Log in Join
Learn

Labs

Every lab in the Academy catalogue, one vulnerability class each.

Easy · Business Logic Flaws

CoworkNow hidden-price tampering

A coworking day-pass booking site. The price is a hidden form field the server trusts as submitted.

2 solves

Easy · OS Command Injection

PingPoint uptime checker injection

A network uptime checker. The host field is concatenated straight into a shell ping command.

2 solves

Easy · JWT Attacks

TicketFlow alg-none forgery

An internal help-desk system. The token verifier accepts whatever algorithm the token's header claims, including none.

1 solve

Easy · Insecure Deserialization

MemoryLane preferences cookie gadget

A photo-album app. A shared-preferences cookie is restored with a bare unserialize() call.

0 solves

Easy · SSTI

NoteForge greeting template RCE

A sticky-note app. A custom greeting is compiled directly as an unsandboxed Twig template.

0 solves

Easy · XXE

InvoicePilot XML import file read

A freelance invoicing tool. Uploaded invoice XML is parsed with external entity loading left on.

0 solves

Easy · File Upload

PixelFrame gallery upload RCE

A client-proofing photo gallery. The extension blacklist misses .phtml.

0 solves

Easy · Authentication & Session Flaws

QuickCourt reset-code takeover

A padel and tennis court booking site. The reset code is derived from the send time, with no rate limit.

0 solves

Easy · Server-Side Request Forgery

SnapProof webhook SSRF

A document-notarization service. The completion webhook URL is fetched server-side with no restriction.

0 solves

Easy · Broken Access Control / IDOR

DriveShare booking IDOR

A peer-to-peer car rental app. Find a way to read another user's booking.

3 solves