Start your first Docker container from scratch.
In this article, we have tried to practically demonstrate all the steps from pulling an image with the docker run command to starting a container.
Hands-on training in offensive and defensive security: in-depth articles, ethical hacking labs, daily challenges and a broad test bank. Free, in four languages.
A new hands-on cybersecurity and coding challenge every day — solve it, get scored, and climb the leaderboard.
Create a simple network packet sniffer using Python's `socket` library. The program should listen for incoming packets on a specified interface and print out the source and destination IP addresses along with t…
Create a free account or sign in to solve the challenge and earn points.
MetaExploit covers both sides of cybersecurity — ethical hacking and blue-team defense — in one place: practical, honest, hands-on learning from the terminal up.
Exploitation, post-exploitation, penetration testing and attack simulation.
Detection engineering, DFIR, monitoring and hardening.
Step-by-step labs, quizzes and self-assessment.
Make cybersecurity accessible, honest and practical. No dry theory, no cheap hype — real skill.
Good defence starts with understanding offence. Offence and defence are two sides of one coin; we teach both.
Three fresh, hand-picked cybersecurity articles every day — check back tomorrow.
In this article, we have tried to practically demonstrate all the steps from pulling an image with the docker run command to starting a container.
In our next article, we clarify which real protocols correspond to the two reference models by comparing them layer by layer.
This time we are comparing methods that leave traces using information gathered without direct contact with the target.
You get today's picks for free. Sign up to unlock every article, lab and the full archive — it takes seconds.
Four routes through the same library. Follow one in order instead of guessing where to begin.
New to security? Build the ground floor first — you cannot attack or defend what you cannot read.
How attacks actually work: find the surface, break the logic, understand the impact.
Detect, harden and respond — the side that has to be right every single time.
Take things apart: binaries, malware behaviour and the maths that protects data.
Web security, cryptography, malware analysis, OSINT, networking and more.
The newest tutorials, write-ups and guides in the journal.
In this article, we clarify the meanings of the root symbol, dot, colon, and tilde characters, as well as the logic of path construction.
We describe the rules for compliance with legislation, privacy, and professional ethics while collecting information.
In this article, we clarify the frame structure of the second layer and MAC-based addressing step by step.
We demonstrate creating, sending, and sniffing raw TCP/IP packets with Scapy using practical examples.
We explain the fundamental philosophy of modern cryptography in a historical context.
We describe the stages of a typical attack with an analytical perspective.
A free 25-question cybersecurity quiz — 5 easy, 8 medium, 12 hard. Answer and see your result instantly.
Your result is for you only — shown instantly with explanations.
What you can expect from every article, lab and challenge published here.
Written for lab environments and systems you are authorised to test. No target lists, no ready-made attacks on real services.
Commands, code and payloads you can actually run, with the reasoning behind each step rather than a copy-paste recipe.
Everything is published in Azerbaijani, English, Russian and Turkish — the translated version is not a shortened one.
Tooling moves fast. Material is revised when versions, flags or defaults change, and challenges are dated so you know how fresh they are.
Spotted an error, or want to write for MetaExploit? Get in touch
What people ask before they start learning here.
Yes. Every article, quiz and daily challenge is free. A free account unlocks the full question bank, the challenges and your progress tracking — there is no paid tier.
Learning is legal; attacking systems you do not own is not. Everything here is written for lab environments and systems you have explicit permission to test. Using what you learn against anyone else is a crime and against our Terms.
No. The material starts from fundamentals and builds up. Take the self-assessment on this page to find your level, then follow the categories that match it.
Azerbaijani, English, Russian and Turkish. Articles and challenges are published in all four — switch language from the top bar.
A fresh hands-on task every day — reverse engineering, web exploitation, cryptography and more. Your answer is graded, you earn points, and the leaderboard ranks the best solvers.
No. Everything runs in the browser. For hands-on lab work you can use your own virtual machine, but nothing is required to read, practise or take the quizzes.
Your account keeps your quiz results, solved challenges and total points. Progress is visible on your dashboard and, once you place, on the public leaderboard.
Report it privately through the contact page rather than publishing it. While testing, please do not disrupt the service, reach other people's data, or point automated scanners at the site. We read every report and fix confirmed issues.
An account unlocks the full question bank, the daily challenges and a record of everything you have solved.