Academy · Labs

The Lab Universe

Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.

30
labs
Difficulty
Category
Track
PractitionerSubdomain takeover

A CNAME pointing at a deleted bucket

Claim a dangling DNS record that points at an unclaimed host.

25 pts · 45 minStart →
PractitionerCross-site scripting (XSS)

A comment field that renders markdown too eagerly

Get your script to run in another visitor's browser on this origin.

25 pts · 45 minStart →
PractitionerPrivilege escalation

A hidden form value that grants admin

Climb from the access you were given to access you were not.

25 pts · 45 minStart →
PractitionerCSRF

A JSON endpoint that accepts form content-type

Make a logged-in victim's browser send a state-changing request.

25 pts · 45 minStart →
PractitionerCryptographic weakness

A password-reset token you can predict

Break the guarantee a weak or misused primitive was meant to give.

25 pts · 45 minStart →
PractitionerInsecure deserialization

A serialized cart the client can edit

Feed the server a serialized object it will trust and rebuild.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

A webhook tester pointed at localhost

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerCryptographic weakness

An ECB-mode image that leaks its shape

Break the guarantee a weak or misused primitive was meant to give.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

An image importer aimed inward

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerBusiness logic flaw

Applying the same coupon twice

Use the feature exactly as built, in an order it never anticipated.

25 pts · 45 minStart →
PractitionerCross-site scripting (XSS)

Breaking out of an HTML attribute

Get your script to run in another visitor's browser on this origin.

25 pts · 45 minStart →
PractitionerBroken access control / IDOR

Deleting a comment you did not write

Reach an object that was never yours by changing the id that names it.

25 pts · 45 minStart →
PractitionerBroken access control / IDOR

Editing a profile that is not yours

Reach an object that was never yours by changing the id that names it.

25 pts · 45 minStart →
PractitionerSQL / command injection

Error-based extraction from a chatty endpoint

Break out of a query or a shell command through unescaped input.

25 pts · 45 minStart →
PractitionerRace condition

Redeeming a one-time code twice

Slip through the window between a check and the action it guards.

25 pts · 45 minStart →
PractitionerRace condition

Registering the same username twice

Slip through the window between a check and the action it guards.

25 pts · 45 minStart →
PractitionerInformation disclosure

Secrets committed to an exposed .git

Find the secret the application leaks without meaning to.

25 pts · 45 minStart →
PractitionerAuthentication bypass

Skipping the second step of a two-step login

Get past the login without the credential it is supposed to demand.

25 pts · 45 minStart →
PractitionerCross-site scripting (XSS)

Stored in a display name

Get your script to run in another visitor's browser on this origin.

25 pts · 45 minStart →
PractitionerInformation disclosure

The debug endpoint still answering in production

Find the secret the application leaks without meaning to.

25 pts · 45 minStart →
PractitionerBroken access control / IDOR

The export endpoint that forgot to ask who is asking

Reach an object that was never yours by changing the id that names it.

25 pts · 45 minStart →
PractitionerCSRF

The form with no anti-forgery token

Make a logged-in victim's browser send a state-changing request.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

The link-preview that fetches anything

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerSubdomain takeover

The pages site that was never published

Claim a dangling DNS record that points at an unclaimed host.

25 pts · 45 minStart →
PractitionerAuthentication bypass

The remember-me cookie that means too much

Get past the login without the credential it is supposed to demand.

25 pts · 45 minStart →
PractitionerPrivilege escalation

The role field the client should not set

Climb from the access you were given to access you were not.

25 pts · 45 minStart →
PractitionerInsecure deserialization

The role hidden in a base64 cookie

Feed the server a serialized object it will trust and rebuild.

25 pts · 45 minStart →
PractitionerSQL / command injection

UNION-selecting the users table

Break out of a query or a shell command through unescaped input.

25 pts · 45 minStart →
PractitionerInformation disclosure

User enumeration through timing

Find the secret the application leaks without meaning to.

25 pts · 45 minStart →
PractitionerBusiness logic flaw

Voting more than once by replaying the request

Use the feature exactly as built, in an order it never anticipated.

25 pts · 45 minStart →