Academy · Labs

The Lab Universe

Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.

21
labs
Difficulty
Category
Track
PractitionerInsecure deserialization

A serialized cart the client can edit

Feed the server a serialized object it will trust and rebuild.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

A webhook tester pointed at localhost

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

An image importer aimed inward

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

The link-preview that fetches anything

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerInsecure deserialization

The role hidden in a base64 cookie

Feed the server a serialized object it will trust and rebuild.

25 pts · 45 minStart →
ExpertRemote code execution

A file type check you can talk past

Turn a foothold into commands running on the server itself.

50 pts · 90 minStart →
ExpertRemote code execution

An upload that lands in an executable path

Turn a foothold into commands running on the server itself.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Blind SSRF confirmed out of band

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Bypassing an allowlist with a DNS trick

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Reaching the cloud metadata endpoint

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertInsecure deserialization

Tampering with a signed-but-unverified token

Feed the server a serialized object it will trust and rebuild.

50 pts · 90 minStart →
ExpertInsecure deserialization

Type confusion in a rebuilt object

Feed the server a serialized object it will trust and rebuild.

50 pts · 90 minStart →
MasterRemote code execution

A dependency confusion package that runs on install

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterInsecure deserialization

A gadget chain to state change

Feed the server a serialized object it will trust and rebuild.

100 pts · 180 minStart →
MasterRemote code execution

Argument injection into a called binary

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterRemote code execution

From deserialization gadget to shell

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterInsecure deserialization

From deserialization to file write

Feed the server a serialized object it will trust and rebuild.

100 pts · 180 minStart →
MasterServer-side request forgery (SSRF)

Gopher-smuggling a request to an internal service

Make the server fetch a URL of your choosing, from inside its network.

100 pts · 180 minStart →
MasterServer-side request forgery (SSRF)

Redirect-hopping into a private range

Make the server fetch a URL of your choosing, from inside its network.

100 pts · 180 minStart →
MasterRemote code execution

Template injection to command execution

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterRemote code execution

XXE escalated to a file read and beyond

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →