Home labs

In-browser labs

Read the artifact. Name what matters.

Four drills with no virtual machine and no network. Each sample is fictional. You identify the method, the claims, the certificate fields, or the scan pattern. Nothing here forges a token or sends a packet.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

beginner
HTTP

Read an HTTP request

A fictional request to lab.opsfield.example. Separate the method, the path, the headers, and the body.

POST /api/v1/notes HTTP/1.1
Host: lab.opsfield.example
Authorization: Bearer lab-demo-token
Content-Type: application/json
Accept: application/json

{"title":"scope notes","owner":"avery"}
What is the method?
What is the path?
Which header carries the caller's credential in this sample?
Which body field names the note owner?
Answers stay in this browser.
beginner
JWT

Inspect a JWT

Decode the header and payload only. The third segment is not a real signature and is not checked. This drill does not modify the token.

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJsYWItdXNlciIsIm5hbWUiOiJBdmVyeSBDaGVuIiwicm9sZSI6InJlYWRlciIsImlzcyI6Im9wc2ZpZWxkLWxhYiIsImF1ZCI6ImFjYWRlbXkiLCJleHAiOjE4OTM0NTYwMDB9.signature-not-checked

Header

{
  "alg": "HS256",
  "typ": "JWT"
}

Payload

{
  "sub": "lab-user",
  "name": "Avery Chen",
  "role": "reader",
  "iss": "opsfield-lab",
  "aud": "academy",
  "exp": 1893456000
}

The signature segment is the literal text signature-not-checked. It is not verified and there is nothing to forge.

Which signing algorithm does the header claim?
What role does the payload claim?
Who is the subject (sub)?
Who is the issuer?
The exp claim is 1893456000. Which year is that?
Answers stay in this browser.
beginner
Certificate

Read a certificate

A text summary of a lab certificate. No private key is included. Name the subject, the issuer, and the expiry.

Subject:     CN=lab.opsfield.example
Issuer:      CN=OpsField Lab CA
Not before:  2026-01-15
Not after:   2027-01-15
SAN:         DNS:lab.opsfield.example
Key usage:   digitalSignature
What is the subject common name?
Who issued it?
When does it expire?
Answers stay in this browser.
beginner
Logs

See that a scan happened

A fictional firewall and app log. Decide which source looks like a port scan, and which line is an ordinary login. No commands.

2026-10-04T14:02:11Z fw accept src=10.8.0.15 dst=10.8.0.40 proto=tcp dport=22
2026-10-04T14:02:12Z fw accept src=10.8.0.15 dst=10.8.0.40 proto=tcp dport=80
2026-10-04T14:02:12Z fw accept src=10.8.0.15 dst=10.8.0.40 proto=tcp dport=443
2026-10-04T14:02:13Z fw accept src=10.8.0.15 dst=10.8.0.40 proto=tcp dport=445
2026-10-04T14:02:14Z fw accept src=10.8.0.15 dst=10.8.0.40 proto=tcp dport=3389
2026-10-04T14:02:18Z fw accept src=10.8.0.15 dst=10.8.0.40 proto=tcp dport=8080
2026-10-04T14:05:01Z app login user=avery result=success src=10.8.0.20
Which source address fits a port scan?
What makes that pattern a scan rather than normal use?
Which source is the ordinary successful login, not the scan?
Answers stay in this browser.