FORTIHACK // FortiVox Lab
1 2 3
Beginner · Web Recon STEP 0/4 SCORE 0 HINTS 0 TIME 00:00
L1 — fortihack@fortivox-lab:~$

FortiHack Simulator: hacking games in your browser

A free capture-the-flag playground built by FortiVox. You get a realistic Linux terminal, three missions of increasing difficulty, and a weekly global leaderboard — while every command is 100% simulated inside your browser. Nothing touches a real system.

Three missions. One terminal.

Tier 1 · Beginner

Web Recon

Confirm a silent host is alive, scan its web port and chase a hidden backup file. Commands: ping nmap curl

Tier 2 · Intermediate

Credential Harvesting

Enumerate a legacy box, pull anonymous FTP loot and pivot into an interactive SSH session. Commands: nmap -sV ftp ssh

Tier 3 · Advanced

Privilege Escalation

Hunt a misconfigured SUID binary, keep your effective UID and read root’s flag. Commands: find python3

How to play

Why it’s safe (and why that matters)

Frequently asked questions

Is FortiHack Simulator safe to play?

Yes. Every command runs inside a client-side emulation engine in your browser. No real systems, networks or servers are ever contacted or executed against.

Do I need to install anything?

No. FortiHack runs entirely in your browser using a virtual terminal — open the page and start typing ls, nmap, curl or ssh.

How does scoring work?

Missions award 1000, 1500 and 2000 points. Each hint costs 150 points. The server recomputes your score from verified flags, hints and time — so the weekly leaderboard stays fair.

Can I play on my phone?

Yes. The terminal adapts to small screens, though a physical keyboard makes commands much faster.