The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
A quote that breaks the login query
Break out of a query or a shell command through unescaped input.
The search filter that trusts your input
Break out of a query or a shell command through unescaped input.
Error-based extraction from a chatty endpoint
Break out of a query or a shell command through unescaped input.
UNION-selecting the users table
Break out of a query or a shell command through unescaped input.
Boolean-blind, one bit at a time
Break out of a query or a shell command through unescaped input.
Second-order injection through a stored value
Break out of a query or a shell command through unescaped input.
Time-based extraction from a silent endpoint
Break out of a query or a shell command through unescaped input.
Command injection through a filename
Break out of a query or a shell command through unescaped input.
Reading files through the database engine
Break out of a query or a shell command through unescaped input.
Stacking queries to write, not just read
Break out of a query or a shell command through unescaped input.