Academy · Labs

The Lab Universe

Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.

38
labs
Difficulty
Category
Track
ExpertRemote code execution

A file type check you can talk past

Turn a foothold into commands running on the server itself.

50 pts · 90 minStart →
ExpertBroken access control / IDOR

A GUID is not an authorization check

Reach an object that was never yours by changing the id that names it.

50 pts · 90 minStart →
ExpertCryptographic weakness

A length-extension against a naive MAC

Break the guarantee a weak or misused primitive was meant to give.

50 pts · 90 minStart →
ExpertAuthentication bypass

A password reset that trusts the wrong field

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertPrivilege escalation

An admin route that never re-checks

Climb from the access you were given to access you were not.

50 pts · 90 minStart →
ExpertInformation disclosure

An API version that forgot to retire

Find the secret the application leaks without meaning to.

50 pts · 90 minStart →
ExpertSubdomain takeover

An expired CDN configuration still referenced

Claim a dangling DNS record that points at an unclaimed host.

50 pts · 90 minStart →
ExpertPrivilege escalation

An invite flow that leaks a higher role

Climb from the access you were given to access you were not.

50 pts · 90 minStart →
ExpertAuthentication bypass

An OAuth state parameter nobody validates

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertRemote code execution

An upload that lands in an executable path

Turn a foothold into commands running on the server itself.

50 pts · 90 minStart →
ExpertRace condition

Applying two coupons in the same instant

Slip through the window between a check and the action it guards.

50 pts · 90 minStart →
ExpertPrivilege escalation

Approving your own request as its reviewer

Climb from the access you were given to access you were not.

50 pts · 90 minStart →
ExpertRace condition

Beating a rate limit with concurrency

Slip through the window between a check and the action it guards.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Blind SSRF confirmed out of band

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertSQL / command injection

Boolean-blind, one bit at a time

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Bypassing an allowlist with a DNS trick

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertCSRF

Defeating a predictable token

Make a logged-in victim's browser send a state-changing request.

50 pts · 90 minStart →
ExpertCross-site scripting (XSS)

DOM XSS through the URL fragment

Get your script to run in another visitor's browser on this origin.

50 pts · 90 minStart →
ExpertInformation disclosure

GraphQL introspection left switched on

Find the secret the application leaks without meaning to.

50 pts · 90 minStart →
ExpertCross-site scripting (XSS)

Injecting into a JSON block the page evaluates

Get your script to run in another visitor's browser on this origin.

50 pts · 90 minStart →
ExpertBroken access control / IDOR

Mass-assigning your way into an admin group

Reach an object that was never yours by changing the id that names it.

50 pts · 90 minStart →
ExpertInformation disclosure

Metadata in an uploaded file's response

Find the secret the application leaks without meaning to.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Reaching the cloud metadata endpoint

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertBusiness logic flaw

Referral rewards that pay you to invite yourself

Use the feature exactly as built, in an order it never anticipated.

50 pts · 90 minStart →
ExpertAuthentication bypass

Reusing a magic link that never expired

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertCSRF

SameSite is not set, and it matters

Make a logged-in victim's browser send a state-changing request.

50 pts · 90 minStart →
ExpertSQL / command injection

Second-order injection through a stored value

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
ExpertBusiness logic flaw

Skipping the payment step of the order

Use the feature exactly as built, in an order it never anticipated.

50 pts · 90 minStart →
ExpertCross-site scripting (XSS)

Slipping past a naive filter

Get your script to run in another visitor's browser on this origin.

50 pts · 90 minStart →
ExpertCryptographic weakness

Swapping a JWT to the 'none' algorithm

Break the guarantee a weak or misused primitive was meant to give.

50 pts · 90 minStart →
ExpertInsecure deserialization

Tampering with a signed-but-unverified token

Feed the server a serialized object it will trust and rebuild.

50 pts · 90 minStart →
ExpertSubdomain takeover

The cancelled SaaS that left a dangling record

Claim a dangling DNS record that points at an unclaimed host.

50 pts · 90 minStart →
ExpertCryptographic weakness

The JWT signed with a guessable secret

Break the guarantee a weak or misused primitive was meant to give.

50 pts · 90 minStart →
ExpertBroken access control / IDOR

The nested resource that skipped its parent's check

Reach an object that was never yours by changing the id that names it.

50 pts · 90 minStart →
ExpertSQL / command injection

Time-based extraction from a silent endpoint

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
ExpertInsecure deserialization

Type confusion in a rebuilt object

Feed the server a serialized object it will trust and rebuild.

50 pts · 90 minStart →
ExpertBusiness logic flaw

Upgrading a plan without paying the difference

Use the feature exactly as built, in an order it never anticipated.

50 pts · 90 minStart →
ExpertRace condition

Withdrawing a balance in parallel

Slip through the window between a check and the action it guards.

50 pts · 90 minStart →