Acceptable use policy
Pebble Labs gives you administrative access to live virtual machines in our cloud account, reachable over a VPN tunnel into a private network. This page sets out what you may attack, what you may not, and what happens if you cross the line. It forms part of the user agreement.
What is in scope
Every deploy builds its own isolated network in our cloud account, dedicated to you for as long as that lab runs. The machines and subnets shown in that lab's topology are your target. You may attack them by any means the lab permits: exploit them, escalate on them, move between them, break them, and reset them as often as you like.
Nothing else on our infrastructure is in scope. The boundary is the lab network you deployed, not the account it happens to run in.
What is out of scope
Do not attack, probe, or attempt to gain access to:
- The Pebble Labs web application, its database, its authentication, or the accounts of other users.
- The VPN gateway itself, the provisioning system that builds labs, the machine image catalog, or anything in our cloud account outside your own lab network.
- Another customer's lab. Labs are isolated from each other, and attempting to reach one is a breach whether or not it works.
- Any host on the public internet. A lab is a closed environment and is not a launch point.
If you find a flaw in the platform itself, we want to hear about it. Report it to [TO BE COMPLETED] rather than exploiting it, and we will not pursue you for finding it in good faith. Continuing past proof of the flaw, taking other people's data, or degrading the service for anyone else takes it outside that protection.
Egress and the outside world
Most lab machines have no general internet access. Where a lab grants one outbound connectivity, it is limited to a few protocols, and the traffic is translated through your lab gateway, which applies its own allow-list on top. Defeating either is a breach of this policy, even from a machine you have legitimately compromised.
Some labs include an internet-facing machine, because the attack path being taught begins on the public side. That machine has a real public address, is reachable from the internet on the ports the lab exposes, and routes outward directly rather than through the gateway. Its address is shown on the lab page, so you can always tell which of your machines this applies to. Less sits between it and the outside world than between any other machine and the outside world, which makes the rule below the thing keeping it in bounds rather than the network.
Concretely, do not use any lab machine to scan, attack, relay traffic to, or host anything for a system outside your own lab. That includes using one as a proxy, an exit node, a command-and-control host for real operations, or a staging point for a live engagement. This holds whatever the network in front of you happens to permit.
What lab machines are not for
Compute in a lab is for working the lab. Do not use it for cryptocurrency mining, distributed computing for hire, sending mail, hosting a service, or storing material unrelated to the exercise. Do not store anything on a lab machine that is illegal to possess, and do not upload personal data belonging to anyone else.
Some labs give a machine access to a hosted AI model, metered against the credit allowance shown on the lab page. That access exists so the lab works. Draining it on unrelated work is misuse of the lab, not clever budgeting.
Your VPN profile and your account
Your VPN profile is one permanent file, issued against a certificate authority that exists only for you. It reaches your labs and nobody else's. Treat it the way you would treat a password: do not share it, publish it, or commit it to a repository. If a copy escapes, regenerate it from your account page. Regenerating is what revokes the old one, and it takes effect everywhere the old file was copied.
Your account is for you. Do not share credentials or let another person work labs under your subscription. One person, one account.
Solutions and spoilers
Do not publish flags. Do not publish a step-by-step walkthrough of a lab that is currently on the platform, whether as text, video, or a repository of scripts. Labs take a long time to build and a published solution set retires one for everybody.
Writing about what you learned is welcome, and so is discussing technique. The line is whether someone could follow your work to the flags without doing the lab. If we retire a lab, that line goes with it.
Conduct in shared spaces
Some parts of the service are shared with other people: our support email, and any community channels we run, such as Discord. In them, behave like a professional. Harassment, threats, hate speech, spam, and deliberately disrupting other people's use of a channel are not allowed, and neither is posting flags or walkthroughs the section above rules out. We may remove your access to a channel, or suspend your account, for any of these. This is the one place the rest of this policy does not reach: aggression toward a lab target is the point, aggression toward a person is not.
Outside the platform
What you learn here works on systems that are not ours. Using it against a system you do not own or have written permission to test is a crime in most countries, and it is not something we can authorize. Your account with us is not authorization for anything beyond your own labs.
If you break these rules
Depending on what happened, we may suspend your labs, suspend or close your account, revoke your VPN profile, or refuse to serve you in future. For anything that damages other customers or breaks the law, we will also preserve the relevant logs and cooperate with law enforcement.
We would rather ask first. If something you want to try sits near one of these lines, write to [TO BE COMPLETED] and ask.