Hands-on Hacking Lab
Ninja Cyber Range
Learn to hack — and to defend — by doing it. 21 guided labs of deliberately vulnerable targets you attack from your own machine. Safe, isolated, beginner-proof. Lifetime access.
Get the Kit — ₹1,999 · Lifetime →One command to start · runs offline · no subscription
Three commands to your first hack
- Install Docker (Windows / Mac / Linux).
- Start the lab and step onto the attack box:
docker compose up -d --build docker compose exec attackbox sh
- Attack the targets and follow the guide:
curl -sI http://target/ # the vulnerable web app nmap -sV ssh # the SSH host
What's in the kit
Everything you need to run the whole range locally.
21 guided labs
Attack and defend, each a step-by-step walkthrough written for beginners — what to run, why, what output to expect, and how to fix it when it breaks.
Your own attack box
A Debian box with curl, nmap, netcat, sqlmap, ssh — pre-wired to the targets. `docker compose exec attackbox sh` and you're in.
Runs on your machine
One command: `docker compose up -d --build`. No cloud, no account, works offline. Nothing to keep paying for.
Bonus: Windows AD range
A full Windows Active Directory lab (Domain Controller + workstation) for AS-REP roasting, Kerberoasting, ACL abuse and DCSync — via VirtualBox + Vagrant.
Beginner-proof docs
START-HERE, INSTALL, USAGE, SAFETY and UPGRADES guides in the kit. If you can install one program, you can run this.
Lifetime access + upgrades
Buy once. New scenarios and improvements are added over time — re-download the latest kit anytime, free, for life.
21 guided scenarios
Mapped to CEH & OSCP topics — from first recon to full compromise, plus blue-team hunting.
Recon & Assessment
- Footprinting & Reconnaissance
- Scanning Networks
- Enumeration
- Vulnerability Analysis — scan, confirm, prioritise
Web Attacks
- SQL Injection to Shell
- Command Injection to Exfil
- Local File Inclusion / Path Traversal
- Server-Side Template Injection
- Reflected Cross-Site Scripting
- Open Redirect
- XML External Entity (XXE)
API Attacks
- IDOR / Broken Object-Level Auth
- JWT Auth Bypass (alg=none)
- NoSQL Injection
Advanced
- Log4Shell (CVE-2021-44228)
- SSRF to Cloud Metadata Credential Theft
- Network Pivot / Lateral Movement
- Denial-of-Service basics
Blue Team — Defend
- Hunt the Attack in Traffic
- Hunt the CVE Probes
- Hunt the SSRF Probes
Safe by design
- Nothing is exposed. The lab publishes no network ports — the vulnerable targets are only reachable from the attack box inside a private, isolated sandbox on your machine.
- Disposable. Everything runs in containers. `docker compose down` removes it all — nothing touches your operating system.
- Authorized-use only. The kit is for learning and security practice you're authorized to perform. Full safety & legal notes are included.
Start hacking today
One-time ₹1,999. Lifetime access, every future scenario included. Delivered to your email the moment you buy.
Get the Kit — ₹1,999 · Lifetime →