The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
7
labsDifficulty
Category
ExpertRemote code execution
A file type check you can talk past
Turn a foothold into commands running on the server itself.
50 pts · 90 minStart →
ExpertRemote code execution
An upload that lands in an executable path
Turn a foothold into commands running on the server itself.
50 pts · 90 minStart →
ExpertSQL / command injection
Boolean-blind, one bit at a time
Break out of a query or a shell command through unescaped input.
50 pts · 90 minStart →
ExpertSQL / command injection
Second-order injection through a stored value
Break out of a query or a shell command through unescaped input.
50 pts · 90 minStart →
ExpertInsecure deserialization
Tampering with a signed-but-unverified token
Feed the server a serialized object it will trust and rebuild.
50 pts · 90 minStart →
ExpertSQL / command injection
Time-based extraction from a silent endpoint
Break out of a query or a shell command through unescaped input.
50 pts · 90 minStart →
ExpertInsecure deserialization
Type confusion in a rebuilt object
Feed the server a serialized object it will trust and rebuild.
50 pts · 90 minStart →