Auth bypass on API token refresh
How a critical authentication bypass in *.northwind.com was found, reported to Northwind Cloud and fixed.
The Academy is free to browse and free to join. Below it, the community where findings get discussed and the board where security work gets hired. Everything here is open — you do not need a program to start.
Over a hundred hands-on labs across every vulnerability class, plus the reading and the walkthroughs that go around them. Browsing is open to everyone; joining is free and one click, and it is what unlocks flag submission and progress.
111 labs
Hands-on exercises. Find the bug, capture the flag.
6 courses
Guided paths from reading to lab.
14 concepts
What each class of bug is, before you hunt one.
20 videos
Short walkthroughs.
Join, track progress, earn your level.
What a class of bug actually is, before you go looking for one.
A short video of someone finding it, so you know what the process looks like.
A hands-on lab at one of four difficulty tiers. Hints cost points; the walkthrough forfeits them.
→ Points and a level
A guided path that strings readings and labs into one sequence, tracked to completion.
→ Course progress
Take it to a live program and file your first report. That is a different scoreboard, and it is the one that counts.
→ Reputation
How a critical authentication bypass in *.northwind.com was found, reported to Northwind Cloud and fixed.
Most researchers skim the scope and start testing. The half hour you spend reading it properly is the highest-value half hour of the engagement.
How a critical other in Webhook delivery service was found, reported to Orbit Payments and fixed.
Threads on technique, disclosure and the platform itself, organised by vulnerability class and specialty. Researchers and companies both post here.
Open the community →Companies listing security roles, and researchers open to work. Both sides are reviewed before anything is published.
3 hiring · 4 open to work
Open the board →