Academy · Labs

The Lab Universe

Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.

10
labs
Difficulty
Category
Track
PractitionerCross-site scripting (XSS)

A comment field that renders markdown too eagerly

Get your script to run in another visitor's browser on this origin.

25 pts · 45 minStart →
PractitionerCSRF

A JSON endpoint that accepts form content-type

Make a logged-in victim's browser send a state-changing request.

25 pts · 45 minStart →
PractitionerCross-site scripting (XSS)

Breaking out of an HTML attribute

Get your script to run in another visitor's browser on this origin.

25 pts · 45 minStart →
PractitionerInformation disclosure

Secrets committed to an exposed .git

Find the secret the application leaks without meaning to.

25 pts · 45 minStart →
PractitionerAuthentication bypass

Skipping the second step of a two-step login

Get past the login without the credential it is supposed to demand.

25 pts · 45 minStart →
PractitionerCross-site scripting (XSS)

Stored in a display name

Get your script to run in another visitor's browser on this origin.

25 pts · 45 minStart →
PractitionerInformation disclosure

The debug endpoint still answering in production

Find the secret the application leaks without meaning to.

25 pts · 45 minStart →
PractitionerCSRF

The form with no anti-forgery token

Make a logged-in victim's browser send a state-changing request.

25 pts · 45 minStart →
PractitionerAuthentication bypass

The remember-me cookie that means too much

Get past the login without the credential it is supposed to demand.

25 pts · 45 minStart →
PractitionerInformation disclosure

User enumeration through timing

Find the secret the application leaks without meaning to.

25 pts · 45 minStart →