FAQ

Frequently asked questions

The short answers. Still stuck? Ask in Discord.

  • Is RedSec really free?
    Yes — completely. No accounts, no paywalls, no premium tier, and no ads. RedSec is open source on GitHub.
  • Do I need an account?
    No. There's no login, signup, or profile anywhere on RedSec. Open a page and start reading — that's the whole point.
  • Where are the lessons and learning content?
    On the learning platform at learn.redsec.cc. It's organized like documentation — sections for CTFs, bug bounties, and finding vulnerabilities. This site (redsec.cc) is the front door.
  • Is any of this legal? Can I use these techniques anywhere?
    The techniques are real and intended for authorized testing and education only. Only ever use them on systems you own or have explicit, written permission to test. Practice on intentionally-vulnerable targets and CTFs.
  • Do you track me or use cookies?
    No. RedSec sets no cookies, ships no analytics, and makes no third-party requests. On the learning site, any progress is stored only in your own browser (localStorage) and never leaves your device.
  • I'm a complete beginner — where do I start?
    Head to Getting started on the learning site, set up a practice environment, then pick the track that interests you: CTFs, bug bounties, or finding vulnerabilities.
  • How can I contribute?
    RedSec is open source — open an issue or pull request on GitHub to suggest lessons, fix mistakes, or add new sections. New contributors are welcome.
  • How do I join the community?
    Jump into our Discord. It's the best place to ask questions, share writeups, and hang out with other learners.
  • How do I report a problem with the site or content?
    Open an issue on GitHub or let us know in Discord.