Academy · Track

Injection

Untrusted input reaching an interpreter — SQL, commands, templates and the query underneath.

23
labs
← All labs
ApprenticeSQL / command injection

A quote that breaks the login query

Break out of a query or a shell command through unescaped input.

10 pts · 20 minStart →
ApprenticeSQL / command injection

The search filter that trusts your input

Break out of a query or a shell command through unescaped input.

10 pts · 20 minStart →
PractitionerInsecure deserialization

A serialized cart the client can edit

Feed the server a serialized object it will trust and rebuild.

25 pts · 45 minStart →
PractitionerSQL / command injection

Error-based extraction from a chatty endpoint

Break out of a query or a shell command through unescaped input.

25 pts · 45 minStart →
PractitionerInsecure deserialization

The role hidden in a base64 cookie

Feed the server a serialized object it will trust and rebuild.

25 pts · 45 minStart →
PractitionerSQL / command injection

UNION-selecting the users table

Break out of a query or a shell command through unescaped input.

25 pts · 45 minStart →
ExpertRemote code execution

A file type check you can talk past

Turn a foothold into commands running on the server itself.

50 pts · 90 minStart →
ExpertRemote code execution

An upload that lands in an executable path

Turn a foothold into commands running on the server itself.

50 pts · 90 minStart →
ExpertSQL / command injection

Boolean-blind, one bit at a time

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
ExpertSQL / command injection

Second-order injection through a stored value

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
ExpertInsecure deserialization

Tampering with a signed-but-unverified token

Feed the server a serialized object it will trust and rebuild.

50 pts · 90 minStart →
ExpertSQL / command injection

Time-based extraction from a silent endpoint

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
ExpertInsecure deserialization

Type confusion in a rebuilt object

Feed the server a serialized object it will trust and rebuild.

50 pts · 90 minStart →
MasterRemote code execution

A dependency confusion package that runs on install

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterInsecure deserialization

A gadget chain to state change

Feed the server a serialized object it will trust and rebuild.

100 pts · 180 minStart →
MasterRemote code execution

Argument injection into a called binary

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterSQL / command injection

Command injection through a filename

Break out of a query or a shell command through unescaped input.

100 pts · 180 minStart →
MasterRemote code execution

From deserialization gadget to shell

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterInsecure deserialization

From deserialization to file write

Feed the server a serialized object it will trust and rebuild.

100 pts · 180 minStart →
MasterSQL / command injection

Reading files through the database engine

Break out of a query or a shell command through unescaped input.

100 pts · 180 minStart →
MasterSQL / command injection

Stacking queries to write, not just read

Break out of a query or a shell command through unescaped input.

100 pts · 180 minStart →
MasterRemote code execution

Template injection to command execution

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →
MasterRemote code execution

XXE escalated to a file read and beyond

Turn a foothold into commands running on the server itself.

100 pts · 180 minStart →