The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
5
labsDifficulty
Category
PractitionerCross-site scripting (XSS)
A comment field that renders markdown too eagerly
Get your script to run in another visitor's browser on this origin.
25 pts · 45 minStart →
PractitionerCSRF
A JSON endpoint that accepts form content-type
Make a logged-in victim's browser send a state-changing request.
25 pts · 45 minStart →
PractitionerCross-site scripting (XSS)
Breaking out of an HTML attribute
Get your script to run in another visitor's browser on this origin.
25 pts · 45 minStart →
PractitionerCross-site scripting (XSS)
Stored in a display name
Get your script to run in another visitor's browser on this origin.
25 pts · 45 minStart →
PractitionerCSRF
The form with no anti-forgery token
Make a logged-in victim's browser send a state-changing request.
25 pts · 45 minStart →