ACKrobatics
The three-way handshake, as a side-scroller.
Open the connection, ride OPEN → PAYLOAD → CLOSE, dodge RST firewalls, filter Martian packets, and land the FIN gate before the RTO runs out.
a networking arcade game
Open the connection → route the payload → close cleanly.
SYN City turns the stuff of networking into an arcade run. You're a packet bouncing across a neon city - beating the retransmit timer, dodging firewalls, and completing handshakes, each level dramatizing a real protocol.

How it plays
Most levels work the same way: your packet waits on a pad, you build send power, and you let go to hop to the next one. Everything else - the timers, the scanners, the hazards - is a networking idea wearing an arcade costume.
Press and hold anywhere to charge the shot. The longer you hold, the farther the packet flies toward the next pad.
Let go to launch. Tilt off a pad's left or right edge to aim your hop backward or forward and recover a missed target.
The retransmit-timeout bar is always draining. Land the next pad before it empties, or the packet is retransmitted and you lose a life.
Hold STEALTH while queued under IDS or MITM sweeps so scanners can't see you, then slip through and reach the FIN gate.
Learn the moves
Levels look wildly different, but they're built from the same handful of moves. Learn these once and you can read any route - every new level just dresses them in a new protocol.
Every pad is a host, and the line of pads is the path your packet takes. Land each hop in order to move forward. The goal sits at the far end - usually a FIN gate, sometimes a themed finish like a restored database or a HOME LAN to park on.
Tap a pad's left or right edge to aim your next hop backward or forward (on vertical climbs it's the upper or lower half). This is how you recover a target you overshot and how you choose a branch when the route forks.
Now and then a pad isn't a jump - it's a job you hold to finish while a meter fills: download and import a backup, fence then resync a split-brain cluster, transfer a DNS zone, or crack a WPA2 handshake. You're stationary and exposed while it fills, so scanners can still catch you mid-action.
Pads that dim to a dashed outline aren't there - you drop straight through them. A cron job outside its window, the wrong DNS view, an encrypted AP you haven't paid for: clear it in a single hop, or spend what it costs to make the road solid.
IDS, MITM and WIDS beams sweep the route. Get caught waiting inside one and you're flagged and knocked back a life. Hold STEALTH to go invisible while a beam passes overhead, then move the instant it clears - but Stealth drains faster, so don't sit in it.
TTL is your lives; the bar that's always draining is the retransmit timer - land the next pad before it empties. Checksum is your score, and clean, on-time landings build a streak multiplier. Each level adds its own gauge on top: a cred wallet, a divergence meter, a "serve this view" prompt.
The route
Each one unlocks the next and rebuilds a different corner of the stack - from the TCP handshake up through VPN tunnels, WAF defense and a stack overflow, to a split-brain failover, a level where every wrong answer is inevitably a DNS problem, a wardrive across the neighbourhood's Wi-Fi, a build you must reproduce bit for bit, a traceroute where you throw the road ahead of yourself, a race against a rising tide of RAM, and a closing volume group grown one extent at a time. Here's what you're getting into.
The three-way handshake, as a side-scroller.
Open the connection, ride OPEN → PAYLOAD → CLOSE, dodge RST firewalls, filter Martian packets, and land the FIN gate before the RTO runs out.
Negotiate a handshake a MITM can't crack.
Advertise modern cipher suites, resist downgrade traps, wait for the certificate VERIFY gate, and complete ephemeral key exchange for Perfect Forward Secrecy - fall once and you lose PFS.
Climb the CAT5 to the switch port.
Follow the cable rope, jump the gaps RJ45 crimpers chomp into it, grab VLAN tags for checksum, and reach LINK UP before the establishment window closes - mind the ARP poisoners.
Six hops, two circuits, zero IPs leaked.
You're an onion packet in three layers of encryption. Fetch the descriptor, plant a secret at the rendezvous, send INTRODUCE1 - then re-wrap at guard relays and reach the hidden .onion service.
Climb the receive path to userspace.
The only vertical level. Ascend from the wire through NIC, driver, IP and TCP up to the app. Green STP ports forward; red ones drop you through. Deliver the payload with recv().
Restore a dead service under a 500 rain.
Hold to download the database backup, carry it across failing pads while 500 errors pour down, jump the I/O ERROR pads before they corrupt it, then import at the restore target.
Get the mail accepted, records and all.
Step through EHLO and STARTTLS, land a valid FQDN, collect floating SPF, DKIM and PTR record coins, then reach 250 QUEUED - while greylists, spambots and the spam filter try to bounce you.
You're the load balancer, not the packet.
A role reversal: drag two backend pads - one per thumb - so falling requests land safely. Round robin takes either; least-connections flips the target. Keep the connection alive to the keepalive.
Boss level. You're an open file handle.
Hold to float the FD up, release to sink. Shred crawls up the lane behind you, BOFH sysadmins hurl chmod/rm/tar from above, stale inodes need a STAT - only fsync() and close() commit you cleanly.
Stage it, commit it, push origin/syn.
Collect file coins, git add and commit them, fork at git branch, survive reverts and squashes, dodge git blame sentinels, jump conflict walls, then push - or it's git reset --hard HEAD.
A random TRUE/FALSE flips gravity.
Follow a bash script toward exit 0 while a boolean flips gravity whenever you're grounded - floor pads one moment, ceiling pads the next. ShellCheck sentinels flip with it; set -e is your RTO.
Time your hops across spinning logs.
No RTO here - just timing. Logfile pads orbit and swipe underfoot while copytruncate crawls in and compression sweeps the queue. Skip up to three bad spins in a row and reach rotate complete.
Pipe the malware to /dev/null.
A rail shooter. Hold and release a full-screen grep-sonar sweep to reveal hidden malware, then quick-tap finite /dev/null ammo to clear each match before the outbreak timer spreads out of control.
Escape the vim-vs-emacs maze.
Run through a scrolling maze. Roaming vim and emacs zealots chase pico home to SYN City. Steer at junctions and HOLD STOP to freeze - releasing scatters them into a clean lane.
Tail the suspect IP, keep your cover.
You're not the packet - you're following it. Shadow the suspect one or two pads back, never landing on its pad, stealthing under ctstate INVALID scans, until it reaches FIN with your cover intact.
A padless rush through the VPN tunnel.
Forward motion is automatic and ramps toward the exit. Hold to rise, release to sink, thread the mssfix/MTU squeeze, and keep tun0 off the walls so MITM probes stay blind until FIN.
Defend the origin at the edge for 60 seconds.
A padless stand at the edge, with traffic raining down from the Internet. Hold to close the WAF and block malicious riff-raff; release to open the gate and let clean GET/POST requests reach the origin. Survive the full RTO, then the availability and security ratios decide whether the origin held.
A vertical memory-corruption climber.
You are the overflow, climbing an unstable stack frame one mapped page at a time. Pages flicker, dangle and get reclaimed under you, ASLR sweeps rebase the upper stack sideways, INFO LEAK freezes the layout just long enough to read it, and a NOP SLED forgives a sloppy landing. The exploit only counts after RET→EIP and JMP ESP - then the payload pops a shell.
Your clock lies. The route keeps time.
A hidden clock skew wanders while you sit queued, and a hot clock drains the real RTO faster than a true one. Resync on stratum servers - centre a stratum-1 landing and it pays a TTL back - hop clean over lying falsetickers, and budget for LEAP SEC pads that swallow 2.2 seconds whole. The final approach narrows onto the smallest pads in SYN City.
The whole route is somebody's crontab.
Every pad is a job that is only solid while its schedule window is open; closed jobs dim to ghosts you fall straight through - or clear in one long hop. Watch the NEXT JOB timer, never park on a job about to exit (cron reaps finished jobs, and you with them), and when an admin opens crontab -e over the route, don't be sitting on a line when the editor saves.
Two nodes both think they're primary. Only one is right.
One lost heartbeat and the cluster splits: a ghost primary starts hopping a mirrored lane above you, happily accepting writes while the divergence meter climbs toward beyond-repair. Skip the DUAL WRITE and STALE LOCK traps, hold FENCE to STONITH the rogue node, hold RESYNC to replay the WAL - and only then touch the VIP. The lease keeps expiring whether you're ready or not.
It's always DNS. This time you're the resolver.
Hold XFER to push the hidden primary's zone to the secondaries, then serve a split-horizon route where every fork randomly demands the INTERNAL row or the EXTERNAL bridge. Read the HUD, press the right channel and arc between the lanes Stack-Mountain style - the view nobody asked for is ghosted, and packets fall straight through it. DNSSEC pads add armour, because the cache-poison scanners overhead are very interested in your answers.
Drive the block. Every Wi-Fi AP is a stretch of road.
A road trip across the neighbourhood's access points. Encrypted APs are un-laid road you fall straight through until you spend a matching key: grab WEP coins in flight, but WPA2 is harder - park on the pad and hold to crack the handshake while WIDS scanners can still see you (MAC-spoof with Stealth if a beam sweeps close). No key means a DEAD END, so reverse to collect what you missed. Jump the captive-portal roadblocks, and park on the HOME LAN to finish the drive.
Same source, same artifact. Now land it twice.
A reproducible build should be exactly that. First the BUILD pass: hop the pipeline from SOURCE to ARTIFACT past pads like SOURCE_DATE_EPOCH, -frandom-seed and tar --sort=name, and every landing is recorded as that step's hash, stamped exactly where you touched down. Reach the artifact and you're flung all the way back to source for the REPRODUCE pass: run it again and land on each recorded hash within a few pixels. Drift too far and the build is non-deterministic. No moving hazards - just you against your own footprints.
The road doesn't exist until you probe it.
A traceroute where holding charges a THROW, not a jump: release and the next pad is flung ahead of you, and you ride the probe onto it in the same motion. You get 29 pads for the whole trace, dealt in frame sizes from jumbo to runt, and the physics is honest - a wide frame catches a greedy throw on its edge, a runt forgives nothing. Throw past the gold ring and the auto-jump can't reach the pad at all: that probe answers * * *, and it's still spent. Short-hop the budget away and the trace strands at !H max hops exceeded. Packet-loss sweeps drop probes that loiter, every landed hop prints its traceroute line with an RTT, and dst.syn.city answers the final probe - the only free one - with an ECHO REPLY.
The waterline is the clock.
Your process gets 256 MiB and the heap only grows: a tide of allocated RAM rises from below, and touching it is an OOM kill. It reaches the low pads long before the meter reads 100%, so the route climbs - and so should you. Violet SWAP pads teleport you fore or aft like the wire's NAT rewrites and free pages off the tide either way, but the swap itself is a disk-thrash freeze you can't jump out of while the oom reaper sweeps overhead. Red pads leak, filling RAM twice as fast while you stand on them; free() pickups reclaim pages mid-flight; and faint use-after-free echoes of your earlier jumps trail you the whole way. Reach exit(0) before the water does.
Grow the road. Pay in extents.
The route is a volume group and you are its allocator: flex sets how FAR the next pad lands and how BIG it grows, billed in physical extents from one shared pool. Bigger volumes travel further per extent, so greed is the efficient strategy - right up to the gold ring, where the auto-jump stops reaching the centre and your own grown width has to catch you at the edge. Miss, and the extents are orphaned with the I/O error. Spend the pool short of /dev/vg/root and it's insufficient free extents - run over. Stand still on a fresh volume to fstrim a refund back, if you can spare the journal timer with fsck sweeping overhead, and grab pvcreate disks for bonus extents. The final hop onto the mount point costs nothing.
No install, no account. It runs in any modern browser and installs as an app if you want it on your phone.
Play SYN City freeTip: on mobile, use “Add to Home Screen” to play offline.