← Ninja SecurityBuy the Kit

Hands-on Hacking Lab

Ninja Cyber Range

Learn to hack — and to defend — by doing it. 21 guided labs of deliberately vulnerable targets you attack from your own machine. Safe, isolated, beginner-proof. Lifetime access.

Get the Kit — ₹1,999 · Lifetime →

One command to start · runs offline · no subscription

Three commands to your first hack

  1. Install Docker (Windows / Mac / Linux).
  2. Start the lab and step onto the attack box:
    docker compose up -d --build
    docker compose exec attackbox sh
  3. Attack the targets and follow the guide:
    curl -sI http://target/      # the vulnerable web app
    nmap -sV ssh                 # the SSH host

What's in the kit

Everything you need to run the whole range locally.

21 guided labs

Attack and defend, each a step-by-step walkthrough written for beginners — what to run, why, what output to expect, and how to fix it when it breaks.

Your own attack box

A Debian box with curl, nmap, netcat, sqlmap, ssh — pre-wired to the targets. `docker compose exec attackbox sh` and you're in.

Runs on your machine

One command: `docker compose up -d --build`. No cloud, no account, works offline. Nothing to keep paying for.

Bonus: Windows AD range

A full Windows Active Directory lab (Domain Controller + workstation) for AS-REP roasting, Kerberoasting, ACL abuse and DCSync — via VirtualBox + Vagrant.

Beginner-proof docs

START-HERE, INSTALL, USAGE, SAFETY and UPGRADES guides in the kit. If you can install one program, you can run this.

Lifetime access + upgrades

Buy once. New scenarios and improvements are added over time — re-download the latest kit anytime, free, for life.

21 guided scenarios

Mapped to CEH & OSCP topics — from first recon to full compromise, plus blue-team hunting.

Recon & Assessment

  • Footprinting & Reconnaissance
  • Scanning Networks
  • Enumeration
  • Vulnerability Analysis — scan, confirm, prioritise

Web Attacks

  • SQL Injection to Shell
  • Command Injection to Exfil
  • Local File Inclusion / Path Traversal
  • Server-Side Template Injection
  • Reflected Cross-Site Scripting
  • Open Redirect
  • XML External Entity (XXE)

API Attacks

  • IDOR / Broken Object-Level Auth
  • JWT Auth Bypass (alg=none)
  • NoSQL Injection

Advanced

  • Log4Shell (CVE-2021-44228)
  • SSRF to Cloud Metadata Credential Theft
  • Network Pivot / Lateral Movement
  • Denial-of-Service basics

Blue Team — Defend

  • Hunt the Attack in Traffic
  • Hunt the CVE Probes
  • Hunt the SSRF Probes

Safe by design

  • Nothing is exposed. The lab publishes no network ports — the vulnerable targets are only reachable from the attack box inside a private, isolated sandbox on your machine.
  • Disposable. Everything runs in containers. `docker compose down` removes it all — nothing touches your operating system.
  • Authorized-use only. The kit is for learning and security practice you're authorized to perform. Full safety & legal notes are included.

Start hacking today

One-time ₹1,999. Lifetime access, every future scenario included. Delivered to your email the moment you buy.

Get the Kit — ₹1,999 · Lifetime →