Academy · Labs

The Lab Universe

Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.

28
labs
Difficulty
Category
Track
MasterRemote code execution

A dependency confusion package that runs on install

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterInsecure deserialization

A gadget chain to state change

Feed the server a serialized object it will trust and rebuild.

100 pts · 180 minStart →
MasterCryptographic weakness

A padding oracle that reads the ciphertext

Break the guarantee a weak or misused primitive was meant to give.

100 pts · 180 minStart →
MasterPrivilege escalation

A support-impersonation feature turned on yourself

Climb from the access you were given to access you were not.

100 pts · 180 minStart →
MasterRace condition

A TOCTOU gap in a file upload

Slip through the window between a check and the action it guards.

100 pts · 180 minStart →
MasterRemote code execution

Argument injection into a called binary

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterBusiness logic flaw

Assembling a discount no single rule forbids

Use the feature exactly as built, in an order it never anticipated.

100 pts · 180 minStart →
MasterSubdomain takeover

Chaining a takeover into cookie theft

Claim a dangling DNS record that points at an unclaimed host.

100 pts · 180 minStart →
MasterBroken access control / IDOR

Chaining two objects into a full account read

Reach an object that was never yours by changing the id that names it.

100 pts · 180 minStart →
MasterSQL / command injection

Command injection through a filename

Break out of a query or a shell command through unescaped input.

100 pts · 180 minStart →
MasterRace condition

Double-spend across two endpoints at once

Slip through the window between a check and the action it guards.

100 pts · 180 minStart →
MasterCryptographic weakness

Forging a session from a leaked signing key

Break the guarantee a weak or misused primitive was meant to give.

100 pts · 180 minStart →
MasterAuthentication bypass

Forging the 'already verified' state

Get past the login without the credential it is supposed to demand.

100 pts · 180 minStart →
MasterRemote code execution

From deserialization gadget to shell

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterInsecure deserialization

From deserialization to file write

Feed the server a serialized object it will trust and rebuild.

100 pts · 180 minStart →
MasterServer-side request forgery (SSRF)

Gopher-smuggling a request to an internal service

Make the server fetch a URL of your choosing, from inside its network.

100 pts · 180 minStart →
MasterPrivilege escalation

Horizontal to vertical in two steps

Climb from the access you were given to access you were not.

100 pts · 180 minStart →
MasterPrivilege escalation

Inheriting permissions through a group you joined

Climb from the access you were given to access you were not.

100 pts · 180 minStart →
MasterCSRF

Login CSRF into an attacker's account

Make a logged-in victim's browser send a state-changing request.

100 pts · 180 minStart →
MasterCross-site scripting (XSS)

Mutation XSS the sanitiser did not expect

Get your script to run in another visitor's browser on this origin.

100 pts · 180 minStart →
MasterCryptographic weakness

Nonce reuse that unwinds the keystream

Break the guarantee a weak or misused primitive was meant to give.

100 pts · 180 minStart →
MasterSQL / command injection

Reading files through the database engine

Break out of a query or a shell command through unescaped input.

100 pts · 180 minStart →
MasterServer-side request forgery (SSRF)

Redirect-hopping into a private range

Make the server fetch a URL of your choosing, from inside its network.

100 pts · 180 minStart →
MasterBusiness logic flaw

Refunding more than you paid

Use the feature exactly as built, in an order it never anticipated.

100 pts · 180 minStart →
MasterSQL / command injection

Stacking queries to write, not just read

Break out of a query or a shell command through unescaped input.

100 pts · 180 minStart →
MasterCross-site scripting (XSS)

Stealing a session under a weak CSP

Get your script to run in another visitor's browser on this origin.

100 pts · 180 minStart →
MasterRemote code execution

Template injection to command execution

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterRemote code execution

XXE escalated to a file read and beyond

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →