Martian Defense Self-hosted · Docker · offline

Attack a whole range
in one command

RedPlanet is seven intentionally vulnerable training ranges and 17 single-vulnerability labs — web, API, DevSecOps, network, cloud, Kubernetes and blue-team — that each stand up on your host from a single Docker image.

7ranges
17custom labs
1command to launch
Seven ranges

Pick the surface you want to attack

Each range is one Docker image. Run one on its own, stand several up side by side, or bring up everything at once with the latest tag.

labs

:labs

17 Mars-themed labs — one vulnerability class each — plus the Mission Control portal and a CTF scoreboard.

web-pentest

:web-pentest

WebGoat, Juice Shop, the full crAPI stack, Metasploitable2 (DVWA / Mutillidae) and 7 OWASP VWAD apps.

full-appsec

:full-appsec

The AppSec range plus a DevSecOps toolchain: Jenkins, GitLab CE, SonarQube, Trivy and Gitleaks.

netsec

:netsec

An in-network Kali box and classic vulnerable services on a static-IP LAN; opt-in AD, CVE, ICS and VoIP packs.

cloud

:cloud

A LocalStack "AWS": pivot an SSRF to the metadata service, steal credentials, and loot S3 / Secrets Manager.

k8s

:k8s

A single-node k3s cluster: anonymous cluster-admin RBAC, then a privileged / hostPath escape onto the node.

blue

:blue

The defensive range: a Suricata IDS and SOC dashboard replaying attack traffic for you to triage and hunt.

labs

17 focused vulnerability labs

Each lab isolates a single vulnerability class. Exploit it, capture an RP{…} flag, and track your progress on the scoreboard.

5001
phobos-sqli
SQL injection
5002
deimos-xss
Cross-site scripting
5003
ares-cmdi
OS command injection
5004
valles-traversal
Path traversal / LFI
5005
olympus-ssrf
Server-side request forgery
5006
curiosity-ssti
Template injection (Jinja2)
5007
viking-xxe
XML external entity
5008
perseverance-jwt
JWT / broken auth
5009
cydonia-deserialize
Insecure deserialization
5010
tharsis-graphql
GraphQL abuse
5011
elysium-idor
IDOR / BOLA
5012
noctis-proto
Prototype pollution (Node)
5013
arcadia-gauntlet
Multi-vuln chain (CTF)
5014
hellas-upload
Unrestricted file upload → RCE
5015
utopia-cors
CORS misconfiguration
5016
gale-massassign
Mass assignment
5017
jezero-nosqli
NoSQL injection

Codenames follow Mars features, moons and rovers. Static IPs on 10.66.6.0/24; the Mission Control portal at :8000 indexes every target.

Quick start

Everything runs in Docker

One image per range, launched through the Docker socket. The controller starts the range and exits; the range keeps running.

One-liner · installs Docker if missing
curl -sSL https://redplanet.martiandefense.org/install.sh \
  | sudo bash

# choose a range (default: labs)
curl ... | sudo RANGE=full-appsec bash
Already have Docker? Run the image
docker run --rm \
  -v /var/run/docker.sock:/var/run/docker.sock \
  martiandefense/redplanet:labs

# dashboard → http://localhost:8000
# stop: add -e RP_ACTION=down

RANGE = labs · web-pentest · full-appsec · netsec · cloud · k8s · blue · all

Host ports bind to 127.0.0.1 by default. On an isolated lab network, set LISTEN_IP=0.0.0.0 to reach targets from an attacker box.

Safety

Everything here is deliberately insecure

These ranges ship real, exploitable vulnerabilities on purpose. Treat the whole project as hostile code and contain it accordingly.

Run only on an isolated host or a dedicated lab VM — never alongside sensitive data or on a production network.
Keep the default 127.0.0.1 binding unless you fully control the network, and never expose these services to the public internet.
Use RedPlanet for authorized learning only. The techniques you practice here are illegal against systems you do not own or have permission to test.