Exploit Education

Visit platform ↗

FreeIntermediateAdvancedActive

Specifications

Specifications
FormatVirtual machines, Learning
LevelIntermediate, Advanced
PriceFree
AccessNo registration
ActivityActive
LanguageEN
CategoryPwn, Reverse, Systems

Four binaries under Phoenix take you through the classic memory bug classes one protection at a time; Nebula and Fusion are shorter linear paths. Open, with no account. The site data carries 57 challenges, a hand tally rather than a published count.

Pros & cons

Pros

  • Protections arrive one at a time, each in its own binary
  • Stack, format string, heap and network levels, not one bug class
  • No account and no subscription: machines and theory in the open

Cons

  • Exploitation only. Nothing here teaches detection, hardening or the web
  • The guests are old, so some tooling has to be installed by hand
  • Building a pwn bench from scratch is a weekend job the first time

Who it fits

Fits someone who already reads x86 assembly and wants the stack, heap and format-string chapters closed in a fixed order instead of pieced together from scattered writeups.

Getting started

  1. Take Phoenix and finish the four binaries in order rather than hopping between them
  2. Read the paragraph on the vulnerability before each level, the task checks that exact bug
  3. Set up one shared bench with gdb, pwntools and a distro you already know

History

Phoenix, Nebula and Fusion have been up for years and the machine set has not changed, which is the point: the classic vulnerability classes in a fixed sequence. Free and open, updates rare, everything still working when checked. The 57-entry figure is an approximate tally counted by hand across the three tracks, so treat it as a floor rather than a total.