Welcome back

Tasks cleared
Apprentice Current rank
0 Rooms active
XSS Hard

Cross-Site Scripting

Learn reflected XSS across HTML, attribute, and script contexts — then bypass a weak filter.

4 tasks 45 pts
0 / 4
Start room
Open Redirect Medium

Open Redirect

Abuse redirect parameters to send victims to attacker-controlled sites.

2 tasks 20 pts
0 / 2
Start room
SQL Injection Hard

SQL Injection

Dump secrets with error-based UNION injection, then extract data blindly.

2 tasks 25 pts
0 / 2
Start room
LFI Medium

Local File Inclusion

Traverse out of the images directory and read sensitive files.

1 tasks 10 pts
0 / 1
Start room
IDOR Low

Insecure Direct Object Reference

Enumerate account IDs and steal another user's details.

1 tasks 10 pts
0 / 1
Start room
CSRF Medium

Cross-Site Request Forgery

Forge state-changing requests. Some actions lack tokens; one is protected.

3 tasks 30 pts
0 / 3
Start room
File Upload Medium

File Upload

Bypass weak upload validators. Files stay inert — prove the bypass.

2 tasks 20 pts
0 / 2
Start room
XXE Expert

XML External Entity

Exploit XXE to read files. Entities resolve against a simulated filesystem only.

2 tasks 35 pts
0 / 2
Start room
SSRF Expert

Server-Side Request Forgery

Make the server request internal resources. All fetches are simulated.

7 tasks 95 pts
0 / 7
Start room
RCE Expert

Remote Code Execution

Command injection and LFI-to-RCE. Commands run in a simulated shell only.

3 tasks 45 pts
0 / 3
Start room
Broken Access Control Medium

Broken Access Control

A mini course platform with hidden APIs, privilege escalation, IDOR, and a payment bypass.

3 tasks 30 pts
0 / 3
Start room
Stored XSS Hard

Stored & Blind XSS

Plant persistent XSS and hit a simulated admin bot.

2 tasks 25 pts
0 / 2
Start room
JWT Hard

JWT Attacks

Forge admin access with alg:none or a weak HMAC secret.

2 tasks 25 pts
0 / 2
Start room
SSTI Expert

Server-Side Template Injection

Jinja evaluates your input. Math first, then go deeper.

2 tasks 30 pts
0 / 2
Start room
CORS Medium

CORS Credential Theft

Reflected ACAO + credentials = steal the API response.

1 tasks 10 pts
0 / 1
Start room
Auth Abuse Hard

Auth Abuse

Host-header reset poisoning and a 2FA skip endpoint.

2 tasks 25 pts
0 / 2
Start room
GraphQL Medium

GraphQL IDOR

Enumerate GraphQL user objects and steal admin's secret.

1 tasks 10 pts
0 / 1
Start room
Business Logic Medium

Business Logic Bugs

Tamper price, reuse coupons, break quantities.

3 tasks 30 pts
0 / 3
Start room
Race Condition Hard

Race Condition

Double-redeem a gift card with parallel requests.

1 tasks 20 pts
0 / 1
Start room
SQL Injection Hard

Second-Order SQLi

Store a payload in your bio, trigger it in admin search.

1 tasks 15 pts
0 / 1
Start room
Filter Evasion Expert

WAF Filter Gauntlet

Three escalating XSS filters. Bypass each stage.

3 tasks 45 pts
0 / 3
Start room
Bug Chain Expert

Bug Chain: XSS → CSRF → ATO

One story. Three bugs. Take over the account email.

1 tasks 25 pts
0 / 1
Start room
Boss Expert

Boss: 0-Click ATO

Poison reset, predict token, own the account.

1 tasks 30 pts
0 / 1
Start room
Weekly Expert

Weekly Hard Challenge

Progressive multi-stage hard room. Clear all three.

3 tasks 55 pts
0 / 3
Start room

How rooms work

Each room is a category with numbered tasks. Open the linked lab, exploit it, then submit the flag or answer on the room page. Progress is stored in localStorage on this browser only — no account required. Labs are sandboxed: no real host files, shells, or outbound network.