The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
A dependency confusion package that runs on install
Turn a foothold into commands running on the server itself.
A gadget chain to state change
Feed the server a serialized object it will trust and rebuild.
A padding oracle that reads the ciphertext
Break the guarantee a weak or misused primitive was meant to give.
A support-impersonation feature turned on yourself
Climb from the access you were given to access you were not.
A TOCTOU gap in a file upload
Slip through the window between a check and the action it guards.
Argument injection into a called binary
Turn a foothold into commands running on the server itself.
Assembling a discount no single rule forbids
Use the feature exactly as built, in an order it never anticipated.
Chaining a takeover into cookie theft
Claim a dangling DNS record that points at an unclaimed host.
Chaining two objects into a full account read
Reach an object that was never yours by changing the id that names it.
Command injection through a filename
Break out of a query or a shell command through unescaped input.
Double-spend across two endpoints at once
Slip through the window between a check and the action it guards.
Forging a session from a leaked signing key
Break the guarantee a weak or misused primitive was meant to give.
Forging the 'already verified' state
Get past the login without the credential it is supposed to demand.
From deserialization gadget to shell
Turn a foothold into commands running on the server itself.
From deserialization to file write
Feed the server a serialized object it will trust and rebuild.
Gopher-smuggling a request to an internal service
Make the server fetch a URL of your choosing, from inside its network.
Horizontal to vertical in two steps
Climb from the access you were given to access you were not.
Inheriting permissions through a group you joined
Climb from the access you were given to access you were not.
Login CSRF into an attacker's account
Make a logged-in victim's browser send a state-changing request.
Mutation XSS the sanitiser did not expect
Get your script to run in another visitor's browser on this origin.
Nonce reuse that unwinds the keystream
Break the guarantee a weak or misused primitive was meant to give.
Reading files through the database engine
Break out of a query or a shell command through unescaped input.
Redirect-hopping into a private range
Make the server fetch a URL of your choosing, from inside its network.
Refunding more than you paid
Use the feature exactly as built, in an order it never anticipated.
Stacking queries to write, not just read
Break out of a query or a shell command through unescaped input.
Stealing a session under a weak CSP
Get your script to run in another visitor's browser on this origin.
Template injection to command execution
Turn a foothold into commands running on the server itself.
XXE escalated to a file read and beyond
Turn a foothold into commands running on the server itself.