9 wargames · 113+ writeups · open source

Learn Linux and security by watching the terminal.

Work through the OverTheWire wargames with level-by-level writeups, and learn the concepts through wargame-independent topic guides — all in one repo, by watching the terminal. 🐧

8
Wargames
5
Topic Areas
22
Pwn Modules
Curiosity
you@linux_learning: ~
$ ls overthewire/

OverTheWire is a free platform that teaches Linux and security skills in a game format. From beginner to advanced, in the recommended order:

Bandit Leviathan Krypton Natas Narnia Behemoth Utumno Maze
Bandit01 / 09

The starter wargame for Linux terminal skills — SSH, reading files, permissions and basic tools. You can begin from scratch.

1/10
Difficulty
34
Levels
SSHcat · less · filegrep · sortfindbase64 · rot13
bandit.labs.overthewire.org:2220 writeups →
Leviathan02 / 09

Binary analysis and simple exploit techniques. You inspect binary behaviour with ltrace/strace. Bandit recommended first.

3/10
Difficulty
8
Levels
ltrace · straceSUID binarysymlinkbasic RE
leviathan.labs...:2223 writeups →
Krypton03 / 09

Cryptography fundamentals — from classic ciphers to modern approaches. You crack encrypted messages.

3/10
Difficulty
7
Levels
Caesar · ROTVigenèrefrequency analysisXOR
krypton.labs...:2231 writeups →
Natas04 / 09

Web security — HTTP, source-code analysis, SQL injection, XSS and more. Played in the browser.

4/10
Difficulty
35
Levels
HTTP headersSQL injectionXSSfile inclusionPHP
natas.labs.overthewire.org writeups →
Narnia05 / 09

Binary exploitation — buffer overflow, format string and basic exploit development. Requires reading assembly.

6/10
Difficulty
10
Levels
stack overflowformat stringshellcodeGDBSUID exploit
narnia.labs...:2226 writeups →
Behemoth06 / 09

Intermediate binary exploitation. More complex scenarios than Narnia, ASLR and various protections.

7/10
Difficulty
9
Levels
stack · heap overflowret-to-libcGOT/PLTpwntools
behemoth.labs...:2221 writeups →
Utumno07 / 09

Advanced binary exploitation. Minimum hints, maximum difficulty — for experienced exploit developers only.

9/10
Difficulty
8
Levels
arbitrary writeinteger truncationjmp_bufPTR_MANGLE
utumno.labs...:2227 writeups →
Maze08 / 09

Mixed binary exploitation & RE — a different vulnerability class each level: TOCTOU, library hijack, self-modifying code, FSOP, ELF parser, format string. A capstone after Behemoth + Utumno.

5/10
Difficulty
9
Levels
TOCTOUlib hijackFSOPformat stringself-modifying
maze.labs...:2225 writeups →
Vortex09 / 09

A broad lab that begins with network/socket programming and walks the entire classic binary-exploitation curriculum — endianness, overflow, format string, heap, ret2libc/ROP, then cryptanalysis + RE/keygen. Source isn't given at most levels.

6/10
Difficulty
27
Levels
endiannessoverflowformat stringheap/ROPcrypto/RE
vortex.labs...:2228 writeups →
$ tree topic_guides/

Files where commands and concepts are kept as wargame-independent reference — now all readable inside the site. Click a category to open the reader.

$ cat resources.md

A curated selection of external resources collected in the repo — for when you want to go deeper.