Acceptable Use Policy
The rules that matter day to day: what the sandboxes are for, what is never acceptable, and what happens when a line is crossed.
- Effective from
- Last updated
What the sandboxes are for
A lab or CTF sandbox is a deliberately vulnerable system that exists so you can attack something safely. It runs on isolated infrastructure on a separate domain from the application, it is destroyed at the end of its lifetime, and it is monitored.
- Attack your own sandbox as hard as you like. That is what it is for.
- Do not attack another learner sandbox. Sandboxes are isolated, attempts are logged, and this is treated as an attack on a third party rather than as an experiment.
- Do not use a sandbox to reach anything outside it: not the internet at large, not a third party, not the Cyber VK application.
- Do not use a sandbox as compute. Mining, hosting, proxying and bulk scanning are all detected and all end the session and usually the account.
Never acceptable
- Testing a system you do not own and have no written permission to test, using anything you learned here.
- Sharing flags, answers or exam content. Flags are per-user and per-season by design, so sharing one achieves nothing except a detection event on your account.
- Automating the platform: scraping content, bulk-registering accounts, or driving the API outside the published rate limits.
- Uploading malware, illegal content, or anything you do not have the right to share, including copyrighted course material from another provider.
- Harassment, abuse or discrimination in the community. The community exists because it is worth having and it will be moderated on that basis.
- Circumventing an entitlement gate or a quota, or helping anyone else to.
Dual-use content, and where we draw the line
Offensive technique is dual-use by nature and we teach it anyway, because defenders who have never attacked anything defend badly. What we do not publish is a weaponised exploit for an unpatched vulnerability, a proof of concept before a vendor patch exists except where the vendor has abandoned the issue, or reconnaissance on a named real-world organisation. That position is set out in full in the CVE content and disclosure policy.
What happens if you cross a line
For anything that affects another person or the platform, suspension is immediate and is not preceded by a warning. For anything else, you will be told what the problem is and given a chance to fix it. Enforcement decisions are logged with a reason, and you can ask for a review by a person rather than a process.
Where conduct appears to be criminal, we cooperate with law enforcement. We will tell you that we have done so unless we are legally prohibited from telling you.
Reporting a problem
Every piece of user-generated content on the platform carries a report control. For a vulnerability in Cyber VK itself, use the responsible disclosure policy rather than the report control, because that route is monitored by the people who can fix it.