to think like a defender by learning to break in.
Work through five modules that take you from the basics to real attacks, then prove your skills against a live vulnerable web app and submit your results here.
- 01Five modules that each teach and test one idea, from the CIA triad to how websites get hacked.
- 02Hands-on activities where you crack a cipher, break weak passwords, and bypass a login safely.
- 03A marked practical on the OWASP Juice Shop, plus a written reflection.
Understand the threat
Start with the ideas behind every security decision. What attackers want, how they get in, and what we are protecting.
Try it on safe targets
Every activity runs in a legal practice environment. You crack ciphers, test weak passwords, and bypass a fake login, with nothing real at risk.
Attack a real app
Finish on the OWASP Juice Shop, a deliberately vulnerable web shop used by security teams worldwide. Solve its challenges and submit your flags here.
Everything you do is stored against your name
Create an account and your progress follows you. Which modules you have finished, the challenges you have solved, your points, and your reflection are all saved to the cloud, not just this browser. Your teacher sees it in one place and enters your marks there.
Create your accountOnly test what you are allowed to test
Everything here is legal and safe because you have permission to attack these practice targets. Using these techniques on any system you do not own or have written permission to test is against the law. Real security professionals live by that line, and so do we.