Home
Legal

Acceptable Use Policy

The rules that matter day to day: what the sandboxes are for, what is never acceptable, and what happens when a line is crossed.

Effective from
Last updated

What the sandboxes are for

A lab or CTF sandbox is a deliberately vulnerable system that exists so you can attack something safely. It runs on isolated infrastructure on a separate domain from the application, it is destroyed at the end of its lifetime, and it is monitored.

  • Attack your own sandbox as hard as you like. That is what it is for.
  • Do not attack another learner sandbox. Sandboxes are isolated, attempts are logged, and this is treated as an attack on a third party rather than as an experiment.
  • Do not use a sandbox to reach anything outside it: not the internet at large, not a third party, not the Cyber VK application.
  • Do not use a sandbox as compute. Mining, hosting, proxying and bulk scanning are all detected and all end the session and usually the account.

Never acceptable

  • Testing a system you do not own and have no written permission to test, using anything you learned here.
  • Sharing flags, answers or exam content. Flags are per-user and per-season by design, so sharing one achieves nothing except a detection event on your account.
  • Automating the platform: scraping content, bulk-registering accounts, or driving the API outside the published rate limits.
  • Uploading malware, illegal content, or anything you do not have the right to share, including copyrighted course material from another provider.
  • Harassment, abuse or discrimination in the community. The community exists because it is worth having and it will be moderated on that basis.
  • Circumventing an entitlement gate or a quota, or helping anyone else to.

Dual-use content, and where we draw the line

Offensive technique is dual-use by nature and we teach it anyway, because defenders who have never attacked anything defend badly. What we do not publish is a weaponised exploit for an unpatched vulnerability, a proof of concept before a vendor patch exists except where the vendor has abandoned the issue, or reconnaissance on a named real-world organisation. That position is set out in full in the CVE content and disclosure policy.

What happens if you cross a line

For anything that affects another person or the platform, suspension is immediate and is not preceded by a warning. For anything else, you will be told what the problem is and given a chance to fix it. Enforcement decisions are logged with a reason, and you can ask for a review by a person rather than a process.

Where conduct appears to be criminal, we cooperate with law enforcement. We will tell you that we have done so unless we are legally prohibited from telling you.

Reporting a problem

Every piece of user-generated content on the platform carries a report control. For a vulnerability in Cyber VK itself, use the responsible disclosure policy rather than the report control, because that route is monitored by the people who can fix it.

Acceptable Use Policy · Cyber VK