The Lab Universe
Hands-on exercises across every class of vulnerability. Read the brief, work it against your own target, and submit the flag. Points and your level are yours the moment you solve one — join the Academy to start tracking them.
A backup file left in the web root
Find the secret the application leaks without meaning to.
A login that leaks which half was wrong
Get past the login without the credential it is supposed to demand.
Changing an email with a single GET
Make a logged-in victim's browser send a state-changing request.
Comments in the source with a key in them
Find the secret the application leaks without meaning to.
Reflected in the search box
Get your script to run in another visitor's browser on this origin.
The default credential nobody changed
Get past the login without the credential it is supposed to demand.
The error page that echoes your input
Get your script to run in another visitor's browser on this origin.
The stack trace that names the database
Find the secret the application leaks without meaning to.
A comment field that renders markdown too eagerly
Get your script to run in another visitor's browser on this origin.
A JSON endpoint that accepts form content-type
Make a logged-in victim's browser send a state-changing request.
Breaking out of an HTML attribute
Get your script to run in another visitor's browser on this origin.
Secrets committed to an exposed .git
Find the secret the application leaks without meaning to.
Skipping the second step of a two-step login
Get past the login without the credential it is supposed to demand.
Stored in a display name
Get your script to run in another visitor's browser on this origin.
The debug endpoint still answering in production
Find the secret the application leaks without meaning to.
The form with no anti-forgery token
Make a logged-in victim's browser send a state-changing request.
The remember-me cookie that means too much
Get past the login without the credential it is supposed to demand.
User enumeration through timing
Find the secret the application leaks without meaning to.
A password reset that trusts the wrong field
Get past the login without the credential it is supposed to demand.
An API version that forgot to retire
Find the secret the application leaks without meaning to.
An OAuth state parameter nobody validates
Get past the login without the credential it is supposed to demand.
Defeating a predictable token
Make a logged-in victim's browser send a state-changing request.
DOM XSS through the URL fragment
Get your script to run in another visitor's browser on this origin.
GraphQL introspection left switched on
Find the secret the application leaks without meaning to.
Injecting into a JSON block the page evaluates
Get your script to run in another visitor's browser on this origin.
Metadata in an uploaded file's response
Find the secret the application leaks without meaning to.
Reusing a magic link that never expired
Get past the login without the credential it is supposed to demand.
SameSite is not set, and it matters
Make a logged-in victim's browser send a state-changing request.
Slipping past a naive filter
Get your script to run in another visitor's browser on this origin.
Forging the 'already verified' state
Get past the login without the credential it is supposed to demand.
Login CSRF into an attacker's account
Make a logged-in victim's browser send a state-changing request.
Mutation XSS the sanitiser did not expect
Get your script to run in another visitor's browser on this origin.
Stealing a session under a weak CSP
Get your script to run in another visitor's browser on this origin.