The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
5
labsDifficulty
Category
ExpertCSRF
Defeating a predictable token
Make a logged-in victim's browser send a state-changing request.
50 pts · 90 minStart →
ExpertCross-site scripting (XSS)
DOM XSS through the URL fragment
Get your script to run in another visitor's browser on this origin.
50 pts · 90 minStart →
ExpertCross-site scripting (XSS)
Injecting into a JSON block the page evaluates
Get your script to run in another visitor's browser on this origin.
50 pts · 90 minStart →
ExpertCSRF
SameSite is not set, and it matters
Make a logged-in victim's browser send a state-changing request.
50 pts · 90 minStart →
ExpertCross-site scripting (XSS)
Slipping past a naive filter
Get your script to run in another visitor's browser on this origin.
50 pts · 90 minStart →