Academy · Labs

The Lab Universe

Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.

111
labs
Difficulty
Category
Track
ApprenticeInformation disclosure

A backup file left in the web root

Find the secret the application leaks without meaning to.

10 pts · 20 minStart →
ApprenticeAuthentication bypass

A login that leaks which half was wrong

Get past the login without the credential it is supposed to demand.

10 pts · 20 minStart →
ApprenticeBusiness logic flaw

A negative quantity at checkout

Use the feature exactly as built, in an order it never anticipated.

10 pts · 20 minStart →
ApprenticeBusiness logic flaw

A price that travels in the request

Use the feature exactly as built, in an order it never anticipated.

10 pts · 20 minStart →
ApprenticeSQL / command injection

A quote that breaks the login query

Break out of a query or a shell command through unescaped input.

10 pts · 20 minStart →
ApprenticeCSRF

Changing an email with a single GET

Make a logged-in victim's browser send a state-changing request.

10 pts · 20 minStart →
ApprenticeInformation disclosure

Comments in the source with a key in them

Find the secret the application leaks without meaning to.

10 pts · 20 minStart →
ApprenticeBroken access control / IDOR

Reading another user's support tickets

Reach an object that was never yours by changing the id that names it.

10 pts · 20 minStart →
ApprenticeCross-site scripting (XSS)

Reflected in the search box

Get your script to run in another visitor's browser on this origin.

10 pts · 20 minStart →
ApprenticeAuthentication bypass

The default credential nobody changed

Get past the login without the credential it is supposed to demand.

10 pts · 20 minStart →
ApprenticeCross-site scripting (XSS)

The error page that echoes your input

Get your script to run in another visitor's browser on this origin.

10 pts · 20 minStart →
ApprenticeBroken access control / IDOR

The invoice with your neighbour's name on it

Reach an object that was never yours by changing the id that names it.

10 pts · 20 minStart →
ApprenticeBroken access control / IDOR

The order history one id away

Reach an object that was never yours by changing the id that names it.

10 pts · 20 minStart →
ApprenticeSQL / command injection

The search filter that trusts your input

Break out of a query or a shell command through unescaped input.

10 pts · 20 minStart →
ApprenticeInformation disclosure

The stack trace that names the database

Find the secret the application leaks without meaning to.

10 pts · 20 minStart →
PractitionerSubdomain takeover

A CNAME pointing at a deleted bucket

Claim a dangling DNS record that points at an unclaimed host.

25 pts · 45 minStart →
PractitionerCross-site scripting (XSS)

A comment field that renders markdown too eagerly

Get your script to run in another visitor's browser on this origin.

25 pts · 45 minStart →
PractitionerPrivilege escalation

A hidden form value that grants admin

Climb from the access you were given to access you were not.

25 pts · 45 minStart →
PractitionerCSRF

A JSON endpoint that accepts form content-type

Make a logged-in victim's browser send a state-changing request.

25 pts · 45 minStart →
PractitionerCryptographic weakness

A password-reset token you can predict

Break the guarantee a weak or misused primitive was meant to give.

25 pts · 45 minStart →
PractitionerInsecure deserialization

A serialized cart the client can edit

Feed the server a serialized object it will trust and rebuild.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

A webhook tester pointed at localhost

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerCryptographic weakness

An ECB-mode image that leaks its shape

Break the guarantee a weak or misused primitive was meant to give.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

An image importer aimed inward

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerBusiness logic flaw

Applying the same coupon twice

Use the feature exactly as built, in an order it never anticipated.

25 pts · 45 minStart →
PractitionerCross-site scripting (XSS)

Breaking out of an HTML attribute

Get your script to run in another visitor's browser on this origin.

25 pts · 45 minStart →
PractitionerBroken access control / IDOR

Deleting a comment you did not write

Reach an object that was never yours by changing the id that names it.

25 pts · 45 minStart →
PractitionerBroken access control / IDOR

Editing a profile that is not yours

Reach an object that was never yours by changing the id that names it.

25 pts · 45 minStart →
PractitionerSQL / command injection

Error-based extraction from a chatty endpoint

Break out of a query or a shell command through unescaped input.

25 pts · 45 minStart →
PractitionerRace condition

Redeeming a one-time code twice

Slip through the window between a check and the action it guards.

25 pts · 45 minStart →
PractitionerRace condition

Registering the same username twice

Slip through the window between a check and the action it guards.

25 pts · 45 minStart →
PractitionerInformation disclosure

Secrets committed to an exposed .git

Find the secret the application leaks without meaning to.

25 pts · 45 minStart →
PractitionerAuthentication bypass

Skipping the second step of a two-step login

Get past the login without the credential it is supposed to demand.

25 pts · 45 minStart →
PractitionerCross-site scripting (XSS)

Stored in a display name

Get your script to run in another visitor's browser on this origin.

25 pts · 45 minStart →
PractitionerInformation disclosure

The debug endpoint still answering in production

Find the secret the application leaks without meaning to.

25 pts · 45 minStart →
PractitionerBroken access control / IDOR

The export endpoint that forgot to ask who is asking

Reach an object that was never yours by changing the id that names it.

25 pts · 45 minStart →
PractitionerCSRF

The form with no anti-forgery token

Make a logged-in victim's browser send a state-changing request.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

The link-preview that fetches anything

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerSubdomain takeover

The pages site that was never published

Claim a dangling DNS record that points at an unclaimed host.

25 pts · 45 minStart →
PractitionerAuthentication bypass

The remember-me cookie that means too much

Get past the login without the credential it is supposed to demand.

25 pts · 45 minStart →
PractitionerPrivilege escalation

The role field the client should not set

Climb from the access you were given to access you were not.

25 pts · 45 minStart →
PractitionerInsecure deserialization

The role hidden in a base64 cookie

Feed the server a serialized object it will trust and rebuild.

25 pts · 45 minStart →
PractitionerSQL / command injection

UNION-selecting the users table

Break out of a query or a shell command through unescaped input.

25 pts · 45 minStart →
PractitionerInformation disclosure

User enumeration through timing

Find the secret the application leaks without meaning to.

25 pts · 45 minStart →
PractitionerBusiness logic flaw

Voting more than once by replaying the request

Use the feature exactly as built, in an order it never anticipated.

25 pts · 45 minStart →
ExpertRemote code execution

A file type check you can talk past

Turn a foothold into commands running on the server itself.

50 pts · 90 minStart →
ExpertBroken access control / IDOR

A GUID is not an authorization check

Reach an object that was never yours by changing the id that names it.

50 pts · 90 minStart →
ExpertCryptographic weakness

A length-extension against a naive MAC

Break the guarantee a weak or misused primitive was meant to give.

50 pts · 90 minStart →
ExpertAuthentication bypass

A password reset that trusts the wrong field

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertPrivilege escalation

An admin route that never re-checks

Climb from the access you were given to access you were not.

50 pts · 90 minStart →
ExpertInformation disclosure

An API version that forgot to retire

Find the secret the application leaks without meaning to.

50 pts · 90 minStart →
ExpertSubdomain takeover

An expired CDN configuration still referenced

Claim a dangling DNS record that points at an unclaimed host.

50 pts · 90 minStart →
ExpertPrivilege escalation

An invite flow that leaks a higher role

Climb from the access you were given to access you were not.

50 pts · 90 minStart →
ExpertAuthentication bypass

An OAuth state parameter nobody validates

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertRemote code execution

An upload that lands in an executable path

Turn a foothold into commands running on the server itself.

50 pts · 90 minStart →
ExpertRace condition

Applying two coupons in the same instant

Slip through the window between a check and the action it guards.

50 pts · 90 minStart →
ExpertPrivilege escalation

Approving your own request as its reviewer

Climb from the access you were given to access you were not.

50 pts · 90 minStart →
ExpertRace condition

Beating a rate limit with concurrency

Slip through the window between a check and the action it guards.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Blind SSRF confirmed out of band

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertSQL / command injection

Boolean-blind, one bit at a time

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Bypassing an allowlist with a DNS trick

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertCSRF

Defeating a predictable token

Make a logged-in victim's browser send a state-changing request.

50 pts · 90 minStart →
ExpertCross-site scripting (XSS)

DOM XSS through the URL fragment

Get your script to run in another visitor's browser on this origin.

50 pts · 90 minStart →
ExpertInformation disclosure

GraphQL introspection left switched on

Find the secret the application leaks without meaning to.

50 pts · 90 minStart →
ExpertCross-site scripting (XSS)

Injecting into a JSON block the page evaluates

Get your script to run in another visitor's browser on this origin.

50 pts · 90 minStart →
ExpertBroken access control / IDOR

Mass-assigning your way into an admin group

Reach an object that was never yours by changing the id that names it.

50 pts · 90 minStart →
ExpertInformation disclosure

Metadata in an uploaded file's response

Find the secret the application leaks without meaning to.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Reaching the cloud metadata endpoint

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertBusiness logic flaw

Referral rewards that pay you to invite yourself

Use the feature exactly as built, in an order it never anticipated.

50 pts · 90 minStart →
ExpertAuthentication bypass

Reusing a magic link that never expired

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertCSRF

SameSite is not set, and it matters

Make a logged-in victim's browser send a state-changing request.

50 pts · 90 minStart →
ExpertSQL / command injection

Second-order injection through a stored value

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
ExpertBusiness logic flaw

Skipping the payment step of the order

Use the feature exactly as built, in an order it never anticipated.

50 pts · 90 minStart →
ExpertCross-site scripting (XSS)

Slipping past a naive filter

Get your script to run in another visitor's browser on this origin.

50 pts · 90 minStart →
ExpertCryptographic weakness

Swapping a JWT to the 'none' algorithm

Break the guarantee a weak or misused primitive was meant to give.

50 pts · 90 minStart →
ExpertInsecure deserialization

Tampering with a signed-but-unverified token

Feed the server a serialized object it will trust and rebuild.

50 pts · 90 minStart →
ExpertSubdomain takeover

The cancelled SaaS that left a dangling record

Claim a dangling DNS record that points at an unclaimed host.

50 pts · 90 minStart →
ExpertCryptographic weakness

The JWT signed with a guessable secret

Break the guarantee a weak or misused primitive was meant to give.

50 pts · 90 minStart →
ExpertBroken access control / IDOR

The nested resource that skipped its parent's check

Reach an object that was never yours by changing the id that names it.

50 pts · 90 minStart →
ExpertSQL / command injection

Time-based extraction from a silent endpoint

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
ExpertInsecure deserialization

Type confusion in a rebuilt object

Feed the server a serialized object it will trust and rebuild.

50 pts · 90 minStart →
ExpertBusiness logic flaw

Upgrading a plan without paying the difference

Use the feature exactly as built, in an order it never anticipated.

50 pts · 90 minStart →
ExpertRace condition

Withdrawing a balance in parallel

Slip through the window between a check and the action it guards.

50 pts · 90 minStart →
MasterRemote code execution

A dependency confusion package that runs on install

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterInsecure deserialization

A gadget chain to state change

Feed the server a serialized object it will trust and rebuild.

100 pts · 180 minStart →
MasterCryptographic weakness

A padding oracle that reads the ciphertext

Break the guarantee a weak or misused primitive was meant to give.

100 pts · 180 minStart →
MasterPrivilege escalation

A support-impersonation feature turned on yourself

Climb from the access you were given to access you were not.

100 pts · 180 minStart →
MasterRace condition

A TOCTOU gap in a file upload

Slip through the window between a check and the action it guards.

100 pts · 180 minStart →
MasterRemote code execution

Argument injection into a called binary

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterBusiness logic flaw

Assembling a discount no single rule forbids

Use the feature exactly as built, in an order it never anticipated.

100 pts · 180 minStart →
MasterSubdomain takeover

Chaining a takeover into cookie theft

Claim a dangling DNS record that points at an unclaimed host.

100 pts · 180 minStart →
MasterBroken access control / IDOR

Chaining two objects into a full account read

Reach an object that was never yours by changing the id that names it.

100 pts · 180 minStart →
MasterSQL / command injection

Command injection through a filename

Break out of a query or a shell command through unescaped input.

100 pts · 180 minStart →
MasterRace condition

Double-spend across two endpoints at once

Slip through the window between a check and the action it guards.

100 pts · 180 minStart →
MasterCryptographic weakness

Forging a session from a leaked signing key

Break the guarantee a weak or misused primitive was meant to give.

100 pts · 180 minStart →
MasterAuthentication bypass

Forging the 'already verified' state

Get past the login without the credential it is supposed to demand.

100 pts · 180 minStart →
MasterRemote code execution

From deserialization gadget to shell

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterInsecure deserialization

From deserialization to file write

Feed the server a serialized object it will trust and rebuild.

100 pts · 180 minStart →
MasterServer-side request forgery (SSRF)

Gopher-smuggling a request to an internal service

Make the server fetch a URL of your choosing, from inside its network.

100 pts · 180 minStart →
MasterPrivilege escalation

Horizontal to vertical in two steps

Climb from the access you were given to access you were not.

100 pts · 180 minStart →
MasterPrivilege escalation

Inheriting permissions through a group you joined

Climb from the access you were given to access you were not.

100 pts · 180 minStart →
MasterCSRF

Login CSRF into an attacker's account

Make a logged-in victim's browser send a state-changing request.

100 pts · 180 minStart →
MasterCross-site scripting (XSS)

Mutation XSS the sanitiser did not expect

Get your script to run in another visitor's browser on this origin.

100 pts · 180 minStart →
MasterCryptographic weakness

Nonce reuse that unwinds the keystream

Break the guarantee a weak or misused primitive was meant to give.

100 pts · 180 minStart →
MasterSQL / command injection

Reading files through the database engine

Break out of a query or a shell command through unescaped input.

100 pts · 180 minStart →
MasterServer-side request forgery (SSRF)

Redirect-hopping into a private range

Make the server fetch a URL of your choosing, from inside its network.

100 pts · 180 minStart →
MasterBusiness logic flaw

Refunding more than you paid

Use the feature exactly as built, in an order it never anticipated.

100 pts · 180 minStart →
MasterSQL / command injection

Stacking queries to write, not just read

Break out of a query or a shell command through unescaped input.

100 pts · 180 minStart →
MasterCross-site scripting (XSS)

Stealing a session under a weak CSP

Get your script to run in another visitor's browser on this origin.

100 pts · 180 minStart →
MasterRemote code execution

Template injection to command execution

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterRemote code execution

XXE escalated to a file read and beyond

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →