Practice what you’ve learned.
Reading only gets you so far. Here you can break things on purpose, in labs and challenges built for exactly that.
Only practice these techniques on systems you own or have written permission to test.
Beginner challenges
Short puzzles you can do right in your browser. No setup needed. Try without hints first.
Decode the shifted message
Someone sent this message using a Caesar cipher, the same kind from the Learn page. The shift is a number between 1 and 25.
Cryptography
Easy
Wkh iodj lv fdhvdu42
Try the most common shift first. If “Wkh” is meant to be a short,common English word, what shift make that true?
Shift 3 backward. The message reads: “The flag is caesar42
Spot the fake login page
You get a link claiming to be your bank’s login page:
Phishing
Easy
secure-natlonalbank.com/login
Something is off about it.
Read the domain name letter by letter instead of skimming it.
The “i” in “national” was replaced with a lowercase “l”. It’s a lookalike domain, not the real bank.
Find the flag in the page source
A flag is hidden in this page’s HTML, not in anything you can see on screen. Right-click anywhere and choose “View Page Source” or press Ctrl/Cmd+U.
Web
Easy
Developers sometimes leave notes for themselves using HTML comments, which look like <!– like this –> and never show up on the page..
Search the source for “flag”. On a real challenge page, you’d place a comment such as <!– flag: hidden_in_plain_sight –> for visitors to find.
Read the email header
An email claims to be from support@yourbank.com, but the header shows:
Return-Path: bounce@mailer-promo3.ru
What does that tell you?
Forensics
Easy
The “From” name a person sees can be set to anything. The Return-Path is harder to fake convincingly.
The mismatch between the friendly “From” name and the actual sending domain is a strong sign of a spoofed email.
Crack the 4-digit code
A door lock uses a 4-digit numeric code. How many possible codes are there, and roughly how long would it take a script trying 10 codes per second to try them all?
Cryptography
Easy
Each of the 4 digits can be 0 through 9, and they’re chosen independently.
10,000 possible codes. At 10 per second, that’s about 17 minutes to try them all, which is why short numeric-only codes are weak on their own.
Guided labs
Longer, hands-on exercises. These need a virtual machine, which the first lab walks you through setting up.
01.
Set up your own home lab
Install a free virtual machine so you have a safe space to practice in, separate from your real computer.
02.
Scan your own network with Nmap
Find out what devices and open ports exist on a network you own, using the tool professionals use for the same job.
03.
Capture your first packets in Wireshark
Watch real network traffic go by and pick out what it means.
04.
Set up a basic firewall rule
Block a port on your own lab machine and confirm the block actually works.
Where to go for more
Once the challenges above feel easy, these established free platforms have far more to work through.
TryHackMe: Guided, beginner-friendly roomsOverTheWire: Classic command-line war gamesPicoCTF: A long-running beginner CTF competitionHack The Box: Harder, less hand-holding
How hints work
Every challenge has up to two reveals. Try it without them first. Open the hint if you’re stuck for more than ten minutes, and only check the answer once you’ve genuinely tried.
Ready to build something?
Practicing individual skills is good. Putting several together into something real is better. Head to Projects for ideas and write-ups.
