FREE Cybersecurity Lab for Beginners | Deploy a Firewall + Practice Offensive & Defensive Security

SafeLine Website: https://ly.safepoint.cloud/Z0XMhHq
Documentation: https://docs.waf.chaitin.com/en/home
SafeLine Discord: https://discord.gg/dy3JT7dkmY
Github: https://github.com/chaitin/SafeLine

⚠️ Safety Disclaimer: This video is for educational purposes only. All attacks in this video were performed inside my own lab. Do NOT test or attack any system without explicit permission.

πŸ”₯ In this video, I show you how to build a completely FREE cybersecurity lab that gives you both offensive and defensive hands-on experience.
You’ll deploy Safeline WAF (open-source, free Web Application Firewall), run real web attacks in a safe environment, and learn how to create your own firewall rules β€” perfect for beginners and ideal for building your CV or cybersecurity portfolio.

This lab helps you practice:
βœ… Web attacks (SQLi, XSS, directory traversal, etc.)
βœ… WAF detection & blocking
βœ… Monitoring logs and alerts
βœ… Creating custom security rules
βœ… Red-team + blue-team thinking
All on your own machine, for free.
————————————————————————–
Video Content:
00: 00 – Intro
02: 14 – Setup
03: 11 – Firewall Console
06: 10 – XSS
07: 35 – SQL
08: 30 – Traversal
09: 38 – Lab Summary
————————————————————–
πŸ§ͺ Setup Steps + Commands (Beginner Friendly)

βœ… Step 1 β€” Install Docker on Kali
sudo apt update
sudo apt install docker.io docker-compose-plugin -y
sudo systemctl enable –now docker

βœ… Step 2 β€” Install SafeLine (Official Script)
This creates all containers automatically (pg + mgt + worker).
sudo bash -c “$(curl -fsSLk https://waf.chaitin.com/release/latest/setup.sh)

Follow the prompts. When finished it gives you something like:
Username: admin
Password: xxxxxxxx
URL: https://127.0.0.1: 9443/

Log in to the SafeLine dashboard by visiting this URL and entering the username, password given.

βœ… Step 3 β€” Start a Python Test Web Server
This will be your β€œattacked website.”
(I’VE REMOVED SOME OF THE ANGLED BRACKETS FROM THE COMMANDS BELOW AS DESCRIPTION DOESNT ALLOW IT, SO DOUBLE CHECK YOUR COMMANDS WITH THE VIDEO DEMO)

In a new terminal:
mkdir ~/testweb
cd ~/testweb
echo “h1Hello, Demo Site/h1” index.html
python3 -m http.server 8000

Your test site is now running at:
http://127.0.0.1: 8000

βœ… Step 4 β€” Add an Application in SafeLine WAF
In SafeLine UI β†’ Applications β†’ Add Application
Use this exact setup:

Domain: *
Listening Ports
(Choose only ONE)
Port: 80 HTTP
Delete port 443 if you don’t need HTTPS.
Mode: βœ” Reverse Proxy
Upstream (MOST IMPORTANT):
Set to:
Protocol: HTTP
Host: 127.0.0.1
Port: 8000

Click Save.

Now your WAF listens on: http://127.0.0.1
And forwards traffic to: http://127.0.0.1: 8000

βœ… Step 5 – Simulate web attacks on your demo site:
Go back to your demo site and simulate different web attacks, examples used in the video mentioned below.

———Test Example Attacks (Used in the demo)

πŸ‘‰ XSS:
http://localhost: 7777/?q=scriptalert(1)/script

πŸ‘‰ SQL Injection (even if it’s a static site):
http://localhost: 7777/?id=1′ OR ‘1’=’1

πŸ‘‰ Path Traversal
http://127.0.0.1: 8090/../../etc/passwd

βœ… Step 6 – Check Logs on Safeline WAF
Go back to your WAF Admin Console and check for the logs of your web attacks being blocked.

πŸŽ‰ Done β€” You now have:

βœ” SafeLine WAF installed
βœ” Python test site running
βœ” Reverse proxy protection active
βœ” Attacks being logged

———————————————————————————————

Schedule 1:1 call with me: https://topmate.io/meeratamboli
Connect with me on Linkedin: https://www.linkedin.com/in/meeratamboli
Connect with me on Instagram: https://www.instagram.com/meeratamboli_

Cyber Career Starter Guide – Top 100 Concepts To Learn: https://topmate.io/meeratamboli/1675000?utm_source=public_profile&utm_campaign=meeratamboli
Cybersecurity Roadmap:
Google Cybersecurity Professional Certificate: https://imp.i384100.net/c/6455422/2153398/14726
IBM Cybersecurity Analyst: https://imp.i384100.net/c/6455422/2804776/14726

Fill in this quick form and get my step-by-step roadmap email that breaks it all down, from the fundamentals every beginner must know, to choosing your cyber subdomain, building the right skills and creating a CV that actually gets noticed: https://forms.gle/JH6wZjxVhPyp5vbt5

Hashtags:
#cybersecurity #waf #safeline #xss #sqlinjection #ethicalhacking #websecurity #infosec #pentesting #bugbounty #hackers #devsecops #securitydemo #applicationsecurity

DISCLAIMER: Everything I share here is based on my personal views and experiences, not connected to any employer, role or organisation.