Academy · Labs

The Lab Universe

Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.

10
labs
Difficulty
Category
Track
ApprenticeSQL / command injection

A quote that breaks the login query

Break out of a query or a shell command through unescaped input.

10 pts · 20 minStart →
ApprenticeSQL / command injection

The search filter that trusts your input

Break out of a query or a shell command through unescaped input.

10 pts · 20 minStart →
PractitionerSQL / command injection

Error-based extraction from a chatty endpoint

Break out of a query or a shell command through unescaped input.

25 pts · 45 minStart →
PractitionerSQL / command injection

UNION-selecting the users table

Break out of a query or a shell command through unescaped input.

25 pts · 45 minStart →
ExpertSQL / command injection

Boolean-blind, one bit at a time

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
ExpertSQL / command injection

Second-order injection through a stored value

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
ExpertSQL / command injection

Time-based extraction from a silent endpoint

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
MasterSQL / command injection

Command injection through a filename

Break out of a query or a shell command through unescaped input.

100 pts · 180 minStart →
MasterSQL / command injection

Reading files through the database engine

Break out of a query or a shell command through unescaped input.

100 pts · 180 minStart →
MasterSQL / command injection

Stacking queries to write, not just read

Break out of a query or a shell command through unescaped input.

100 pts · 180 minStart →