The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
6
labsDifficulty
Category
PractitionerServer-side request forgery (SSRF)
A webhook tester pointed at localhost
Make the server fetch a URL of your choosing, from inside its network.
25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)
An image importer aimed inward
Make the server fetch a URL of your choosing, from inside its network.
25 pts · 45 minStart →
PractitionerBroken access control / IDOR
Deleting a comment you did not write
Reach an object that was never yours by changing the id that names it.
25 pts · 45 minStart →
PractitionerBroken access control / IDOR
Editing a profile that is not yours
Reach an object that was never yours by changing the id that names it.
25 pts · 45 minStart →
PractitionerBroken access control / IDOR
The export endpoint that forgot to ask who is asking
Reach an object that was never yours by changing the id that names it.
25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)
The link-preview that fetches anything
Make the server fetch a URL of your choosing, from inside its network.
25 pts · 45 minStart →