The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
A backup file left in the web root
Find the secret the application leaks without meaning to.
A login that leaks which half was wrong
Get past the login without the credential it is supposed to demand.
A negative quantity at checkout
Use the feature exactly as built, in an order it never anticipated.
A price that travels in the request
Use the feature exactly as built, in an order it never anticipated.
A quote that breaks the login query
Break out of a query or a shell command through unescaped input.
Changing an email with a single GET
Make a logged-in victim's browser send a state-changing request.
Comments in the source with a key in them
Find the secret the application leaks without meaning to.
Reading another user's support tickets
Reach an object that was never yours by changing the id that names it.
Reflected in the search box
Get your script to run in another visitor's browser on this origin.
The default credential nobody changed
Get past the login without the credential it is supposed to demand.
The error page that echoes your input
Get your script to run in another visitor's browser on this origin.
The invoice with your neighbour's name on it
Reach an object that was never yours by changing the id that names it.
The order history one id away
Reach an object that was never yours by changing the id that names it.
The search filter that trusts your input
Break out of a query or a shell command through unescaped input.
The stack trace that names the database
Find the secret the application leaks without meaning to.