The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
3
labsDifficulty
Category
MasterSQL / command injection
Command injection through a filename
Break out of a query or a shell command through unescaped input.
100 pts · 180 minStart →
MasterSQL / command injection
Reading files through the database engine
Break out of a query or a shell command through unescaped input.
100 pts · 180 minStart →
MasterSQL / command injection
Stacking queries to write, not just read
Break out of a query or a shell command through unescaped input.
100 pts · 180 minStart →