Academy · Track

API Security

REST and GraphQL — mass assignment, over-fetching and the object that was never yours.

18
labs
← All labs
ApprenticeBroken access control / IDOR

Reading another user's support tickets

Reach an object that was never yours by changing the id that names it.

10 pts · 20 minStart →
ApprenticeBroken access control / IDOR

The invoice with your neighbour's name on it

Reach an object that was never yours by changing the id that names it.

10 pts · 20 minStart →
ApprenticeBroken access control / IDOR

The order history one id away

Reach an object that was never yours by changing the id that names it.

10 pts · 20 minStart →
PractitionerServer-side request forgery (SSRF)

A webhook tester pointed at localhost

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

An image importer aimed inward

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerBroken access control / IDOR

Deleting a comment you did not write

Reach an object that was never yours by changing the id that names it.

25 pts · 45 minStart →
PractitionerBroken access control / IDOR

Editing a profile that is not yours

Reach an object that was never yours by changing the id that names it.

25 pts · 45 minStart →
PractitionerBroken access control / IDOR

The export endpoint that forgot to ask who is asking

Reach an object that was never yours by changing the id that names it.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

The link-preview that fetches anything

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
ExpertBroken access control / IDOR

A GUID is not an authorization check

Reach an object that was never yours by changing the id that names it.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Blind SSRF confirmed out of band

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Bypassing an allowlist with a DNS trick

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertBroken access control / IDOR

Mass-assigning your way into an admin group

Reach an object that was never yours by changing the id that names it.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Reaching the cloud metadata endpoint

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertBroken access control / IDOR

The nested resource that skipped its parent's check

Reach an object that was never yours by changing the id that names it.

50 pts · 90 minStart →
MasterBroken access control / IDOR

Chaining two objects into a full account read

Reach an object that was never yours by changing the id that names it.

100 pts · 180 minStart →
MasterServer-side request forgery (SSRF)

Gopher-smuggling a request to an internal service

Make the server fetch a URL of your choosing, from inside its network.

100 pts · 180 minStart →
MasterServer-side request forgery (SSRF)

Redirect-hopping into a private range

Make the server fetch a URL of your choosing, from inside its network.

100 pts · 180 minStart →