Every box I've rooted — searchable, filterable, fully documented.
A Linux box running a Flask-based wallpaper-sharing app — testing a filename path-traversal LFI to read application source, credential recovery from leaked backend code, a sudo-permitted Node.js scraper binary, and a real-world script-injection vulnerability in the happy-dom library for the path to root.
A Linux box exposing a leaked .git repository alongside a public-facing SOPlanning instance — testing git-history mining for plaintext database credentials, direct database manipulation to reset an application login, a real-world authenticated RCE, cron-exposed credential reuse, and a writable Flask app run with elevated sudo permissions for the path to root.
A Linux box running MantisBT bug tracker — testing exploitation of a rogue-MySQL-server arbitrary file-read CVE to steal application database credentials, offline hash cracking for admin access, an authenticated configuration-based RCE technique, and cron-job credential exposure combined with unrestricted sudo for the path to root.
A Linux box running Tiny File Manager instrumented with the PHP-SPX profiler — testing discovery of a low-profile CVE via a leaked phpinfo page, a path-traversal read of application source to recover and crack login hashes, and a sudo-permitted make install target for the path to root.
A Linux box running JetBrains TeamCity behind a marketing site — testing exploitation of a real-world authentication-bypass CVE to enable debug-mode command execution, mining git commit history for a removed SSH key, offline key/password cracking, a chain of leaked credentials across several users, and a GTFOBins sudo escape for the path to root.
A Linux box running a file-zipping web app — testing a PHP filter-wrapper LFI to read source code, a `zip://` PHP-wrapper technique to execute an uploaded archive as code for a foothold, and a root-owned backup cron job whose password-protected archive leaks the root password for the path to root.
A Linux box fronting a marketing site that hides a LimeSurvey subdomain — testing default-credential access into LimeSurvey, an authenticated malicious-plugin upload for RCE, credential harvesting from a leaked application config, and an mlocate database leak combined with a symlink bypass of a restrictive sudo script for the path to root.
A Linux box running WordPress alongside an internally-reachable Redis instance — testing exploitation of a vulnerable-plugin LFI, a Redis rogue-server RCE technique gated behind a leaked config password, database-credential pivoting back through the same LFI for a web-user shell, and a tar wildcard-injection cron job for the path to root.
A Linux box running a blog-style API and an internal git server — testing unauthenticated API enumeration for leaked user credentials, a null-session SMB share for lateral clues, and a root-owned cron-triggered git repository we can push malicious commits to for the path to root.
A Linux box running an OpenEMR medical-records portal alongside a vulnerable file manager — testing chained exploitation of a file-manager directory-traversal bug (using a writable anonymous SMB share as a read-back channel) to steal database credentials, offline hash cracking for an authenticated RCE, and root password reuse for the path to root.
A Linux box running a Java issue-tracker app alongside a NextCloud instance — testing leaked backend source code recovered through default-credential NextCloud access, identification of a SQL-injection sink in a custom endpoint, and an INTO OUTFILE webshell write for a direct path to root.
A Linux box running a Postfix/Dovecot mail stack behind a marketing site — testing SMTP VRFY-based username enumeration, credential bruteforcing against POP3/IMAP, a live spear-phishing pivot to harvest a second credential, and abuse of a mail-filter disclaimer script for a GTFOBins-assisted path to root.
A Windows box running Argus Surveillance DVR — testing exploitation of a public directory-traversal vulnerability for arbitrary file reads, theft of a leaked SSH private key for a foothold, and reversal of the application's proprietary weak password-encryption scheme to recover local administrator credentials for the path to SYSTEM.
An aging Windows Server 2008 box — testing identification of an outdated SMB2 service version and exploitation of a well-known public remote-code-execution vulnerability for a direct SYSTEM shell.
A Windows box running a remote-input desktop application — testing exploitation of a public arbitrary-command-execution vulnerability for a foothold, credential recovery from a leaked FTP client config, and a GUI file-dialog privilege-escalation trick in the same application for the path to SYSTEM.
A Linux box running a RaspAP wifi-management portal behind HTTP Basic Auth — testing default-credential access, discovery of a built-in web console for command execution, and a Python library-hijacking technique against a sudo-permitted script for the path to root.
A Windows box fronting an old FTP server and a Basic-Auth-restricted web app — testing anonymous FTP enumeration to leak account artifacts, offline cracking of a leaked htpasswd hash to pass Basic Auth, abuse of writable FTP storage to plant a web-reachable PHP shell, and a SeImpersonatePrivilege token-impersonation technique for the path to SYSTEM.
A Linux box running a NodeBB forum backed by Redis and MongoDB — testing service enumeration across an exposed forum, key-value store, and document database, then exploitation of an unauthenticated Redis remote-code-execution technique for a direct root shell.
A WordPress install alongside an exposed eXtplorer file-manager plugin — testing default-credential access into a web-based file manager, a magic-bytes-free webshell upload for a foothold, credential-store extraction and offline hash cracking for lateral movement, and a disk-group/raw-block-device read technique for privilege escalation.
A Linux box fronted by an Openfire XMPP server whose Hadoop-flavored nmap fingerprint is a red herring — testing identification and exploitation of a real-world authentication-bypass CVE for a foothold, followed by embedded application-database credential harvesting and password reuse for the path to root.
A Linux box running Grafana and Prometheus monitoring services — testing exploitation of a real-world directory-traversal/arbitrary-file-read vulnerability to pull an application database, extraction and offline AES decryption of an embedded data-source credential, and a disk-group raw-block-device read technique to steal a root SSH key for privilege escalation.
A Debian box hosting a "file scanner" web app that only accepts uploads whose leading bytes look like a Windows PE — testing a magic-bytes upload-filter bypass and an .htaccess handler trick for a web foothold, followed by an extended-ACL directory grant and a SUID-binary GTFOBins abuse for the path to root.
An Arch Linux box running WordPress alongside a couple of internal-only services — testing plugin-version enumeration against a known arbitrary file-upload vulnerability for a webshell foothold, then a rare SUID DOS-emulator binary abused via GTFOBins to overwrite `/etc/passwd` for root.
A Windows XAMPP box hiding a WordPress install behind a guessable directory name — testing guest-accessible SMB shares for leaked default credentials, an authenticated malicious-plugin upload for a reverse-shell foothold, and the classic AlwaysInstallElevated MSI misconfiguration for SYSTEM.
A Debian box exposing NFS, an unauthenticated control panel, and a Tomcat instance — testing zip-archive information disclosure to recover a private SSH key restricted to a forced `scp` command, an authorized_keys overwrite to escape that restriction, and a writable SUID binary abused via GTFOBins for root.
A Debian box running a Cassandra database front-end alongside FreeSWITCH — testing an unauthenticated local-file-read vulnerability in the database web UI to harvest a service password, an authenticated telephony-platform exploit for an initial foothold, and a chain of leaked SSH keys and a sudo-permitted binary to pivot all the way to root.
A heavily service-laden Windows box running an application server alongside a file-manager webapp — testing an application-server path traversal to disclose configuration files and a hashed admin credential, spraying a recovered plaintext password across SMB and RDP, and a Windows-service binary swap to escalate to SYSTEM after an antivirus-based privesc attempt hits a dead end.
An Ubuntu box running a recent WordPress install — testing a known SQL-injection CVE to dump password hashes, credential reuse across FTP/SSH/the database, and a custom SUID monitoring binary that loads a missing shared library from a predictable path for root.
An Ubuntu box running a system-administration web console alongside a small login portal — testing a classic SQL-injection authentication bypass to recover credentials, pivoting them into the admin console's built-in terminal, and abusing a wildcard-driven sudo rule around `tar` to exfiltrate root's SSH key.
A Windows box exposing a pair of undocumented internal HTTP APIs — testing HTTP-verb and header manipulation to coax data out of an unauthenticated process-listing endpoint, credential hunting across a leaked command line and a password-protected PDF, pivoting to an internal-only API via a tunnel, and abusing a hidden arbitrary-command endpoint for SYSTEM.
A Windows box fronted entirely by a Squid HTTP proxy — testing proxy-relayed port scanning to uncover internal-only services, default credentials on an exposed phpMyAdmin instance, a SQL `INTO OUTFILE` webshell, and a SeImpersonatePrivilege abuse tool for SYSTEM.
A vintage Ubuntu box running an old ZenPhoto gallery — testing a public RCE exploit against a known ZenPhoto version for an initial (badly-behaved) shell, extensive shell-stabilization and file-transfer troubleshooting around aggressive filesystem permissions, and a classic kernel exploit for root on a box too old for modern enumeration tooling.
A Windows box serving a résumé-upload web form — testing an OpenDocument macro payload to smuggle a reverse shell past a filetype check, lateral movement into a webapp service account via a writable web root, and a SeImpersonatePrivilege abuse tool to finish as SYSTEM.
A Linux box exposing SSH, SMTP, a Flask-based webapp, and a Samba share — testing service-version fingerprinting against a known remote code execution vulnerability in the mail transfer agent for a direct-to-root foothold.
A Debian box exposing FTP, SSH, a webapp, and PostgreSQL — testing default database credentials, a known authenticated command-execution vulnerability in PostgreSQL's `COPY ... FROM PROGRAM`, and a classic SUID binary abuse via GTFOBins for root.
An Ubuntu box running Tomcat and a video-surveillance webapp — testing a blind stacked-query SQL injection in the surveillance software to write a PHP webshell to disk, then chasing leaked database credentials into a root-owned MySQL instance that sqlmap's OS-shell can leverage for full compromise.
A dual-instance XAMPP box running a custom PHP site — testing an LFI-that's-actually-an-RFI discovery via `php://filter`, config-file credential disclosure, and a writable scheduled-task binary swap to land Administrator.
A CentOS box running a legacy PHP photo gallery — testing a remote-file-inclusion vulnerability for a webshell foothold, database credentials that unlock a doubly-base64-encoded password reused by a second user, and a writable `/etc/passwd` file for direct root escalation.
A Windows box running a full legacy mail server stack (SMTP/POP3/IMAP/finger/HTTP) — testing username discovery via the finger protocol, IMAP credential bruteforcing, an office-macro phishing payload delivered through the mail server's own document-processing automation, and a running SYSTEM service binary swapped out via a file-rename trick to finish the box.
A Windows box running an old, unmaintained CMS behind XAMPP — testing CMS enumeration and a hand-built PHP webshell dropped through the admin theme editor for a foothold, then a known local privilege-escalation trick against the XAMPP control panel configuration to finish as Administrator.
An aging Ubuntu box running an early-2000s shopping cart application — testing version fingerprinting against a shelf of dated CVEs, an authenticated template-editor file upload to drop a PHP webshell, and a guessable user password that turns out to carry unrestricted sudo rights.
An aging Debian box running a mail stack alongside Samba and SNMP — testing null-session SMB and community-string SNMP enumeration to fingerprint running services, then a known remote command execution vulnerability in a mail-filtering daemon reachable through crafted SMTP envelope fields.
A Debian box running Samba, CUPS, and a ZooKeeper cluster manager — testing a known command-injection RCE in the ZooKeeper web supervisor for a foothold, then abusing a sudo-permitted core-dump utility to harvest a plaintext root password straight out of process memory.
A Windows box running a Java artifact repository manager — testing default/guessable admin credentials, a known authenticated remote-code-execution exploit against the repository software, and a SeImpersonatePrivilege abuse tool to escalate a webapp-service shell to SYSTEM.
A Windows box running a NuGet feed and a legacy embedded web server side by side — testing weak/guessable admin credentials on a Java artifact manager and a misconfigured WebDAV endpoint that exposes the entire filesystem for direct flag retrieval.
A Windows box running a mail server suite alongside a default IIS install — testing anonymous FTP log-diving for service fingerprints and a known deserialization remote-code-execution vulnerability in the mail client's remoting service.
A minimal Ubuntu box running a crawler-management webapp — testing default-credential access to a known authenticated remote-code-execution vulnerability, and a Linux file-capability misconfiguration on the Python interpreter for a direct root escalation.
A Linux box exposing NFS, mail, and web services — testing NFS share enumeration for leaked onboarding documents, chained credential reuse across a webmail portal and an admin panel, exploitation of a real-world authenticated remote-code-execution CVE, and database credential harvesting for an unauthenticated command-injection path to root.
A Windows box exposing an embedded Java database console — testing a known script-engine remote-code-execution technique against the database's web console for an initial foothold, then a SeImpersonatePrivilege abuse tool to finish as SYSTEM.
A legacy Windows 7 box running a UPS management webapp — testing default-credential login and a known buffer-overflow exploit against the management software for a direct SYSTEM shell via Metasploit.
A Windows Active Directory domain controller — testing RID-cycling enumeration that leaks a plaintext password from a user description field, a grossly misconfigured share that exposes the domain's NTDS database directly, offline hash extraction and pass-the-hash, and BloodHound-guided resource-based constrained delegation abuse to DCSync the domain.
A Windows Active Directory domain controller reachable only as guest — testing a writable file share seeded with NTLM-theft lure files to capture and crack a domain user's NetNTLMv2 hash, then a SeBackupPrivilege abuse technique to read protected files off the DC without ever landing a shell on it.
A Windows Active Directory domain controller fronting a public-facing event site — testing web file-upload filter bypasses, Apache `.htaccess` abuse to smuggle an executable extension past a blocklist, and Kerberos service-account attacks (kerberoasting plus a credentialed run-as tool) to move from a low-privileged web account toward a domain service account.
A full Windows Active Directory domain controller — testing web-scraped username generation, ASREPRoast and password-spraying, kerberoasting two service accounts, BloodHound-guided ACL abuse to reset a helpdesk account's password and pivot into a WinRM-capable user, tunneled access to an internal MSSQL instance, a forged silver ticket to reach a sysadmin database context, and SeImpersonatePrivilege abuse to land full domain compromise.
A Linux box running FreePBX — testing identification and exploitation of a real-world unauthenticated SQL-injection CVE for a foothold via an injected cron job, then enumeration of root-owned incron triggers and a writable PHP include path for the path to root.
A Linux box hosting internal AI/dev-tooling infrastructure — testing identification and exploitation of a real-world unauthenticated remote-code-execution CVE in an MCP inspector tool, pivoting through an internally-exposed Jupyter notebook and a hardcoded-API-key backend service, for the path to root.
A hard Active Directory box exercising the full offensive AD workflow — SMB share enumeration, Kerberos pre-authentication attacks, BloodHound-driven ACL analysis, and a backup-operator privilege path to the domain's secret store. A thorough tour of chaining delegated directory permissions into domain compromise.
A Linux box running a Next.js web app — testing identification and exploitation of a real-world unauthenticated Next.js remote-code-execution CVE for a foothold, offline hash cracking of database-stored credentials, and abuse of an exposed root-owned Node.js debug inspector for the path to root.
An Active Directory box starting from a foothold credential, exercising BloodHound-driven enumeration and a chain of ACL abuses — delegated password resets, targeted Kerberoasting, and DCSync — to walk outbound object-control rights up to full domain compromise.
A beginner-friendly Active Directory box covering core domain reconnaissance — SMB share enumeration, password spraying, LDAP and RID-based user discovery, and a backup-operator privilege path to the domain's secret store. A clean introduction to turning a low-privilege foothold into domain compromise.
An easy Linux box that rewards methodical web enumeration — uncovering a hidden, vulnerable blogging CMS for a foothold, then escalating through a classic writable-script sudo misconfiguration. A solid primer on CMS exploitation and Linux sudo privilege escalation.
An easy Windows box centered on a misconfigured Apache Tomcat server — exercising default-credential checks and abusing the web application manager's deployment feature for code execution. A quick lesson in why exposed management interfaces are dangerous.
A beginner-friendly Active Directory box covering the domain-attack fundamentals: anonymous SMB enumeration, a legacy Group Policy Preferences credential exposure, and Kerberoasting — a clean introduction to chaining small AD misconfigurations into full domain compromise.
A Linux web box centered on an image-shrinking service: it tests source-code recovery from an exposed version-control directory, exploitation of an image-processing library, and abuse of a root-run file-analysis tool for privilege escalation.
A Windows IIS box centred on a custom PHP notes application, exercising client-side request forgery against an authenticated action, credential discovery, and abuse of writable SMB shares for web-shell upload. Privilege escalation explores a Windows Subsystem for Linux install and the credential trails left behind in shell history.
A Linux box centred on a public-facing IT ticketing application and credential-store hygiene. It exercises virtual-host discovery, default-credential hunting against a web app, recovering secrets from a leaky password manager, and pivoting between SSH key formats to escalate.
A Windows box centered on a forgotten Jenkins automation server exposed on a non-standard port. It exercises web content discovery, abusing a CI/CD scripting console for command execution, cracking an offline password-manager database, and Windows credential reuse plus NTFS alternate data streams for the final loot.
An easy Windows box centered on credential hunting across a support portal, leaked network-device configs, and a logged-in desktop application. It exercises Cisco password recovery, SMB/RPC user enumeration, password spraying, and dumping secrets from process memory — a tidy lesson in chaining harvested credentials toward full compromise.
A medium Windows box built around a Microsoft SQL Server instance — exercising SMB share enumeration, secrets hidden in an Office macro, MSSQL client interaction, NTLM hash capture and offline cracking, and a Windows privilege-escalation audit with PowerUp. A well-rounded tour of MSSQL attack paths and Windows credential hygiene failures.
A Windows 7 box centered on a vulnerable third-party chat service, exercising memory-corruption exploitation against a custom network daemon and post-exploitation enumeration that surfaces stored credentials for privilege escalation and credential reuse.
A domain-controller Active Directory box exercising anonymous LDAP enumeration, Kerberos pre-authentication credential attacks, and BloodHound-driven ACL analysis. It is a tidy introduction to mapping AD relationships and chaining group/ACL misconfigurations into full domain compromise.
An Active Directory domain controller that rewards careful enumeration — turning names harvested from a public website into a username wordlist, abusing Kerberos pre-authentication weaknesses, hunting for cached credentials in the Windows registry, and mapping replication rights in BloodHound to reach full domain compromise.
A Windows host exposing a mix of legacy network-monitoring software alongside FTP, SSH, and a locally-bound management console. It exercises anonymous file-share enumeration, web path-traversal/LFI against a vulnerable surveillance app, password reuse and credential hunting, and privilege escalation through an over-privileged service reachable via an SSH tunnel.
A short Active Directory box centered on a network printer's administration interface and the credentials it exposes through LDAP authentication. It exercises capturing service-account credentials by redirecting an appliance's directory binds, then chaining a privileged Windows group membership into SYSTEM-level service abuse for full domain compromise.
A medium Linux box centred on a legacy mail stack — exercising SMTP/POP3 service enumeration, abuse of an exposed remote-administration interface guarded only by default credentials, and credential discovery hidden in mailbox contents. Privilege escalation tests restricted-shell escape and the abuse of a privileged scheduled task. A solid primer on mail-server tradecraft and Linux cron-based root paths.
A FreeBSD web host exercising local file inclusion and path traversal against a script-testing endpoint, layered encoding of a recovered secret, password reuse against an encrypted archive, and pivoting through SSH-tunneled internal services to reach a locally-bound remote desktop. Tests source-disclosure enumeration, credential recovery, and port-forwarding tradecraft.
An easy Windows box built around a legacy Adobe ColdFusion application server — exercising service fingerprinting on a non-standard port, research into known web-application vulnerabilities, and offline hash cracking, followed by a classic Windows token-impersonation privilege escalation against an older Server 2008 host.
A beginner-friendly Windows box centred on credential hunting through legacy file formats: anonymous FTP access leads to a Microsoft Access database and an encrypted archive, while privilege escalation explores stored Windows credentials. A clean introduction to pivoting between forgotten artifacts and abusing cached secrets.
A Windows host running a network-monitoring web application, where anonymous file-share access and leftover configuration artifacts feed an authenticated remote-code-execution flaw. Exercises service enumeration, credential hunting in config backups, and turning leaked credentials into a CVE-based shell.
// no machines match that filter