Academy · Labs

The Lab Universe

Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.

6
labs
Difficulty
Category
Track
PractitionerServer-side request forgery (SSRF)

A webhook tester pointed at localhost

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

An image importer aimed inward

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerBroken access control / IDOR

Deleting a comment you did not write

Reach an object that was never yours by changing the id that names it.

25 pts · 45 minStart →
PractitionerBroken access control / IDOR

Editing a profile that is not yours

Reach an object that was never yours by changing the id that names it.

25 pts · 45 minStart →
PractitionerBroken access control / IDOR

The export endpoint that forgot to ask who is asking

Reach an object that was never yours by changing the id that names it.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

The link-preview that fetches anything

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →