The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
5
labsDifficulty
Category
PractitionerInsecure deserialization
A serialized cart the client can edit
Feed the server a serialized object it will trust and rebuild.
25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)
A webhook tester pointed at localhost
Make the server fetch a URL of your choosing, from inside its network.
25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)
An image importer aimed inward
Make the server fetch a URL of your choosing, from inside its network.
25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)
The link-preview that fetches anything
Make the server fetch a URL of your choosing, from inside its network.
25 pts · 45 minStart →
PractitionerInsecure deserialization
The role hidden in a base64 cookie
Feed the server a serialized object it will trust and rebuild.
25 pts · 45 minStart →