Know the bug before you hunt it
A short read on each class of vulnerability — what it is, how you approach it, how it gets fixed — with the labs that drill it one click away.
Understanding Broken access control / IDOR
Reach an object that was never yours by changing the id that names it.
Read →Authentication bypassUnderstanding Authentication bypass
Get past the login without the credential it is supposed to demand.
Read →Cross-site scripting (XSS)Understanding Cross-site scripting
Get your script to run in another visitor's browser on this origin.
Read →Server-side request forgery (SSRF)Understanding Server-side request forgery
Make the server fetch a URL of your choosing, from inside its network.
Read →SQL / command injectionUnderstanding SQL / command injection
Break out of a query or a shell command through unescaped input.
Read →Insecure deserializationUnderstanding Insecure deserialization
Feed the server a serialized object it will trust and rebuild.
Read →CSRFUnderstanding CSRF
Make a logged-in victim's browser send a state-changing request.
Read →Information disclosureUnderstanding Information disclosure
Find the secret the application leaks without meaning to.
Read →Business logic flawUnderstanding Business logic flaw
Use the feature exactly as built, in an order it never anticipated.
Read →Cryptographic weaknessUnderstanding Cryptographic weakness
Break the guarantee a weak or misused primitive was meant to give.
Read →Race conditionUnderstanding Race condition
Slip through the window between a check and the action it guards.
Read →Subdomain takeoverUnderstanding Subdomain takeover
Claim a dangling DNS record that points at an unclaimed host.
Read →Remote code executionUnderstanding Remote code execution
Turn a foothold into commands running on the server itself.
Read →Privilege escalationUnderstanding Privilege escalation
Climb from the access you were given to access you were not.
Read →