The Bootcamp
The free way in. A guided main path that takes you from your first HTTP request to finding and explaining real web bugs — hands-on, in order, no card needed.
6Bootcamp exercises
5Free online labs
3Free offline labs
42Keys to capture
Step 1
Start safe
The one rule that separates practice from a crime: permission and scope.
| 1 | Scope & Rules of Engagement
The difference between a penetration tester and a criminal is permission. Learn what authorisation and scope mean, what a rules-of-engagement document covers, and why it comes first. |
Easy | Free |
Step 2
How the web really works
Read a request, understand why the browser is the attacker's side, and see where bugs come from.
| 2 | How HTTP Works
Read a real request and response, learn the method and status-code vocabulary, and see why the browser is a place attackers control. |
Easy | Free |
| 3 | Where Web Bugs Come From
One idea sits underneath almost every web vulnerability: the application trusted input it should have checked. Learn to see that pattern everywhere. |
Easy | Free |
Step 3
Set up your own targets
Install the tools and deliberately-vulnerable apps you will practise on, all on your own machine.
| 4 | Offline Lab: See & Edit Real Requests (Intercepting Proxy)
Install a local intercepting proxy, route your browser through it, and watch — then modify — the real HTTP requests behind a page you control. The tool every web tester lives in. |
Easy | Free |
| 5 | Offline Lab: Your First Local Target (DVWA)
Download and run a deliberately-vulnerable web app on your own machine, then practise the bugs you have learned against it. No internet target involved. |
Easy | Free |
| 6 | Offline Lab: A Modern Target (OWASP Juice Shop)
Run OWASP Juice Shop — a modern single-page web app full of real-world bugs — on your own machine and learn to recon and poke a live application you control. |
Medium | Free |
Finished the bootcamp?
Keep going with the full tracks — the same hands-on style, all the way to job-ready.