The point
Most students bounce off cybersecurity because setup eats the weekend. Cyfotok labs run in the browser against isolated targets. You get a task, a vulnerable app, and a flag when you prove the bug.
What a session looks like
- Open a lab. Read the goal in plain language.
- Use the target in your browser — forms, uploads, diagnostic tools.
- Submit the flag. Points and writeup-ready notes stay on your profile.
Writeups welcome
Publish what you learned on the Cyfotok blog once you can explain the bug without leaking a live customer payload.
What we will not do
We will not ship you a full attacker distro on day one. Fundamentals paths cover HTTP, cookies, and DNS first. Then the offensive labs make sense.