Academy · Labs

The Lab Universe

Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.

11
labs
Difficulty
Category
Track
ExpertAuthentication bypass

A password reset that trusts the wrong field

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertInformation disclosure

An API version that forgot to retire

Find the secret the application leaks without meaning to.

50 pts · 90 minStart →
ExpertAuthentication bypass

An OAuth state parameter nobody validates

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertCSRF

Defeating a predictable token

Make a logged-in victim's browser send a state-changing request.

50 pts · 90 minStart →
ExpertCross-site scripting (XSS)

DOM XSS through the URL fragment

Get your script to run in another visitor's browser on this origin.

50 pts · 90 minStart →
ExpertInformation disclosure

GraphQL introspection left switched on

Find the secret the application leaks without meaning to.

50 pts · 90 minStart →
ExpertCross-site scripting (XSS)

Injecting into a JSON block the page evaluates

Get your script to run in another visitor's browser on this origin.

50 pts · 90 minStart →
ExpertInformation disclosure

Metadata in an uploaded file's response

Find the secret the application leaks without meaning to.

50 pts · 90 minStart →
ExpertAuthentication bypass

Reusing a magic link that never expired

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertCSRF

SameSite is not set, and it matters

Make a logged-in victim's browser send a state-changing request.

50 pts · 90 minStart →
ExpertCross-site scripting (XSS)

Slipping past a naive filter

Get your script to run in another visitor's browser on this origin.

50 pts · 90 minStart →