Academy · Track

Web Fundamentals

The HTTP, headers and same-origin groundwork every other track stands on.

33
labs
← All labs
ApprenticeInformation disclosure

A backup file left in the web root

Find the secret the application leaks without meaning to.

10 pts · 20 minStart →
ApprenticeAuthentication bypass

A login that leaks which half was wrong

Get past the login without the credential it is supposed to demand.

10 pts · 20 minStart →
ApprenticeCSRF

Changing an email with a single GET

Make a logged-in victim's browser send a state-changing request.

10 pts · 20 minStart →
ApprenticeInformation disclosure

Comments in the source with a key in them

Find the secret the application leaks without meaning to.

10 pts · 20 minStart →
ApprenticeCross-site scripting (XSS)

Reflected in the search box

Get your script to run in another visitor's browser on this origin.

10 pts · 20 minStart →
ApprenticeAuthentication bypass

The default credential nobody changed

Get past the login without the credential it is supposed to demand.

10 pts · 20 minStart →
ApprenticeCross-site scripting (XSS)

The error page that echoes your input

Get your script to run in another visitor's browser on this origin.

10 pts · 20 minStart →
ApprenticeInformation disclosure

The stack trace that names the database

Find the secret the application leaks without meaning to.

10 pts · 20 minStart →
PractitionerCross-site scripting (XSS)

A comment field that renders markdown too eagerly

Get your script to run in another visitor's browser on this origin.

25 pts · 45 minStart →
PractitionerCSRF

A JSON endpoint that accepts form content-type

Make a logged-in victim's browser send a state-changing request.

25 pts · 45 minStart →
PractitionerCross-site scripting (XSS)

Breaking out of an HTML attribute

Get your script to run in another visitor's browser on this origin.

25 pts · 45 minStart →
PractitionerInformation disclosure

Secrets committed to an exposed .git

Find the secret the application leaks without meaning to.

25 pts · 45 minStart →
PractitionerAuthentication bypass

Skipping the second step of a two-step login

Get past the login without the credential it is supposed to demand.

25 pts · 45 minStart →
PractitionerCross-site scripting (XSS)

Stored in a display name

Get your script to run in another visitor's browser on this origin.

25 pts · 45 minStart →
PractitionerInformation disclosure

The debug endpoint still answering in production

Find the secret the application leaks without meaning to.

25 pts · 45 minStart →
PractitionerCSRF

The form with no anti-forgery token

Make a logged-in victim's browser send a state-changing request.

25 pts · 45 minStart →
PractitionerAuthentication bypass

The remember-me cookie that means too much

Get past the login without the credential it is supposed to demand.

25 pts · 45 minStart →
PractitionerInformation disclosure

User enumeration through timing

Find the secret the application leaks without meaning to.

25 pts · 45 minStart →
ExpertAuthentication bypass

A password reset that trusts the wrong field

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertInformation disclosure

An API version that forgot to retire

Find the secret the application leaks without meaning to.

50 pts · 90 minStart →
ExpertAuthentication bypass

An OAuth state parameter nobody validates

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertCSRF

Defeating a predictable token

Make a logged-in victim's browser send a state-changing request.

50 pts · 90 minStart →
ExpertCross-site scripting (XSS)

DOM XSS through the URL fragment

Get your script to run in another visitor's browser on this origin.

50 pts · 90 minStart →
ExpertInformation disclosure

GraphQL introspection left switched on

Find the secret the application leaks without meaning to.

50 pts · 90 minStart →
ExpertCross-site scripting (XSS)

Injecting into a JSON block the page evaluates

Get your script to run in another visitor's browser on this origin.

50 pts · 90 minStart →
ExpertInformation disclosure

Metadata in an uploaded file's response

Find the secret the application leaks without meaning to.

50 pts · 90 minStart →
ExpertAuthentication bypass

Reusing a magic link that never expired

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertCSRF

SameSite is not set, and it matters

Make a logged-in victim's browser send a state-changing request.

50 pts · 90 minStart →
ExpertCross-site scripting (XSS)

Slipping past a naive filter

Get your script to run in another visitor's browser on this origin.

50 pts · 90 minStart →
MasterAuthentication bypass

Forging the 'already verified' state

Get past the login without the credential it is supposed to demand.

100 pts · 180 minStart →
MasterCSRF

Login CSRF into an attacker's account

Make a logged-in victim's browser send a state-changing request.

100 pts · 180 minStart →
MasterCross-site scripting (XSS)

Mutation XSS the sanitiser did not expect

Get your script to run in another visitor's browser on this origin.

100 pts · 180 minStart →
MasterCross-site scripting (XSS)

Stealing a session under a weak CSP

Get your script to run in another visitor's browser on this origin.

100 pts · 180 minStart →