Academy · Labs

The Lab Universe

Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.

8
labs
Difficulty
Category
Track
PractitionerCryptographic weakness

A password-reset token you can predict

Break the guarantee a weak or misused primitive was meant to give.

25 pts · 45 minStart →
PractitionerCryptographic weakness

An ECB-mode image that leaks its shape

Break the guarantee a weak or misused primitive was meant to give.

25 pts · 45 minStart →
ExpertCryptographic weakness

A length-extension against a naive MAC

Break the guarantee a weak or misused primitive was meant to give.

50 pts · 90 minStart →
ExpertCryptographic weakness

Swapping a JWT to the 'none' algorithm

Break the guarantee a weak or misused primitive was meant to give.

50 pts · 90 minStart →
ExpertCryptographic weakness

The JWT signed with a guessable secret

Break the guarantee a weak or misused primitive was meant to give.

50 pts · 90 minStart →
MasterCryptographic weakness

A padding oracle that reads the ciphertext

Break the guarantee a weak or misused primitive was meant to give.

100 pts · 180 minStart →
MasterCryptographic weakness

Forging a session from a leaked signing key

Break the guarantee a weak or misused primitive was meant to give.

100 pts · 180 minStart →
MasterCryptographic weakness

Nonce reuse that unwinds the keystream

Break the guarantee a weak or misused primitive was meant to give.

100 pts · 180 minStart →