KBCrkLab
Employee VAPT Assessment CTF Competition

One Lab.
Two Missions.

KBCrk Security Lab is a deliberately vulnerable environment built for two real purposes - testing your team's security capability and running Capture The Flag competitions. 50+ vulnerabilities. Two attack layers. One root flag.

Vulnerabilities

50+

Mapped to OWASP Top 10 & API Top 10

Hidden Flags

5

Escalate to root

Attack Layers

2

Web + OS level

Designed for two audiences

The same lab. Two very different goals.

01 / Employee Assessment

Measure Your Team's Security Capability

Give your security team or new hires access to the lab and measure how many vulnerabilities they can identify, exploit, and document. Use it as a structured benchmark for skill evaluation, onboarding tests, or internal red team exercises.

  • Structured scoring by vulnerability severity
  • Realistic attack surface — no artificial hints
  • Full OWASP + API Top 10 coverage
02 / CTF Competition

A Complete CTF Environment

Run it as a fully-featured Capture The Flag event. Participants must chain web exploits into OS access, decrypt credentials, extract hidden files, and escalate privileges through 5 stages to capture the final root flag.

  • 5 progressive flags across user accounts
  • Multi-discipline: web, crypto, stego, privesc
  • Offline - deploy locally via VMware image

Lab Architecture

Two distinct attack layers.

Built on PHP 8.x + MySQL 8.x sitting on top of a hardened Linux OS. No shortcuts, no guided hints - just a realistic environment and your skills.

01

Web Application Layer

A deliberately vulnerable E-Commerce platform with 47 vulnerabilities spread across authentication, authorization, input handling, and API security. Every major OWASP Top 10 and API Top 10 category is represented.

SQLiJWT BypassSSRFIDORPath TraversalXSSCSRFRCEMass Assignment
02

OS-Level Layer

Getting a web shell is just the beginning. A hardened Linux environment lies beneath — with 5 hidden flags distributed across different user accounts. What you find, and how you move, is entirely up to you.

5 Hidden FlagsMulti-User EnvironmentLinux OSThink Outside the Box

Quick Start

How to set up the lab

Getting the lab running on your local machine takes less than two minutes. Follow these simple steps once you receive your download link.

1

Download & Extract

Download the ZIP file from your email link. Extract it to a folder on your computer.

2

Locate the OVF

Open the extracted folder. You will see three files. Look for the file named KBCrk.ovf.

3

Open File

Double-click to open in Oracle VirtualBox. For VMware, right-click it and select Open with -> VMware Workstation.

4

Import & Run

A popup will appear. Enter a name, choose an install location, and click Import. Once finished, power it on!

Get in Touch

Access & Support

Need access to the lab, or having trouble with an existing instance? Use the form to reach out. Due to the offensive nature of the environment, all access requests are manually reviewed.

  • Request lab environment access
  • Report a bug or technical issue
  • Get general help and support

Please select an inquiry type.

Name must be 2–60 letters.

Enter a valid email address.

Must be a valid linkedin.com profile URL.

Please write at least 30 characters.

0 / 500