ZCR Security Arena
Software Security · KOSEN·KMITL & MFU
<div class="alert alert-warning" style="margin-top:2rem">
<b>Authorized use only.</b> Every offensive technique in this arena is for defensive and
authorized testing on the provided sandbox targets. Never attack systems you do not own or
lack written permission to test. Flags are per-student and traceable — submitting someone
else's flag is an academic integrity violation.
</div>
<h4 style="margin-top:2rem">Getting started</h4>
<ol>
<li>Register with your <b>university email address</b> (kmitl.ac.th or mfu.ac.th). Other domains are not accepted.</li>
<li>Use your <b>student ID as your username</b> — this is how lab work is credited to you.</li>
<li>Open <b>Challenges</b>, start an instance, and submit the flag it gives you.</li>
</ol>
<p class="text-muted" style="margin-top:2rem">
Each challenge instance is yours alone and expires automatically. If something looks broken,
tell your instructor rather than working around it — that report is worth more than the flag.
</p>