CyberLab

Terms · CyberLab

Terms of Use and Acceptable Use Policy

The rules for using the copy of CyberLab that CyberLab runs: what you may do in the labs, what you may not, and what happens if the rules are broken.

Effective date:
September 13, 2026
Operated by:
CyberLab
Contact:
not set yet (Admin → Global Settings → Email)
This instance runs in:
School Mode

Please read this first

By signing in, joining a class or starting a lab you agree to these terms. If you do not agree, do not use the platform.

If your account was created by your school, the school has accepted these terms for its students and its own rules of conduct apply as well.

The labs teach techniques that are crimes when used against systems you are not allowed to touch. These terms exist to keep what you learn here inside the lab and inside the law.

01What CyberLab is

CyberLab is software that CyberLab runs on its own server. It provides written lectures with graded quizzes, hands-on labs that run in isolated containers in your browser, guided simulations, classrooms for instructors, and written exams. It is an educational sandbox: a place to practise attacking and defending systems that were built to be attacked.

In these terms, "we" and "the operator" mean CyberLab. "You" means anyone with an account here or anyone using the public pages.

02Accounts

2.1 — Student accounts in School Mode

  • Your school creates your account and gives you a username and a one-time password, usually on a printed slip. The account belongs to the school; it may reset it, suspend it, or close it, and it stops working after your last class term ends plus a grace period.
  • Change the one-time password the first time you sign in, keep the new one to yourself, and tell your instructor at once if you think someone else has used your account.
  • Do not sign in as anyone else, and do not share class join codes outside the class they were given to.

2.2 — Instructors and staff

  • Instructors handle other people's data: class lists they import, credential slips they print, answers they mark, reports they export. They must have the right to use that data here, keep credential slips and exports safe, and use them only to run their classes.
  • Content an instructor uploads (slides, documents, exam questions, imported question files) must be theirs to use. Instructors decide whether the AI assistant, hints and the leaderboard are available in their classes, within what the administrator allows.
  • Administrators configure the instance and can see everything on it; they are bound by these terms and by the Privacy Policy in what they do with that access.

03Acceptable use

3.1 — Education only

Everything you learn here, offensive and defensive, is provided for education. You will use it only for lawful, authorised purposes: your coursework, defending systems you are responsible for, and testing you have explicit written permission to perform. The fact that a technique is taught here does not make it lawful anywhere else and is not permission to use it against any real target.

3.2 — Authorised targets only

You may use the tools and techniques on this platform only against:

  1. the lab targets and challenges this platform provides for the lab you are running, and
  2. systems you have separate, explicit, written authorisation to test.

Never against classmates, the school's network, this platform, or anything on the public internet.

3.3 — Stay inside the sandbox

  • Do not try to escape your lab container or reach the server underneath it.
  • Do not access, attack or disrupt other people's containers, sessions, accounts, submissions or exams.
  • Do not attack, probe or try to bypass the platform itself: sign-in, the CAPTCHA, the exam timer and attempt limits, the terminal service, the sync and administrative interfaces, or the hint and flag checks.
  • Do not scan or send unsolicited traffic to hosts on the school network or the internet from inside a lab, unless the lab itself tells you to and provides the target.

3.4 — Fair use of shared resources

  • Labs are for coursework. No cryptocurrency mining, file sharing, bulk scraping, denial-of-service traffic, or anything unrelated to the lab.
  • Do not try to exceed or work around the memory, time and concurrent-lab limits the administrator has set. Stop a lab when you are done so that others can start theirs.

3.5 — Conduct

  • Messages, lecture comments, tickets and the public meeting form are for civil communication. No harassment, threats, hate speech or abuse.
  • Do not upload or share malware, unlawful content, or material you have no right to share. Handling a sample provided by a lab, inside its sandbox, is part of the course; taking it anywhere else is not.

3.6 — Academic integrity

  • Do not share, post or sell flags, quiz answers, exam questions or write-ups for graded work unless your instructor says you may.
  • Quizzes and exams are your own work, completed with only the aids your instructor allows. Attempt limits and timers are part of the assessment; working around them is cheating.

3.7 — The AI assistant

  • Where an administrator has enabled it, the assistant sends your question and the relevant lecture or lab text to an outside AI provider. Do not paste personal data, credentials or anything confidential into it.
  • Its answers can be wrong. They are study help, not a source of truth, not an authorisation for anything, and not a substitute for your own work where your instructor has ruled it out.

04The law

You must comply with the computer-misuse and data-protection laws that apply where you are and where this server is, and with your school's own policies on information technology and conduct. In most countries, accessing, altering or disrupting a computer, network or data without authorisation is a criminal offence; in the United States, for example, under the Computer Fraud and Abuse Act and state equivalents. Nothing on this platform authorises you to do any of that anywhere but inside the lab you were given.

05Content and ownership

  • Platform content: lectures, labs, simulations, campaigns and the platform itself belong to CyberLab or its licensors and are provided for your personal study. Do not copy or redistribute them outside the platform without permission.
  • Your work: what you write in answers, comments, messages and tickets stays yours. You allow CyberLab to store it and show it to the people section 04 of the Privacy Policy describes, so that the platform can work.
  • Instructor material: exam questions, question banks, slides and documents an instructor uploads remain the instructor's or the school's. Students may use them for the course and nothing else.
  • Certificates carry your name and the class name and can be verified by anyone who has the certificate's link.

06Privacy

What is collected, who can see it, when it leaves the server and how long it is kept is set out in the Privacy Policy, written from this instance's own configuration. By using the platform you acknowledge that you have read it.

07Availability and liability

  • The platform is provided as it is, for education, without any warranty. It may be taken down for maintenance, a lab may fail to start, and a container is destroyed when its session ends. Keep copies of anything you cannot afford to lose.
  • To the extent the law allows, CyberLab and its staff are not liable for loss or damage arising from your use of the platform, and not at all for what you do with skills learned here outside the authorised environment. That responsibility is yours.

08Monitoring and enforcement

Activity on the platform is recorded for security and to run classes: sign-ins, lab sessions, submissions, exam attempts and administrative actions, as the Privacy Policy describes. Breaking these terms can lead to any of the following:

  • Losing a lab session, an exam attempt or class access.
  • Suspension or closure of your account by an administrator.
  • Referral to your school's disciplinary process under its own rules.
  • Referral to law enforcement where a crime appears to have been committed.

09Changes to these terms

The date at the top says when this text last changed. Material changes will be announced inside the platform, and continuing to use it afterwards means you accept them. An administrator can replace this page with the school's own terms.

10Contact

Questions about these terms: CyberLab, the support address shown at the top of this page once the administrator sets it.

Technical help: sign in and open a support ticket.

This document is effective as of September 13, 2026. It describes how this copy of CyberLab, run by CyberLab, is configured and behaves; it is provided for review by your school and is not legal advice.