Offensive security range

Learn to break in.
So you can keep them out.

SiberangeX is a hands-on range of real vulnerable machines, OWASP-mapped attack labs, and CTF challenges. Read less. Exploit more — on targets you’re allowed to break. Made in Malaysia.

Free labs, no card OWASP Top 10 mapped 69 modules · 12 domains
siberangex — machine // Broken Access Control
Objective

Enumerate the target, find a foothold, and capture the flag. Submit it in the panel to earn XP and climb the ladder.

Easy 10 XP OWASP #1
operator@range:~$ nmap -sV 203.0.113.37
80/tcp open http nginx 1.24
22/tcp open ssh OpenSSH 8.9
operator@range:~$ gobuster dir -u http://203.0.113.37
/login (200) /admin (403)
operator@range:~$ cat flag.txt
FLAG{br0ken_4ccess}
operator@range:~$
Environmentrunning
Uptime00:07:41
Target203.0.113.37
Statusunsolved

Copy the flag above and submit it.

Live · runs in your browser

Don’t watch a terminal.
Type into one.

Boot a live box and poke around — a real filesystem, the Linux tools you know, pipes & redirection, a working nano editor. No install, no VPN, nothing to download.

You can’t defend
what you’ve never broken.

Slides and video courses teach you the words. They don’t teach you the moment a misconfigured permission becomes root. That only comes from doing it — safely, repeatedly, on a target built to be broken.

attack surfacechanges every deploy
The range

A place to practise the attack, not just read about it.

Spin up a real vulnerable machine, get a target IP, and work it end to end — recon, foothold, escalation, capture. Every box is intentionally broken and fully yours to take apart.

  • → Isolated, disposable environments — reset any time.
  • → A live objective, briefing, and flag check on every target.
  • → Hints and full walkthroughs when you’re genuinely stuck.
dashboard — operator
Continue learning

Broken Access Control — 8 hands-on tasks on real authorization flaws.

Web Security track Free lab
# your progress
machines ······· 3 / 8 rooted
challenges ····· 5 / 12 solved
rank ·········· Web Novice → Apprentice
The operator loop

Four moves. Every target.

01

Recon

Map the target. Ports, services, versions — find where it’s soft.

02

Exploit

Turn a weakness into access. Get your first foothold on the box.

03

Capture

Escalate, reach the flag, and submit it to prove you rooted it.

04

Rank

Earn XP, climb the ladder, and unlock harder machines and tracks.

One machine, start to root

One flag. Five moves.

This is a single box on the range — from an open port to root, the way an operator actually works. Scroll through it.

session — 203.0.113.37
Recon+0 XP
Move 01

Find the doors

A service scan shows what’s listening. Two ports open — the web server is the obvious way in.

Move 02

Read the map

Directory enumeration turns up a login page and an /admin route that answers with a telling 403.

Move 03

Walk through

A broken access-control check lets a normal request reach the admin view. That’s the foothold.

Move 04

Become root

A misconfigured sudo rule is a known path straight to root. No exploit kit — just the operator’s eye for a mistake.

Move 05

Capture the flag

Read the flag, submit it, solve the box. XP lands and the next machine unlocks.

What’s on the range

Three ways to get your hands dirty.

01 / Attack Labs

The OWASP Top 10, as things you break.

Ten categories of real-world web flaws — from broken access control to injection — each a set of guided, hands-on exploitation tasks ranked by category.

attack labs — OWASP Top 10
#1Broken Access Control8 labs
#3Injection10 labs
#7Auth Failures6 labs
02 / Machines & Boxes

Full vulnerable environments over a lab VPN.

Quick single-flag machines to warm up, or complete boxes you connect to over VPN — enumerate, exploit, and compromise the whole target. Linux and Windows, Easy to Insane.

boxes — lab VPN
Driftwood · LinuxEasy
Ironclad · WindowsHard
Relay · WindowsInsane
$ openvpn siberangex.ovpn
✓ tunnel up · 10.13.37.4 → target reachable
03 / Challenges

CTF flags across every category.

Web, Crypto, Forensics, OSINT and more — bite-sized puzzles that sharpen a single skill. Pick a category, find the flag, bank the points.

challenges — by category
Web

Crawler Rules
Easy · 75 pts

Crypto

Base64 Warmup
Easy · 50 pts

Forensics

Magic Bytes
Medium · 100 pts

OSINT

Who Owns It
Easy · 75 pts

The learning library

Start at zero.
Leave dangerous.

69 modules
12 domains
one clear path

01Fundamentals start here7 modules
02Reconnaissance5 modules
03Network & Recon9 modules
04Web Application23 modules
05Password Attacks5 modules
06Post-Exploitation5 modules
··Active Directory, Wireless, Cloud, Forensics & more+6 domains

Reading about a vulnerability
isn’t the same as exploiting one.

A video course

You watch someone else do it. You finish the module. Faced with a real target and a blank terminal, you don’t know the first command to type.

SiberangeX

You get the target. You type the commands. You fail, adjust, and land the flag yourself — and that muscle memory is what actually transfers to the job.

Who it’s for

Built for operators, students, and the educators who train them.

Lv 1 Web Novice → Lv 11 Apprentice Analyst → Lv 20+ Operator
For educators

Running a classroom or a bootcamp? The Education Program brings the range into your curriculum — pre-configured environments, guided tracks, and progress you can actually see.

Your first flag
is one login away.

Create a free account, spin up a machine, and root your first box tonight. No card, no setup — just a target and a terminal.

Free labs included · Practise only on the machines we give you