Open source network security lab

A network security lab you SSH into.

Shabakah is one self contained Docker container. You start it, you SSH in, and a bilingual guide walks you through fifteen hands on lessons against real services running beside it. Every challenge is checked live, so you learn by doing, not by reading.

15hands on lessons
6live targets
6flags to capture
110points on offer
2languages

How it works

Three commands and you are inside.

No lab to wire up, no cloud to pay for, nothing that reaches the outside world. Everything lives in the container.

01

Run the container

Pull the image or build it, then bring it up. It runs anywhere Docker runs.

docker compose up -d --build
02

SSH in

Log in as the learner. The guide greets you and remembers where you left off.

ssh -p 2222 learner@localhost
03

Learn by doing

Read a lesson, run the tools on the live targets, then let the guide check your answer.

netsec check 03 8080,8443,9000

What is inside

More than a set of notes.

Shabakah is a guide, a set of live targets, and a game, wrapped in one container so nothing gets in your way.

A guide that checks your work

The netsec program is your instructor in the terminal. It carries every lesson, shows the objective and the challenge, then verifies your answer against the running services in real time. Right answers mark the lesson complete and stick between sessions.

live verificationprogress savedno internet needed

Capture the flag

Six flags are hidden across the targets, each reachable with the tools in the box. Hunt them, submit them, watch your score climb to a hundred and ten.

Achievements

Seven badges unlock as you clear lessons and capture flags, all the way to Shabakah master.

English and Arabic

Every lesson, prompt, and hint is written in both languages. Switch any time and your progress follows.

Real tools

nmap, tcpdump, openssl, dig, netcat, hping3 and more are already installed. The same tools you use on the job.

Safe by design

Every service binds inside the container and nothing reaches the outside world. You practise the aggressive tools with no risk to anyone, which is the only honest way to learn them.

Learn the whole surface

Recon, banner grabbing, HTTP and TLS inspection, service enumeration, DNS, UDP, packet capture, firewalling, and chaining findings into access. A full first pass over network security.

A quick look

See the guide before you start.

Real screens from the guide, straight out of the terminal.

The Shabakah guide as seen after logging in

The guide greets you when you SSH in and remembers your progress.

Capture the flag

Six flags. A hundred and ten points. One container.

Each flag sits somewhere a careless operator would leave it, and each is reachable with a tool you already have. Find one, then run netsec submit flag{...}.

10 pt

Recon rookie

The web service has a page it should not. A first curl finds it.

10 pt

Source reader

The home page hides a note in its HTML source, not in the text you see.

20 pt

Left the door open

robots.txt points at paths that were never meant to be public. One holds a config backup.

20 pt

Undocumented

A service answers more commands than it admits to. Enumeration finds the one it hides.

30 pt

One leak, three doors

A cleartext console reuses a password you already saw cross the wire. Reuse is the whole lesson.

20 pt

Hidden in plain sight

The TLS certificate carries a field it never should. Read the whole subject, not just the common name.

110 pt

Clean board

Capture all five and the master badge is yours. Track it any time with netsec ctf.

Lesson twelve walks the full chain, from one small leak to real access, so the hunt doubles as a lesson in how a real assessment actually runs.

The curriculum

Fifteen lessons, each with a live challenge.

Every lesson ends with something to prove on the running targets, checked by the guide.

01The lay of the landSee what is listening and read the shape of the hostrecon
02Grab the bannersPull service banners and the HTTP headers that give a host awayhttp
03Scan the portsMap open application ports with nmap and read the resultsnmap
04Enumerate a serviceTalk to a raw TCP service and make it tell you its versionenum
05Cleartext is a findingCatch a password sent in the clear and understand why it matterscapture
06Capture the trafficUse tcpdump on the loopback and read what crosses ittcpdump
07Inspect the certificateRead a TLS certificate and its subject with openssltls
08Shape the firewallWrite nftables rules and watch them take effectfirewall
09Resolve namesQuery the lab DNS resolver and read every record typedns
10Think like a defenderTurn findings into least privilege and safer defaultsdefense
11UDP services and why they hideScan and speak to a UDP service that answers only when askedudp
12Chaining findings into accessFollow a trail from a small leak all the way to a loginchain
13Read a capture like an investigatorReconstruct an incident from a saved packet captureforensics
14Find the attack in the logsPick a brute force and its source out of an auth loglogs
15Harden the door you came in throughThe settings that make an SSH server hard to attackhardening

Practice targets

Six live services to work against.

Real services, running beside the guide, each one there so a lesson has something honest to find.

tcp 8080

Cleartext web

An HTTP service with a telling banner, hidden paths, and a page it should never expose.

tcp 8443

TLS web

The same service over TLS with a self signed certificate to inspect and reason about.

tcp 9000

Enumeration service

A raw TCP service with a chatty banner and an undocumented command to uncover.

tcp 2323

Cleartext console

A forgotten admin console that reuses a password, the kind that turns one leak into three.

udp 5353

Lab DNS resolver

An offline resolver for the shabakah.lab zone, with A, MX, and TXT records to query.

udp 9001

UDP banner service

A UDP service that stays silent until you speak its protocol, which is the point.

The toolbox

The tools are already installed.

Nothing to apt install mid lesson. The container ships with a working network security kit and the guide to drive it.

Inside the container

nmaptcpdumpngrepopenssldigwhoisnetcatsocatcurlwgethping3nftablesiptablesmtrtraceroute

Drive it with netsec

netsecopen the interactive guide
netsec lesson 05read one lesson
netsec check 05 <a>check a challenge answer
netsec ctfshow the capture the flag board
netsec submit flag{...}submit a flag you found
netsec achievementsshow your badges
netsec targetssee which targets are up
netsec lang arswitch to Arabic

Quick start

Up and running in a minute.

You need Docker. Everything else is in the image.

git clone https://github.com/SiteQ8/Shabakah.git
cd Shabakah
docker compose up -d --build
ssh -p 2222 learner@localhost
# the password is set in docker-compose.yml, default: shabakah

Prefer the prebuilt image? Pull it from the GitHub container registry.

docker run -d --name shabakah --cap-add NET_ADMIN -p 2222:22 ghcr.io/siteq8/shabakah:latest
ssh -p 2222 learner@localhost

Questions

Good to know.

Is any of this dangerous to run?

No. Every practice service binds inside the container and nothing reaches the outside world. You get to run nmap, tcpdump, and hping3 the aggressive way with no risk to anyone, which is exactly why a contained lab is the right place to learn them.

Do I need to know the command line already?

A little comfort with a terminal helps, but the guide shows you the exact commands for each lesson and the cheat sheet is one keypress away. Beginners can follow along and the challenges teach by repetition.

Does it need an internet connection?

Only to pull or build the image the first time. After that everything runs offline inside the container, including the lab DNS resolver.

Can I use it to teach a class or run a workshop?

Yes. It is MIT licensed, bilingual, and each learner just needs their own container. Progress and flags are per learner, so a room can work through it at its own pace.

Where do I report a problem or suggest a lesson?

Open an issue on the GitHub repository. Contributions of new lessons and targets are welcome.

Open a terminal and begin.

Fifteen lessons, six live targets, and a hunt for six flags are waiting inside one container.

مشروع مفتوح المصدر لأمن الشبكات

مختبر لأمن الشبكات في جهازك!

شبكة مختبرٌ متكامل لأمن الشبكات يعمل في بيئة Docker معزولة على جهازك وحده، تشغّله وتدخل إليه عبر SSH فيستقبلك مرشد بالعربية والإنجليزية ويسير بك في خمسة عشر درسا تطبيقيا على خدمات حقيقية تعمل داخله، ويصحّح لك كل تمرين لحظة تنفيذه فتتعلّم بيدك لا بعينك.

15درسا تطبيقيا
6أهداف للتدريب
6تحديات مخفية
110نقطة
2لغتان

كيف يعمل

ثلاثة أوامر وتدخل المختبر.

لا إعدادات معقّدة ولا خوادم سحابية بمقابل، فكل شيء يعمل داخل بيئة معزولة على جهازك وحده.

01

شغّل المختبر

نزّل الصورة الجاهزة أو ابنها بنفسك ثم شغّلها، فهي تعمل أينما توفّر Docker.

docker compose up -d --build
02

ادخل عبر SSH

ادخل بحساب المتعلّم فيستقبلك المرشد من حيث توقّفت آخر مرة.

ssh -p 2222 learner@localhost
03

تعلّم بالتجربة

اقرأ الدرس ثم جرّب الأدوات على أهداف التدريب، ودع المرشد يصحّح إجابتك.

netsec check 03 8080,8443,9000

ما في الداخل

أكثر من مجرد دروس تقرؤها.

يجمع المختبر بين مرشد يعلّمك، وأهداف حقيقية تتدرّب عليها، وتحديات تتنافس فيها، كلها في مكان واحد.

مرشد يصحّح إجابتك

برنامج netsec هو معلّمك داخل الطرفية، يعرض لك هدف كل درس وتمرينه ثم يتأكد من حلّك باختباره مباشرة على الخدمات العاملة، فيُحفظ تقدّمك مع كل إجابة صحيحة ويبقى معك بين الجلسات.

تصحيح فوريتقدّم محفوظبلا إنترنت

تحديات مخفية

خبّأنا في المختبر ستة رموز سرية، تكشف كل واحد منها بأدواتك ثم تسلّمه لترفع نتيجتك حتى مئة وعشر نقاط.

الإنجازات

سبع شارات تكسبها تباعا مع كل درس تُنهيه وكل رمز تكشفه، وصولا إلى لقب أستاذ شبكة.

عربية وإنجليزية

كل درس وتمرين وتلميح متوفّر بالعربية والإنجليزية، تنتقل بينهما وقتما تشاء دون أن تفقد تقدّمك.

أدوات حقيقية

تجد nmap وtcpdump وopenssl وdig وnetcat وhping3 وغيرها جاهزة للعمل، وهي الأدوات ذاتها التي يعتمدها المحترفون في الميدان.

معزول وآمن

كل الخدمات محبوسة داخل البيئة المعزولة ولا شيء يخرج منها إلى شبكتك، فتستخدم الأدوات الهجومية بحرّية ودون أن تؤذي أحدا، وهذه هي الطريقة الصحيحة الوحيدة لإتقانها.

من الاستطلاع إلى التحصين

تمرّ على الاستطلاع والتقاط اللافتات، وفحص HTTP وTLS، وتعداد الخدمات، وDNS وUDP، والتقاط الحزم، وضبط الجدار الناري، وربط الثغرات للوصول، فتخرج بجولة أولى شاملة في أمن الشبكات.

معاينة سريعة

شاهد المرشد قبل أن تبدأ.

قبل أن تبدأ، شاهد لقطات حقيقية من المرشد كما ستظهر في طرفيتك تماما.

مرشد شبكة كما يظهر بعد تسجيل الدخول

يستقبلك المرشد فور دخولك ويتذكّر أين وصلت.

تحديات المختبر

ابحث عن ستة رموز سرية واجمع مئة وعشر نقاط.

التقاط الأعلام أسلوب تدريب معروف في الأمن السيبراني، خبّأنا فيه ستة رموز سرية داخل المختبر، ترك كلَّ واحد منها مشرف مهمل في مكان ما كان ينبغي أن يظهر فيه، فمهمتك أن تكشفه بالأدوات التي بين يديك ثم تسلّمه بالأمر netsec submit flag{...} لتكسب نقاطه.

10 نقاط

مستكشف مبتدئ

خدمة الويب تُخفي صفحة ما كان ينبغي أن تظهر، يكشفها أول طلب بـ curl.

10 نقاط

قارئ المصدر

الصفحة الرئيسة تُخفي ملاحظة في مصدر HTML لا في النص الذي أمامك.

20 نقطة

باب مفتوح

يدلّك ملف robots.txt على مسارات ما كان يُفترض أن تُنشر، وفي أحدها نسخة احتياطية من ملف الإعداد.

20 نقطة

غير موثّق

إحدى الخدمات تنفّذ أوامر أكثر مما تُعلن عنه، والتعداد الجيّد يكشف الأمر الخفيّ.

30 نقطة

تسريب واحد وثلاثة أبواب

وحدة تحكّم تعمل بنص صريح تستخدم كلمة مرور سبق أن رأيتها تمرّ على الشبكة، وإعادة استخدام كلمة المرور هي الدرس كله.

20 نقطة

مخبأ على مرأى

شهادة TLS تحمل حقلا زائدا ما كان ينبغي وجوده، فاقرأ حقل الموضوع كاملا لا الاسم الشائع وحده.

110 نقطة

لوحة نظيفة

اجمع الرموز الستة كلها لتنال شارة الأستاذ، وتابع تقدّمك في أي وقت بالأمر netsec ctf.

يأخذك الدرس الثاني عشر في هذه السلسلة خطوة بخطوة، من تسريب بسيط إلى اختراق فعلي، فيتحوّل البحث عن الرموز إلى تدريب حقيقي على أسلوب التقييم الأمني.

المنهج

خمسة عشر درسا، ولكل درس تمرين يُختبر مباشرة.

ينتهي كل درس بتطبيق عملي على الأهداف يتحقق منه المرشد بنفسه.

01تعرّف على المضيفاكتشف الخدمات التي تستمع، واقرأ ملامح المضيف من بعيداستطلاع
02التقط اللافتاتاستخرج لافتات الخدمات وترويسات HTTP التي تفضح المضيفhttp
03افحص المنافذامسح المنافذ المفتوحة بأداة nmap واقرأ نتائجهاnmap
04عدّد الخدمةخاطب خدمة TCP مباشرة واجعلها تفصح عن إصدارهاتعداد
05النص الصريح ثغرةالتقط كلمة مرور مرسلة بنص صريح، وافهم لماذا يُعدّ ذلك ثغرةالتقاط
06راقب الحركةراقب حركة الشبكة بـ tcpdump على واجهة الاسترجاع، واقرأ ما يمرّ عبرهاtcpdump
07افحص الشهادةافحص شهادة TLS وحقل الموضوع فيها بأداة openssltls
08اضبط الجدار النارياكتب قواعد بـ nftables وراقب أثرها مباشرةجدار
09حلّل الأسماءاستعلم خادم DNS في المختبر واقرأ مختلف أنواع سجلاتهdns
10فكّر كمدافعوظّف ما اكتشفته لبناء دفاع بمبدأ أقل امتياز وإعدادات أكثر أمانادفاع
11خدمات UDP ولماذا تختبئامسح خدمة UDP لا تردّ إلا إذا خاطبتها، وتعلّم كيف تكشفهاudp
12اربط النتائج للوصولتتبّع الخيط من تسريب صغير حتى تسجيل دخول كاملسلسلة
13حلّل الالتقاط كمحقّقأعد بناء ما جرى من ملف التقاط محفوظتحقيق
14اعثر على الهجوم في السجلاتاكشف هجوم تخمين كلمات المرور ومصدره من سجل المصادقةسجلات
15حصّن الباب الذي دخلت منهطبّق إعدادات تجعل اختراق خادم SSH أصعبتحصين

أهداف التدريب

ست خدمات حقيقية تتدرّب عليها.

خدمات حقيقية تعمل إلى جانب المرشد، وضعنا كل واحدة منها ليجد فيها الدرس شيئا حقيقيا يكتشفه.

tcp 8080

ويب بنص صريح

خدمة HTTP بلافتة تفضح نفسها، ومسارات مخفية، وصفحة ما كان ينبغي أن تظهر أبدا.

tcp 8443

ويب عبر TLS

الخدمة نفسها لكن عبر TLS، بشهادة موقّعة ذاتيا تفحصها وتحلّل محتواها.

tcp 9000

خدمة تعداد

خدمة TCP بسيطة بلافتة ثرثارة، وفيها أمر غير موثّق عليك أن تكتشفه.

tcp 2323

وحدة تحكم بنص صريح

وحدة تحكّم إدارية منسيّة تُعيد استخدام كلمة مرور، من النوع الذي يحوّل تسريبا واحدا إلى ثلاثة أبواب مفتوحة.

udp 5353

خادم DNS للمختبر

خادم أسماء محلّي لنطاق shabakah.lab، فيه سجلات A وMX وTXT تستعلم عنها.

udp 9001

خدمة لافتة UDP

خدمة UDP تلزم الصمت حتى تخاطبها باللغة التي تفهمها، وذلك هو التحدي.

صندوق الأدوات

الأدوات جاهزة من البداية.

لن تحتاج إلى تثبيت أي شيء أثناء الدرس، فالمختبر يأتي بعُدّة أمن شبكات كاملة ومعها المرشد الذي يوجّهك في استخدامها.

داخل المختبر

nmaptcpdumpngrepopenssldigwhoisnetcatsocatcurlwgethping3nftablesiptablesmtrtraceroute

تحكّم بها عبر netsec

netsecافتح المرشد التفاعلي
netsec lesson 05اقرأ درسا محدّدا
netsec check 05 <a>تحقّق من حلّ تمرين
netsec ctfاعرض لوحة التحديات
netsec submit flag{...}سلّم رمزا كشفته
netsec achievementsاعرض شاراتك
netsec targetsاعرض حالة الأهداف
netsec lang enبدّل إلى الإنجليزية

بداية سريعة

جاهز في دقيقة.

كل ما تحتاجه هو Docker، والباقي موجود داخل الصورة.

git clone https://github.com/SiteQ8/Shabakah.git
cd Shabakah
docker compose up -d --build
ssh -p 2222 learner@localhost
# كلمة المرور محدّدة في docker-compose.yml وقيمتها الافتراضية shabakah

تفضّل صورة جاهزة؟ نزّلها من سجل الصور على GitHub.

docker run -d --name shabakah --cap-add NET_ADMIN -p 2222:22 ghcr.io/siteq8/shabakah:latest
ssh -p 2222 learner@localhost

أسئلة شائعة

أمور يحسن أن تعرفها.

هل تشغيله خطر على جهازي؟

لا، فكل شيء محبوس داخل البيئة المعزولة ولا شيء يخرج إلى شبكتك، فتشغّل nmap وtcpdump وhping3 بأقوى صورها دون أن تُلحق ضررا بأحد، ولهذا فالمختبر المعزول هو المكان الصحيح لتعلّم هذه الأدوات.

هل أحتاج إلى خبرة بسطر الأوامر مسبقا؟

تكفي معرفة بسيطة بالطرفية، فالمرشد يعرض لك الأوامر الدقيقة في كل درس، وورقة الأوامر السريعة على بُعد ضغطة، حتى يستطيع المبتدئ أن يتابع، والتكرار كفيل بترسيخ المهارة.

هل يحتاج إلى اتصال بالإنترنت؟

يحتاجه مرة واحدة فقط لتنزيل الصورة أو بنائها، ثم يعمل كل شيء بعد ذلك دون إنترنت، حتى خادم الأسماء الخاص بالمختبر.

هل يصلح لتدريس صف أو تنظيم ورشة؟

نعم، فهو مفتوح المصدر برخصة MIT وبلغتين، ويكفي كل متعلّم أن يشغّل نسخته الخاصة، فتقدّم كل واحد ونقاطه مستقلّة عن غيره، ويسير كلٌّ بالإيقاع الذي يناسبه.

أين أُبلّغ عن مشكلة أو أقترح درسا جديدا؟

افتح مسألة (Issue) في مستودع المشروع على GitHub، ونرحّب بكل مساهمة بدروس أو أهداف جديدة.

افتح الطرفية وابدأ الآن.

خمسة عشر درسا، وست خدمات للتدريب، وستة تحديات تخوضها، كلها بانتظارك في مختبر واحد.