Bootcamp
The Bootcamp is the free way in. It takes you from the one rule that keeps this legal, through how the web actually works, to standing up your own practice targets and attacking them safely on your own machine. Every exercise here is free. Finish it and you are ready for the full tracks.
Chapter 1
Start safe
The one rule that separates practice from a crime: permission and scope.
| 1 | Scope & Rules of Engagement
The difference between a penetration tester and a criminal is permission. Learn what authorisation and scope mean, what a rules-of-engagement document covers, and why it comes first. |
Easy | Free |
Chapter 2
How the web really works
Read a request, understand why the browser is the attacker's side, and see where bugs come from.
Recommended first: chapter 1
| 2 | How HTTP Works
Read a real request and response, learn the method and status-code vocabulary, and see why the browser is a place attackers control. |
Easy | Free |
| 3 | Where Web Bugs Come From
One idea sits underneath almost every web vulnerability: the application trusted input it should have checked. Learn to see that pattern everywhere. |
Easy | Free |
Chapter 3
Set up your own targets
Install the tools and deliberately-vulnerable apps you will practise on, all on your own machine.
Recommended first: chapter 2
| 4 | Offline Lab: See & Edit Real Requests (Intercepting Proxy)
Install a local intercepting proxy, route your browser through it, and watch — then modify — the real HTTP requests behind a page you control. The tool every web tester lives in. |
Easy | Free |
| 5 | Offline Lab: Your First Local Target (DVWA)
Download and run a deliberately-vulnerable web app on your own machine, then practise the bugs you have learned against it. No internet target involved. |
Easy | Free |
| 6 | Offline Lab: A Modern Target (OWASP Juice Shop)
Run OWASP Juice Shop — a modern single-page web app full of real-world bugs — on your own machine and learn to recon and poke a live application you control. |
Medium | Free |