Exercises
| Exercise | Avg. Time | Difficulty | Solved by | Tier | |
|---|---|---|---|---|---|
|
|
Secure Design: Event Publishing & Data Boundaries | 6 | PRO | ||
|
|
Secure Design: Idempotency Keys | 8 | PRO | ||
|
|
Secure Design: Rendering Untrusted Content on a Throwaway Origin | 7 | PRO | ||
|
|
Secure Design: Sandboxing Code Execution | 11 | PRO | ||
|
|
Secure Design: Session Management | 16 | PRO | ||
|
|
Secure Design: Write-only API Keys | 12 | PRO | ||
|
|
Secure Design: Password Reset Flow | 16 | PRO | ||
|
|
Secure Design: OAuth / SSO Integration | 16 | PRO | ||
|
|
Java Serialize 09
This challenge covers exploiting toString() through a wrapper class, the technique behind BadAttributeValueExpException in Commons Collections.
|
8 | PRO | ||
|
|
Java Serialize 07
This challenge covers using readResolve() as a deserialization entry point to trigger a gadget chain after the object is restored.
|
8 | PRO | ||
|
|
Java Serialize 10
This challenge covers chaining multiple classes together into a multi-class gadget chain, bridging single-class exploits to real-world attacks.
|
7 | PRO | ||
|
|
Java Serialize 08
This challenge covers exploiting Object.equals(), triggered during HashSet and HashMap deserialization, as a gadget entry point.
|
8 | PRO | ||
|
|
Secure Design: Error Proofing (Poka-yoke) | 18 | PRO | ||
|
|
Secure Design: Framework Security Evaluation | 18 | PRO | ||
|
|
Secure Design: CI/CD Pipeline | 21 | PRO | ||
|
|
Secure Design: Password Storage & Hashing | 20 | PRO | ||
|
|
Secure Design: Fail Closed | 20 | PRO | ||
|
|
CVE-2026-55415: Schema Import Injection
Gain code execution by injecting Python through a crafted JSON Schema when the generated Pydantic model is imported.
|
10 | PRO | ||
|
|
ODF XXE
This exercise covers the exploitation of an XXE in an ODF Parser
|
10 | PRO | ||
|
|
SOAPBridge: Savon WSDL Code Injection
Gain code execution through an unsafe module_eval call during WSDL import.
|
9 | PRO | ||
|
|
Secure Design: Secret & Credential Management | 21 | PRO | ||
|
|
Secure Design: Control Placement | 30 | PRO | ||
|
|
Secure Design: Backend Authentication Proxy | 16 | PRO | ||
|
|
Secure Design: Safe Serialization | 14 | PRO | ||
|
|
AI Fundamentals: Tool Use & Agents | 36 | PRO | ||
|
|
AI Fundamentals: Retrieval-Augmented Generation | 37 | PRO | ||
|
|
Open Door
No guardrails at all. Simply ask the model for the secret key.
|
91 | PRO | ||
|
|
Polite Refusal
The model is told to refuse key requests. Use social engineering to convince it to share anyway.
|
51 | PRO | ||
|
|
AI Fundamentals: Using Models in Practice | 36 | PRO | ||
|
|
AI Fundamentals: Multimodal Models | 35 | PRO |
Showing 1–30 of 808 exercises
Free Labs of the Month