P3N73S7 L4B :: NIGHTFALL ::
Not just a lab - a conspiracy you'll uncover one hack at a time. Eight episodes teach real exploits while a story emerges: encrypted messages, evidence files, a missing whistleblower.
You'll learn: FTP backdoors, SSH brute forcing, WAR uploads, command injection, SQL injection, SMB exploits, and more.
Every command moves you closer to the truth.
Exploit the infamous vsftpd 2.3.4 backdoor to gain initial access.
Brute force SSH credentials using Hydra and rockyou wordlist.
Upload a malicious WAR file to Tomcat Manager for code execution.
Exploit SambaCry (CVE-2017-7494) to upload and execute a shared library.
Exploit DistCC daemon for remote code execution.
Command injection through web forms to achieve reverse shell.
SQL injection to bypass authentication and extract sensitive data.
Modern SQL injection against OWASP Juice Shop e-commerce platform.
Full story payoff and comprehensive skills review.