HackThisSite: Beginner's Guide to the Missions (2026)

CTF & Practice
12 min read
HackThisSite: Beginner's Guide to the Missions (2026)
On this page
  1. What Is HackThisSite?
  2. Is HackThisSite Still Worth It in 2026?
  3. HackThisSite Challenge Categories Explained
  4. What Each HackThisSite Basic Mission Teaches
    1. Missions 1 to 3: learn to read what the server sends you
    2. Missions 4 to 6: the browser is under your control
    3. Missions 7 to 9: from a web page to the server's shell
    4. Missions 10 and 11: trust and configuration
  5. How to Play HackThisSite With Modern Tools
  6. How to Get Unstuck Without Spoiling the Mission
  7. HackThisSite vs OverTheWire, Root-Me, and HackerDNA
  8. Legal and Ethical Considerations
  9. Frequently Asked Questions
  10. Your Next Steps

HackThisSite is one of the oldest free hacking playgrounds on the internet, and it is still a good place to capture your first flags. Since 2003, beginners have been using its missions to learn how websites break: hidden form fields, weak homemade encryption, command injection, sloppy server configuration. If you have never solved a challenge before, take five minutes on HackerDNA's Capture the Flag 101 lab first, so the "find the secret, submit it, score" loop already feels familiar when you open your first HackThisSite mission.

This guide covers what HackThisSite is, how the mission categories work, what each of the 11 Basic missions teaches (without spoiling them), and how to play a site built in the 2000s with the tools you have today.

TL;DR: HackThisSite (hackthissite.org) is a free, volunteer-run training ground with web, JavaScript, programming, steganography, forensics, and application challenges. Make a free account, then do the 11 Basic web missions in order: they teach page source reading, parameter tampering, command injection, and server misconfiguration. Old tutorials rely on browser add-ons that no longer exist, so use your browser's DevTools or Burp Suite instead.

What Is HackThisSite?

HackThisSite (often shortened to HTS) is a free website where you practice hacking legally on challenges built to be attacked. The homepage describes it as "a free, safe and legal training ground for hackers to test and expand their ethical hacking skills with challenges, CTFs, and more," active since 2003.

The project grew out of Chicago and is run entirely by volunteers. The challenges are free, and the site pays its bills through donations and a merchandise store. Its homepage states that "HTS costs up to $300 a month to operate."

What makes Hack This Site different from a modern CTF platform is the community around it. The HTS Project Guide describes the challenges as "simulated wargames," backed by an IRC network, forums, a Discord server, and user-written articles. Many of those articles are mission tutorials written by players who were beginners themselves, and they are often more useful than a full walkthrough because they explain the concept and stop before the answer.

A quick history note, since you will see it mentioned: according to Wikipedia, the site was founded by Jeremy Hammond, who later left the organization and was convicted for unrelated hacking activity. The site has been maintained by its community since.

Is HackThisSite Still Worth It in 2026?

Yes, for the Basic missions and a handful of others. But go in knowing what you are getting.

The site is old and says so itself. In a news post dated December 3, 2025, the staff wrote: "Hack This Site is old in a lot of ways. It turned 20 years old in 2023, but the code is also old and so are the challenges, even the server design is outdated." The same post announced a server migration for early 2026, followed by a recode with "new website, new challenges, return of the forums." When we checked on October 2, 2026, the homepage still showed that December 2025 post as the latest news, and the page footer still reported code revision v3.2.5 from May 2016.

Here is our honest take on what holds up and what does not:

  • Still excellent: the Basic web missions. They teach how a web server, a form, and a password check fit together, and none of that has changed.
  • Still fun: the Realistic missions, where you play a freelance hacker hired to fix an injustice on a fake website. The storytelling is part of the charm.
  • Dated: the advice around the challenges. Many tutorials recommend Firefox add-ons like Tamper Data, which stopped working years ago, and some techniques (like typing JavaScript into the address bar) are now blocked by browsers.
  • Missing: modern topics. You will not find JWTs, APIs, cloud misconfigurations, or containers here.

So treat HackThisSite as a fundamentals gym, not a complete curriculum. The concepts transfer, even when the PHP pages around them look like 2005.

💻
Practice this now: Hack This Site - yes, HackerDNA has a free lab with the same name. It is a modern take on the JavaScript missions: a vault login protected by obfuscated client-side code that you take apart with browser DevTools to capture the flag.

HackThisSite Challenge Categories Explained

All missions sit behind a free account: the mission pages show "Login Required" until you sign in. Once you are in, the menu lists these categories:

CategoryWhat you doBeginner-friendly?
Basic11 short web missions: get past a password page by exploiting a simple flawYes, start here
RealisticComplete fake websites with a story and an objectiveAfter Basic
JavaScriptRead and abuse client-side JavaScriptYes
Extended BasicRead vulnerable code snippets, then exploit or patch themNeeds some code reading
SteganographyExtract a hidden message from a media file (17 missions)Mixed
ForensicAnalyze evidence filesMixed
ProgrammingWrite a script that solves a task within a time limitNeeds basic Python
ApplicationExtract a key from a program on your own machine (reversing)No

The Project Guide says the Basic challenges "are designed to outline the fundamentals of a hacker's first steps in web hacking." That is exactly right, and it is why we tell beginners to ignore everything else until Basic 11 is done. The Realistic missions build directly on them, and the guide is clear that "the web hacking skills taught in this series of challenges can be directly applied to systems in the real world."

If terms like "steganography" or "reversing" are new to you, our CTF for beginners guide explains each challenge type and the tools that go with it.

What Each HackThisSite Basic Mission Teaches

Every Basic mission follows the same pattern: a page with a password box, and a fictional webmaster named Sam who keeps making mistakes. Your job is to find the password. Below is the concept behind each mission, with no answers. The modern names are what you would call the same flaw in a pentest report today.

MissionWhat it teachesModern name
Basic 1Reading the page sourceSensitive data in client-side code
Basic 2Reading the mission text very carefullyLogic flaw
Basic 3How HTML forms send data, and where they send itInformation disclosure
Basic 4Changing what a form sendsParameter tampering
Basic 5The same idea, against a slightly smarter scriptParameter tampering
Basic 6Breaking a homemade "encryption" schemeWeak cryptography
Basic 7Running extra commands through a script that calls a Unix toolOS command injection
Basic 8Abusing Server Side Includes on a .shtml pageSSI injection
Basic 9Combining the previous trick with directory navigationPath traversal
Basic 10Convincing the page you are authorizedCookie tampering
Basic 11Exploring how an Apache server is configuredSecurity misconfiguration

Missions 1 to 3: learn to read what the server sends you

The first missions train the single most useful habit in web hacking: look at everything the browser receives, not just what it displays. Press Ctrl+U to view the source, read every comment and every hidden field, and ask what each one is for. Mission 2 is famous for stumping people who skim. A community tutorial on the site puts it bluntly: "Read it once, then read it again without even trying to get the password."

Missions 4 to 6: the browser is under your control

Missions 4 and 5 teach that anything in a web page, including a hidden value inside a form, can be changed before it reaches the server. This is the root of a huge share of real bugs. Mission 6 hands you an "encryptor" and an encrypted password.

In practice, the fastest way through a mission like this is to feed the encryptor boring, predictable input and compare what comes out. Try a string of identical characters, then a string of increasing ones. Patterns jump out quickly, and the habit (control the input, watch the output) is the same one you will use on real encoding schemes later.

Missions 7 to 9: from a web page to the server's shell

Mission 7 is where HackThisSite gets serious. The page runs the Unix cal command with your input, and you need a way to end that command and start another. This is OS command injection, one of the most dangerous flaws a web app can have, and it still appears in real routers, NAS devices, and admin panels today. Missions 8 and 9 do the same with Server Side Includes, and the syntax has to be exact: a tutorial on the site warns that "your syntax is monitored very carefully."

💻
Practice this now: Ping Pwn - the same lesson as Basic 7 on a modern target: a network monitoring page passes your input to ping, and you chain your own command onto it to read the flag.

Missions 10 and 11: trust and configuration

Mission 10 checks whether you are authorized with a cookie. If the client stores the decision, the client can change it. Mission 11 is the hardest Basic mission by a distance. It is not about code at all, but about how an Apache web server exposes directories and configuration files when nobody locks them down. Expect it to take longer than any other Basic mission.

How to Play HackThisSite With Modern Tools

The biggest trap for beginners in 2026 is following a 2008 tutorial word for word. The concepts are fine. The tools are not. Here is what to use instead:

  • Instead of Firefox add-ons (Tamper Data, Web Developer, Cookie editors): use the built-in DevTools in Firefox or Chrome. The Inspector/Elements tab lets you edit HTML on the page, and the Storage (Firefox) or Application (Chrome) tab lets you view and edit cookies.
  • Instead of "javascript:" typed into the address bar: open the DevTools Console and run your JavaScript there. Firefox ignores javascript: URLs typed in the address bar, and Chrome strips the prefix when you paste it.
  • Instead of a referer-switching add-on: use Firefox's "Edit and Resend" on a request in the Network tab, or route your browser through Burp Suite and change any header you like.

The DevTools chapter of HackerDNA's Web Security Basics course walks through each of these panels from an attacker's point of view, which covers almost everything the Basic and JavaScript missions need.

Tip: HackThisSite invites people to attack the site itself and rewards responsible disclosure with a Hall of Fame entry. That also means you should treat it like any old web app: register with a password you do not use anywhere else.

How to Get Unstuck Without Spoiling the Mission

Full walkthroughs for every Basic mission are one search away, on Medium, GitHub, and wikiHow. Reading one before you have tried for real is the quickest way to learn nothing. Use this order instead:

  1. Reread the mission text. Sam's description almost always tells you what he did wrong.
  2. Name the concept. Use the table above, then read a general explanation of that concept (not of the mission).
  3. Read an HTS article. The site's own Basic tutorials, like the "Basic Guide (1-11)," give hints and deliberately stop before the answer.
  4. Ask for a nudge. The Project Guide says the community helps "people who ask intelligent questions." Say what you tried and what you expected.
  5. Only then, read a write-up. And after you solve it, read one anyway: there is often a cleaner method.

That last habit is underrated. Once Basic 4 is done, look at how others solved it. Some edited the HTML, some injected JavaScript, some crafted the request from scratch. Knowing three ways to do the same thing is what makes the next mission easier.

HackThisSite vs OverTheWire, Root-Me, and HackerDNA

HackThisSite is one of several free places beginners hear about. Here is where it fits:

PlatformCostStyleBest for
HackThisSiteFree (donations)Story-driven missions, community tutorialsWeb fundamentals in the browser
OverTheWireFreeSSH wargames, one password per levelGetting comfortable in a Linux terminal
Root-MeFree (non-profit)Hundreds of short challenges, community solutionsBreadth across many categories
HackerDNAFree tier, paid ProBrowser labs, guided courses, a daily hackBeginners who want explanations and modern targets

A solid zero-budget path: OverTheWire Bandit for the terminal, HackThisSite Basic for the web, then Root-Me when you want more variety. Our Root-Me beginner guide lists the first ten challenges to try there. HackThisSite's weak spot is that its content belongs to the PHP-and-forms web of the 2000s. Once the Basic missions click, you will want targets with APIs, tokens, and frameworks you will actually meet on the job.

Critical reminder: HackThisSite's missions are legal to attack because the site built them for that. The same techniques used on a system you do not own, or do not have explicit written permission to test, are illegal.

  • Read the Terms and Conditions: the homepage says all users are "required to read and adhere to" them. Do it before you start.
  • Report, do not exploit: HTS encourages people to look for flaws in the site itself, but rewards responsible disclosure. Taking data, defacing pages, or disrupting other users is not part of the deal.
  • Do not publish answers: posting passwords or step-by-step solutions spoils the missions for the next beginner.
  • Keep the practice in the lab: command injection on Basic 7 is a lesson. The same input on your school's or employer's website is a crime.

Frequently Asked Questions

What is HackThisSite?

HackThisSite (hackthissite.org) is a free, volunteer-run website where you practice ethical hacking on challenges built to be attacked. Active since 2003, it offers Basic and Realistic web missions plus JavaScript, programming, steganography, forensics, and application challenges, along with community tutorials, IRC, and Discord.

Is HackThisSite free?

Yes. All missions are free, but you need a free account to access them. The site is funded by donations and says it costs up to $300 a month to run.

Is HackThisSite good for beginners?

Yes. The 11 Basic missions were designed as a first step in web hacking and need only a browser. The main drawback is age: many tutorials reference outdated tools, so use your browser's DevTools instead of the add-ons they mention.

Is HackThisSite legal?

Yes. Attacking the missions is legal because the site provides them for practice, and users must accept its Terms and Conditions. Using the same techniques on any other website without permission is illegal.

How many Basic missions does HackThisSite have?

There are 11 Basic web missions. They start with reading the page source and end with an Apache configuration challenge that is much harder than the first ten.

Is HackThisSite the same as HackerDNA's Hack This Site lab?

No. HackThisSite at hackthissite.org is an independent community site. HackerDNA's Hack This Site lab is a separate, free browser challenge on HackerDNA about obfuscated JavaScript and client-side authentication.

Last verified: October 2026. Categories, login requirement, news, and quotes checked on hackthissite.org and its Project Guide.

Your Next Steps

HackThisSite is old, free, and still one of the best ways to learn how websites fail. Make an account, open Basic 1, and work through all 11 Basic missions in order with DevTools open. Read the mission text twice, name the concept before you search, and read someone else's solution after every password you find.

When you want the same skills on modern targets, with explanations along the way, HackerDNA's Web Security Basics course and labs like Hack This Site and Ping Pwn run entirely in your browser. Start with HackerDNA's free tier - no credit card required.

HackerDNA Team

HackerDNA Team

Written by the HackerDNA team - cybersecurity professionals building hands-on hacking labs and educational content to help you develop real-world security skills.

Meet the Team

Ready to put this into practice?

Stop reading, start hacking. Real machines, in your browser, free.

Start Hacking Free
30,000+ Hackers Real labs Free
Start Hacking Free or solve today's hack, no account needed