The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
A CNAME pointing at a deleted bucket
Claim a dangling DNS record that points at an unclaimed host.
A comment field that renders markdown too eagerly
Get your script to run in another visitor's browser on this origin.
A hidden form value that grants admin
Climb from the access you were given to access you were not.
A JSON endpoint that accepts form content-type
Make a logged-in victim's browser send a state-changing request.
A password-reset token you can predict
Break the guarantee a weak or misused primitive was meant to give.
A serialized cart the client can edit
Feed the server a serialized object it will trust and rebuild.
A webhook tester pointed at localhost
Make the server fetch a URL of your choosing, from inside its network.
An ECB-mode image that leaks its shape
Break the guarantee a weak or misused primitive was meant to give.
An image importer aimed inward
Make the server fetch a URL of your choosing, from inside its network.
Applying the same coupon twice
Use the feature exactly as built, in an order it never anticipated.
Breaking out of an HTML attribute
Get your script to run in another visitor's browser on this origin.
Deleting a comment you did not write
Reach an object that was never yours by changing the id that names it.
Editing a profile that is not yours
Reach an object that was never yours by changing the id that names it.
Error-based extraction from a chatty endpoint
Break out of a query or a shell command through unescaped input.
Redeeming a one-time code twice
Slip through the window between a check and the action it guards.
Registering the same username twice
Slip through the window between a check and the action it guards.
Secrets committed to an exposed .git
Find the secret the application leaks without meaning to.
Skipping the second step of a two-step login
Get past the login without the credential it is supposed to demand.
Stored in a display name
Get your script to run in another visitor's browser on this origin.
The debug endpoint still answering in production
Find the secret the application leaks without meaning to.
The export endpoint that forgot to ask who is asking
Reach an object that was never yours by changing the id that names it.
The form with no anti-forgery token
Make a logged-in victim's browser send a state-changing request.
The link-preview that fetches anything
Make the server fetch a URL of your choosing, from inside its network.
The pages site that was never published
Claim a dangling DNS record that points at an unclaimed host.
The remember-me cookie that means too much
Get past the login without the credential it is supposed to demand.
The role field the client should not set
Climb from the access you were given to access you were not.
The role hidden in a base64 cookie
Feed the server a serialized object it will trust and rebuild.
UNION-selecting the users table
Break out of a query or a shell command through unescaped input.
User enumeration through timing
Find the secret the application leaks without meaning to.
Voting more than once by replaying the request
Use the feature exactly as built, in an order it never anticipated.