Root-Me is a free, non-profit hacking platform from France that has been training players since 2010, and it is just as useful if you have never typed a command in your life. It has more than 600 challenges, no paywall on the core content, and a reputation for being blunt: you get a goal, a target, and very little hand-holding. If you have never captured a flag before, spend five minutes on HackerDNA's Capture the Flag 101 lab first, so you know what a flag looks like and how to submit one before Root-Me drops you in the deep end.
This guide explains what Root-Me is, how it is organized, the ten challenges we would solve first, and the two traps that make most beginners quit in their first week.
TL;DR: Root-Me (root-me.org) is a free learning platform run by a French non-profit association, with 608 challenges, 178 virtual environments, and 6,127 community solutions as of October 2026. Start in the Web - Server, Network, and Cryptanalysis categories with the 5-point challenges, never run scanners at full speed (the firewall bans you for 5 minutes), and read other players' solutions after every flag.
What Is Root-Me?
Root-Me is a free online platform for learning hacking and information security through hands-on challenges. It is run by a non-profit association whose stated goal is "to promote the spread of knowledge related to hacking and information security." The site has been online since 2010 and is available in French, English, German, Spanish, Russian, and Chinese.
Each challenge gives you a short statement and something to attack: a web page, a file to download, a packet capture, or SSH access to a small Linux box. Somewhere inside is a password, which Root-Me calls a "flag" or "validation password." You type it into the challenge page and the points are yours.
The numbers on the Root-Me homepage, checked on October 1, 2026:
- 608 challenges across 11 categories, from 5-point warm-ups to 100-point cryptography problems.
- 178 virtual environments for full machine compromises in the "CTF all the day" rooms.
- 6,127 solutions written by players, which you can read once you solve a challenge.
The oldest challenges are very popular. HTML - Source code, the first challenge in the Web - Server category, shows 188,898 validations on its listing. That gives you an idea of how many people have walked through the same door you are about to open.
Is Root-Me Free? Visitor, Contributor, and Root-Me PRO
Yes. The challenges, the virtual environments, and the solutions are free for individual players. The homepage describes three kinds of access:
- Visitor access: free. You can "train for free on various exercises" and "see solutions proposed by the other members."
- Contributor access: for members who pay a membership fee to the association. Contributors get the latest exercises created by other contributors, help with moderation and proofreading solutions, and can be rewarded for challenges they create.
- Root-Me PRO: a separate commercial offer for schools and companies, with learning paths, team progress tracking, and private CTF events.
For a beginner, visitor access is plenty. You will not run out of free content for a long time: the Web - Server category alone has 97 challenges.
How Root-Me Is Organized: The 11 Challenge Categories
Root-Me sorts its challenges into 11 categories. Inside each one, challenges are listed by points, and points track difficulty closely. A 5-point challenge is a warm-up. Anything above 40 points will take a beginner days, not minutes.
| Category | What you practice | Beginner-friendly? |
|---|---|---|
| Web - Server | HTTP, authentication, SQL injection, file upload, JWT | Yes, start here |
| Web - Client | JavaScript, XSS, browser-side logic | Yes |
| Network | Packet captures, protocols like FTP, Telnet, DNS | Yes |
| Cryptanalysis | Encodings, hashes, classical ciphers, RSA | First few only |
| Programming | Scripts that talk to a server faster than a human can | Needs basic Python |
| Steganography | Data hidden in images and files | Mixed |
| Forensic | Memory dumps, logs, disk images | Mixed |
| App - Script | Linux shell, sudo, cron, scripting mistakes | First two only |
| App - System | Memory corruption, buffer overflows | No |
| Cracking | Reverse engineering binaries | No |
| Realist | Multi-step scenarios on realistic web apps | No |
Root-Me's own FAQ has a section titled "I'm a beginner and I'm a bit lost... where should I start?" It admits that "some Root-Me sections are quite hard, like the Realistic challenges," and suggests a path that starts with Network, Programming, Cryptanalysis, and Steganography before moving to the web categories. We would start with Web - Server instead, and Root-Me itself backs that up: the French description of the category calls it "la série d'épreuves la plus accessible," the most accessible series of challenges on the site. Web challenges need nothing but a browser, and quick wins keep you coming back.
If the category names mean nothing to you yet, our guide to CTF for beginners explains each type of challenge and the tools that go with it.
The First 10 Root-Me Challenges to Solve
These are the challenges we would hand a friend on day one. All of them are worth 5 to 15 points, each one teaches a skill you will reuse for years, and together they cover four categories. No spoilers here, only the idea behind each one.
- HTML - Source code (Web - Server, 5 points): the classic first flag. Right-click, view the source, read carefully.
- HTTP - User-agent (Web - Server, 10 points): the server only trusts a certain browser. You will learn that every HTTP header is something you control.
- Weak password (Web - Server, 10 points): an admin login page. Think about the passwords lazy administrators actually use.
- HTTP - Directory indexing (Web - Server, 15 points): what happens when a web server lists a folder's contents to anyone who asks.
- FTP - authentication (Network, 5 points): your first packet capture. Open it in Wireshark and see why plaintext protocols are dangerous.
- TELNET - authentication (Network, 5 points): same lesson, different protocol. Wireshark's "Follow TCP Stream" is your friend.
- Encoding - ASCII (Cryptanalysis, 5 points): encoding is not encryption. Recognize the format and convert it.
- Hash - Message Digest 5 (Cryptanalysis, 5 points): your first hash to crack. MD5 has been considered broken for years, and this shows you why that matters.
- Bash - System 1 (App - Script, 5 points): SSH into a real Linux box and read a tiny C program. The bug is in how it calls another command.
- sudo - weak configuration (App - Script, 5 points): your first privilege escalation. Start with
sudo -land read what it tells you.
In practice, the jump after these ten is steep. Shift cipher, HTTP - Cookies, and SQL injection - Authentication are good next steps, but the validation numbers drop fast. HTML - Source code has 188,898 validations, while SQL injection - Authentication has 51,349. That gap is where most people stall, and it is usually a knowledge gap, not a talent gap.
A cookie challenge is a good example. If you have never edited a cookie, HTTP - Cookies will feel impossible. Our Hack the Cookie lab walks through the same idea with a Base64 session cookie and an admin role you can switch on yourself.
Two Traps That Stall Root-Me Beginners
1. Getting your IP banned by the firewall
This one surprises almost everyone. According to the Root-Me FAQ, a firewall bans any IP address that opens more than 25 connections per second or keeps more than 25 TCP connections open at once. The ban lasts 5 minutes, and trying to connect during the ban extends it.
Tools like ffuf, Gobuster, or Hydra can blow past that limit with their default settings. So the beginner fires up a directory scan, the site goes dark, and they assume Root-Me is down. Slow your tools down (ffuf's -rate option, Gobuster's -t and --delay), and remember that most early challenges do not need a scanner at all.
2. Not being logged in from the same IP
Challenge machines only accept connections from IP addresses that are logged in to www.root-me.org. The FAQ says you must "use the same IP address for your authentication and for challenges." If you log in on your laptop's browser but connect from a VPN or a cloud VM, you will get nowhere. The FAQ also warns that Root-Me's SSH services do not run on port 22, so always copy the port from the challenge page.
Tip: the FAQ notes that some older published solutions "don't textually work anymore" because challenge systems get updated. If a solution fails, understand the idea behind it and adapt, instead of copying commands line by line.
How to Use Root-Me Solutions Without Cheating Yourself
The solutions section is the best part of Root-Me, and also the easiest to misuse. Once you validate a challenge, you can read the write-ups other players submitted. Some are three lines of commands, others are full explanations with background reading.
Our honest advice: always read at least two solutions after every flag, even when you solved it easily. You will often find a cleaner method, a tool you did not know, or the concept you only half understood. That habit is where most of the learning happens.
Searching for answers to a challenge you have not solved yet is a different story. A flag you copied teaches you nothing, and your score stops meaning anything. If you are stuck, use this order instead:
- Reread the statement and the challenge title. On Root-Me, the title is often the biggest hint.
- Open the "related resources" listed on the challenge page. Some are in French, but the technique names are universal.
- Step away for a day. Many flags fall on the second attempt with fresh eyes.
- Ask in the Root-Me forum for a nudge, not the answer.
CTF All the Day: Root-Me's Shared Boot-to-Root Rooms
Once you are comfortable with single challenges, Root-Me's "CTF all the day" mode is where you attack full machines. The goal, in Root-Me's words, is "to fully compromise, « root » the host."
It works differently from Hack The Box or TryHackMe. There are 35 public rooms. Players in a room vote on which virtual environment to load, the game starts when everyone is ready (one player is enough), and the target appears at an address like ctf01.root-me.org. The game ends when someone submits the validation flag or when the maximum "woot time" runs out.
Two consequences matter for beginners. First, other players may be attacking the same machine as you, so services can crash or change under your feet. Second, someone else can finish first and end the round. Wait until you have a few dozen regular challenges behind you before trying it.
Root-Me vs TryHackMe, Hack The Box, and HackerDNA
Root-Me is a great platform, but it is not the right first stop for everyone. Here is how it compares:
| Platform | Cost | Teaching style | Best for |
|---|---|---|---|
| Root-Me | Free (non-profit) | Short challenges, community solutions | Breadth across many categories |
| TryHackMe | Free rooms, paid Premium | Guided rooms with questions | Step-by-step learners |
| Hack The Box | Free tier, paid VIP | Full machines, little guidance | Players aiming at pentest certifications |
| HackerDNA | Free tier, paid Pro | Browser labs, guided courses, a daily hack | Beginners who want explanations and no setup |
Root-Me's weak spot is teaching. A challenge gives you a goal and some links, not a lesson. If you like figuring things out alone, that is a feature. If you keep hitting walls, pair it with something that explains the concept first, then come back and solve the Root-Me version. For a longer comparison of free and paid platforms, see our roundup of Hack The Box alternatives.
Legal and Ethical Considerations
Critical reminder: Root-Me's targets are legal to attack because the association built them for that purpose. Using the same techniques on any system you do not own, or do not have explicit written permission to test, is illegal.
- Attack the challenges, not the platform: the portal, the forum, and other players' accounts are off-limits. If you find a real flaw in Root-Me itself, report it to the team.
- Respect the rate limits: the firewall is there to protect a free service run by volunteers. Hammering it hurts everyone else.
- Do not publish flags: the solutions section exists so that write-ups stay behind a validated challenge. Posting flags or full answers elsewhere spoils the platform for everyone.
- Keep your practice in the lab: "I learned it on Root-Me" is not a defense if you try it on your school or employer's network.
Frequently Asked Questions
What is Root-Me?
Root-Me (root-me.org) is a free platform for learning hacking through hands-on challenges. It is run by a French non-profit association, has been online since 2010, and offers more than 600 challenges in 11 categories, including web, network, cryptanalysis, forensics, and reverse engineering.
Is Root-Me good for beginners?
Yes, if you start in the right place. The 5- and 10-point challenges in Web - Server, Network, and Cryptanalysis are made for beginners. Root-Me gives less guidance than TryHackMe or HackerDNA, so expect to research concepts on your own.
Is Root-Me available in English?
Yes. The site is available in English, French, German, Spanish, Russian, and Chinese. Some related resources and older forum threads are only in French, but the challenges themselves can be played in English.
Is Root-Me the same as the TryHackMe RootMe room?
No. "RootMe" is also the name of a beginner room on TryHackMe, which is a different platform. Root-Me with a hyphen, at root-me.org, is the French non-profit platform covered in this guide.
Why can't I connect to Root-Me challenges?
The two usual causes are a temporary IP ban (more than 25 connections per second triggers a 5-minute ban) and connecting from a different IP than the one logged in to the website. Root-Me's SSH services also use non-standard ports, so copy the port from the challenge page.
Does Root-Me look good on a CV?
It can help, especially in France, where the platform is well known. A score on its own proves little, though. Write-ups explaining how you solved challenges, published after you validated them and without flags, say much more about your skills.
Last verified: October 2026. Challenge counts, categories, validation numbers, and firewall rules checked on root-me.org.
Your Next Steps
Root-Me is one of the best free places to practice hacking: hundreds of challenges, a non-profit behind it, and a community that shares its solutions. Make an account, open the Web - Server category, and work through the first ten challenges in this guide at your own pace. Read two solutions after every flag, and keep your tools slow.
When a Root-Me challenge leaves you stuck on a concept, learn it properly and come back. HackerDNA's Web Security Basics course covers HTTP, cookies, and authentication from an attacker's point of view, and labs like Secrets in Source and Hack the Cookie let you practice in the browser with explanations along the way. Start with HackerDNA's free tier - no credit card required.