VulnLab: How to get started

Ryan Yager
2 min readMay 5, 2023

Today we are looking at a VulnLab. If you are now wondering WTF is VulnLab, no worries, I just found out about it the other day also. XCT developed VulnLab and made many of the machines, if you are a regular on HTB then you know that XCT is no joke and he does some pretty awesome stuff. He also has a YouTube channel which can be found here: https://www.youtube.com/channel/UClGm2C8Qi0_Wv68zfjCz2YA. VulnLab can be found here https://vulndev.io/lab/. If you notice you will have to signup for his Patreon, USD is around 5 dollars a month which is very cheap for the machines you get. Right now there are around 45 vulnerable machines ranging from beginner to hard, which a few machines being part if a network as show below:

Also, when I signed up for his Patreon, I immediately got the invite for the Discord channel and had a machine up and running in about 3 minutes. Remember before you can do anything you have to give a thumbs up to the rules and regulations and then register with your email, from there you can download the VPN and you are off to the races:

Now if you are downloading the VPN pack and you want to download it straight to your kali vm, right click on Download VPN Pack 1 then from there click copy URL. After that you can do a wget for that URL and it will download the openVPN file.

Lastly, after you start up a machine you will get an IP address:

Alright and we are all ready to attack the machine.

If you want to see more hacking follow on twitch / youtube:

--

--

Ryan Yager

Known on Twitch and YouTube as OvergrownCarrot1 or OGC