Learn how to use a WAF with the WAFShield lab
Every lab on CyberLearner so far has put you on the attacking side. Find the bug, write the exploit, get the flag. WAFShield flips that. You get a real, unpatched, vulnerable Flask application sitting behind a WAF dashboard you control, and a second, sandboxed container that launches real attack tools against it: nmap, nikto, sqlmap, ffuf, masscan and hping3. Your job is to write rules that block the attacks without blocking the legitimate traffic a background generator keeps sending the whole time.
Why real tools instead of simulated traffic
Canned "attack signatures" teach you to recognise a signature, not an attack. Running actual
sqlmap against an actual SQLite backend means the WAF has to hold up against whatever sqlmap
really does, including its more aggressive scan modes. Those turned out to have their own
failure modes. SQLite's RANDOMBLOB() can be coaxed into allocating enough memory per
call to OOM-kill the target container under a --risk 3 --level 3 sweep. Building
the lab meant fixing that at the SQLite layer, not papering over it.
What "solved" looks like
There is no single flag. Seven categories each unlock their own mini-flag: SQLi, XSS, command injection, path traversal, scanner detection, rate limiting, and a private-endpoint check. A category only goes green when your rules block the attack traffic and the legitimate traffic generator still gets through cleanly. Block everything and you fail the false-positive check. Block nothing and the attacks get through. The final flag needs all seven green at once.
WAFs offer decent protection, but any WAF can be bypassed. That is why it is one layer, not the whole plan. This lab is the first on the platform built to reward the unglamorous half of security work: tuning, not just breaking.
CyberLearner.org is a free cybersecurity training platform, built on the curriculum of the International Cybersecurity Olympiad (ICO). Every lab is hands-on and runs in your browser. It is open to everyone, regardless of skill level.