[ OPEN SECURITY PLAYGROUND ] EST. 2024

BREAK IT.UNDERSTAND IT.SECURE IT.

Explore a system through its weakest point.
Experiment with vulnerabilities, read the code and learn to build more secure applications.

5 labs / real code / hands-on learning

FIG_01 / ATTACK SURFACE
vault / data flow DEMO

❯ inspect --attack-surface

Inspecting the data flow

01 user_inputRECEIVED
02 raw_query⚠ VULNERABLE
03 parameterize✓ PROTECTED

❯ understand. then secure.

TRUST NOTHING. VERIFY EVERYTHING.
LEARN / EXPLOIT / DEFENDSCROLL TO EXPLORE VV — 2026 EDITION

01 / THE LABS

Find the weak point.

Five ways to break an application.
Five opportunities to understand its defenses.

02 / THE MINDSET

Don’t guess.
Understand.

Basic programming knowledge and curiosity are enough to start. Each lab takes you from an attack mechanism to a concrete defense.

  1. 01

    Read the system

    Explore the code and find where data crosses a trust boundary.

  2. 02

    Test your hypothesis

    Try a payload in the form and observe the actual result.

  3. 03

    Close the gap

    Compare the variants and see why the protected code changes the result.

03 / YOUR ENVIRONMENT

Your local
testing ground.

The full lab runs on localhost. Download the project, start the containers and open your first exercise.

Source code on GitHub

QUICK START / DOCKER

docker compose up --build -d

Open localhost:8080/vulnerability-vault/

Test accounts and requirements

Install Docker with Docker Compose. On Windows, enable Docker Desktop integration with WSL.

Accounts: admin/admin, test/test, user/user.
phpMyAdmin: localhost:8081. Data and uploads survive restarts.