The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
A dependency confusion package that runs on install
Turn a foothold into commands running on the server itself.
A gadget chain to state change
Feed the server a serialized object it will trust and rebuild.
Argument injection into a called binary
Turn a foothold into commands running on the server itself.
Command injection through a filename
Break out of a query or a shell command through unescaped input.
From deserialization gadget to shell
Turn a foothold into commands running on the server itself.
From deserialization to file write
Feed the server a serialized object it will trust and rebuild.
Reading files through the database engine
Break out of a query or a shell command through unescaped input.
Stacking queries to write, not just read
Break out of a query or a shell command through unescaped input.
Template injection to command execution
Turn a foothold into commands running on the server itself.
XXE escalated to a file read and beyond
Turn a foothold into commands running on the server itself.