The Bootcamp

The free way in. A guided main path that takes you from your first HTTP request to finding and explaining real web bugs — hands-on, in order, no card needed.

6Bootcamp exercises
5Free online labs
3Free offline labs
42Keys to capture
Step 1

Start safe

The one rule that separates practice from a crime: permission and scope.

1 Scope & Rules of Engagement
The difference between a penetration tester and a criminal is permission. Learn what authorisation and scope mean, what a rules-of-engagement document covers, and why it comes first.
Easy Free
Step 2

How the web really works

Read a request, understand why the browser is the attacker's side, and see where bugs come from.

2 How HTTP Works
Read a real request and response, learn the method and status-code vocabulary, and see why the browser is a place attackers control.
Easy Free
3 Where Web Bugs Come From
One idea sits underneath almost every web vulnerability: the application trusted input it should have checked. Learn to see that pattern everywhere.
Easy Free
Step 3

Set up your own targets

Install the tools and deliberately-vulnerable apps you will practise on, all on your own machine.

4 Offline Lab: See & Edit Real Requests (Intercepting Proxy)
Install a local intercepting proxy, route your browser through it, and watch — then modify — the real HTTP requests behind a page you control. The tool every web tester lives in.
Easy Free
5 Offline Lab: Your First Local Target (DVWA)
Download and run a deliberately-vulnerable web app on your own machine, then practise the bugs you have learned against it. No internet target involved.
Easy Free
6 Offline Lab: A Modern Target (OWASP Juice Shop)
Run OWASP Juice Shop — a modern single-page web app full of real-world bugs — on your own machine and learn to recon and poke a live application you control.
Medium Free

Finished the bootcamp?

Keep going with the full tracks — the same hands-on style, all the way to job-ready.

See all tracks