One Lab.
Two Missions.
KBCrk Security Lab is a deliberately vulnerable environment built for two real purposes - testing your team's security capability and running Capture The Flag competitions. 50+ vulnerabilities. Two attack layers. One root flag.
Vulnerabilities
50+
Mapped to OWASP Top 10 & API Top 10
Hidden Flags
5
Escalate to root
Attack Layers
2
Web + OS level
Designed for two audiences
The same lab. Two very different goals.
Measure Your Team's Security Capability
Give your security team or new hires access to the lab and measure how many vulnerabilities they can identify, exploit, and document. Use it as a structured benchmark for skill evaluation, onboarding tests, or internal red team exercises.
- Structured scoring by vulnerability severity
- Realistic attack surface — no artificial hints
- Full OWASP + API Top 10 coverage
A Complete CTF Environment
Run it as a fully-featured Capture The Flag event. Participants must chain web exploits into OS access, decrypt credentials, extract hidden files, and escalate privileges through 5 stages to capture the final root flag.
- 5 progressive flags across user accounts
- Multi-discipline: web, crypto, stego, privesc
- Offline - deploy locally via VMware image
Lab Architecture
Two distinct attack layers.
Built on PHP 8.x + MySQL 8.x sitting on top of a hardened Linux OS. No shortcuts, no guided hints - just a realistic environment and your skills.
Web Application Layer
A deliberately vulnerable E-Commerce platform with 47 vulnerabilities spread across authentication, authorization, input handling, and API security. Every major OWASP Top 10 and API Top 10 category is represented.
OS-Level Layer
Getting a web shell is just the beginning. A hardened Linux environment lies beneath — with 5 hidden flags distributed across different user accounts. What you find, and how you move, is entirely up to you.
Quick Start
How to set up the lab
Getting the lab running on your local machine takes less than two minutes. Follow these simple steps once you receive your download link.
Download & Extract
Download the ZIP file from your email link. Extract it to a folder on your computer.
Locate the OVF
Open the extracted folder. You will see three files. Look for the file named KBCrk.ovf.
Open File
Double-click to open in Oracle VirtualBox. For VMware, right-click it and select Open with -> VMware Workstation.
Import & Run
A popup will appear. Enter a name, choose an install location, and click Import. Once finished, power it on!
Get in Touch
Access & Support
Need access to the lab, or having trouble with an existing instance? Use the form to reach out. Due to the offensive nature of the environment, all access requests are manually reviewed.
- Request lab environment access
- Report a bug or technical issue
- Get general help and support
Received Successfully
Thank you for reaching out! We've received your submission and will get back to you shortly.