TAKE CONTROL.
SECURE THE BRIDGE.
Run the website and Rust CLI bridge on your own Kali Linux host, then access it from a trusted browser on the same network or in your Tailscale tailnet.
One Kali host. Browser-controlled jobs.
The all-in-one Node web server serves the UI, manages authenticated sessions, accepts challenge artifacts and starts the installed WROSECODE native CLI as a child process. Events are streamed over Server-Sent Events (SSE). This package does not modify the WROSECODE Rust repository.
Start on Kali Linux.
Transfer the ZIP archive to Kali, extract it, open the resulting WROSECODE-Web-Console folder and confirm that WROSECODE is installed and working. Requires Node.js 22.13 or newer.
node --version
wrosecode --version
wrosecode providers list
cp .env.example .env
# Edit .env to set:
# BRIDGE_MODE=cli
# WROSECODE_BIN=/absolute/path/to/wrosecode
node --env-file=.env server/server.mjsDefault local access URL: http://127.0.0.1:8787. The backend is disabled until you explicitly set BRIDGE_MODE=cli. BRIDGE_MODE=mock is for demos only.
Create the first account.
Run this in the extracted folder before launching the server. Choose a unique password of 12 or more characters.
read -rp "Admin email: " ADMIN_EMAIL
read -rsp "Admin password (12+ chars): " ADMIN_PASSWORD; echo
export ADMIN_EMAIL ADMIN_PASSWORD
node --env-file=.env scripts/create-admin.mjs
unset ADMIN_EMAIL ADMIN_PASSWORDThen open /login.html. Passwords use salted scrypt hashes in a local SQLite database. Session tokens are HttpOnly cookies, and tasks are owner-only by default.
Choose a LAN IP and port.
Find Kali's LAN address (example only: 192.168.1.50). To serve devices on the same network, set HOST=0.0.0.0, PORT=8787 and PUBLIC_BASE_URL=http://192.168.1.50:8787 in .env. Restart the server.
hostname -I
# Sample .env values (replace with the REAL Kali LAN IP):
HOST=0.0.0.0
PORT=8787
PUBLIC_BASE_URL=http://192.168.1.50:8787
BRIDGE_MODE=cliConnect through Tailscale.
On Kali, install and log in to Tailscale. Use a loopback-only backend; let Tailscale Serve provide encrypted HTTPS for devices authorized on the same tailnet. You do not need a public port-forward.
sudo tailscale up
# .env on Kali:
HOST=127.0.0.1
PORT=8787
# Set PUBLIC_BASE_URL to the exact HTTPS URL shown by Tailscale Serve
node --env-file=.env server/server.mjs
# In another terminal:
tailscale serve --bg 8787
tailscale serve statusCopy the actual https://your-kali.your-tailnet.ts.net URL from the status output into PUBLIC_BASE_URL and restart the Node server. Users must be allowed into your tailnet. Tailscale Funnel is different: it exposes a service publicly and is not recommended for a CLI execution server.
Enable Google and GitHub.
Create your own OAuth apps and configure the credentials in Kali's private .env. The login page shows the buttons, but they only activate when both client ID and secret are configured. For an existing email/password account, sign in first and use the AI providers page to explicitly link your Google/GitHub identity. Email/password registration does not verify inbox ownership and requires careful owner review. Register these exact redirect URIs with the providers:
https://your-kali.your-tailnet.ts.net/api/oauth/google/callback
https://your-kali.your-tailnet.ts.net/api/oauth/github/callbackGOOGLE_CLIENT_ID=your_google_client_id
GOOGLE_CLIENT_SECRET=your_google_client_secret
GITHUB_CLIENT_ID=your_github_client_id
GITHUB_CLIENT_SECRET=your_github_client_secretGoogle may impose domain verification, test-user and OAuth consent restrictions. A private tailnet URL is not guaranteed to be accepted as an authorized Google redirect domain; a managed public HTTPS domain may be required. Keep all client secrets on the server.
Decide who can execute.
Set SIGNUP_MODE=open only if you want visitors to register. Accounts are initially pending. The owner can approve or revoke them from Access control in the console. Approval by itself does not allow them to execute the host CLI: that is deliberately restricted to the owner.
Separate marketing from execution.
You can host the static homepage, screenshots and CLI documentation on Cloudflare Pages. The authenticated console API and native Rust subprocesses require a live Kali/server runtime, and the console pages must connect to that API on a compatible HTTPS origin. Simply uploading the ZIP to Pages does not create a functioning backend.
Read before deployment.
Challenge files are untrusted. Avoid running untrusted binaries or macros without a proper sandbox. The bridge limits upload size and job count, records task events, checks authentication and login origin, and never exposes stored provider credentials intentionally. It is not a hardened multi-tenant platform. CTF patterns are unverified candidates until an authorized challenge authority validates them.
Live CLI compatibility and provider functionality must be checked against your installed WROSECODE version using wrosecode --help, wrosecode ctf --help and wrosecode providers list.
