Specifications
| Format | Virtual machines, Learning |
|---|---|
| Level | Intermediate, Advanced |
| Price | Free |
| Access | No registration |
| Activity | Active |
| Language | EN |
| Category | Pwn, Reverse, Systems |
Four binaries under Phoenix take you through the classic memory bug classes one protection at a time; Nebula and Fusion are shorter linear paths. Open, with no account. The site data carries 57 challenges, a hand tally rather than a published count.
Pros & cons
Pros
- Protections arrive one at a time, each in its own binary
- Stack, format string, heap and network levels, not one bug class
- No account and no subscription: machines and theory in the open
Cons
- Exploitation only. Nothing here teaches detection, hardening or the web
- The guests are old, so some tooling has to be installed by hand
- Building a pwn bench from scratch is a weekend job the first time
Who it fits
Fits someone who already reads x86 assembly and wants the stack, heap and format-string chapters closed in a fixed order instead of pieced together from scattered writeups.
Getting started
- Take Phoenix and finish the four binaries in order rather than hopping between them
- Read the paragraph on the vulnerability before each level, the task checks that exact bug
- Set up one shared bench with gdb, pwntools and a distro you already know
History
Phoenix, Nebula and Fusion have been up for years and the machine set has not changed, which is the point: the classic vulnerability classes in a fixed sequence. Free and open, updates rare, everything still working when checked. The 57-entry figure is an approximate tally counted by hand across the three tracks, so treat it as a floor rather than a total.