The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
A login that leaks which half was wrong
Get past the login without the credential it is supposed to demand.
The default credential nobody changed
Get past the login without the credential it is supposed to demand.
A hidden form value that grants admin
Climb from the access you were given to access you were not.
Skipping the second step of a two-step login
Get past the login without the credential it is supposed to demand.
The remember-me cookie that means too much
Get past the login without the credential it is supposed to demand.
The role field the client should not set
Climb from the access you were given to access you were not.
A password reset that trusts the wrong field
Get past the login without the credential it is supposed to demand.
An admin route that never re-checks
Climb from the access you were given to access you were not.
An invite flow that leaks a higher role
Climb from the access you were given to access you were not.
An OAuth state parameter nobody validates
Get past the login without the credential it is supposed to demand.
Approving your own request as its reviewer
Climb from the access you were given to access you were not.
Reusing a magic link that never expired
Get past the login without the credential it is supposed to demand.
A support-impersonation feature turned on yourself
Climb from the access you were given to access you were not.
Forging the 'already verified' state
Get past the login without the credential it is supposed to demand.
Horizontal to vertical in two steps
Climb from the access you were given to access you were not.
Inheriting permissions through a group you joined
Climb from the access you were given to access you were not.