Exercises

Exercise Avg. Time Difficulty Solved by Tier
RCE via argument injection
This exercise covers a remote command execution vulnerability via argument injection
< 1 Hr. hard 66 PRO
SAML: Signature Wrapping
This exercise covers how to use Signature Wrapping to become an arbitrary user
< 1 Hr. hard 617 PRO
Code Review 13
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 459 PRO
OAuth2: Predictable State II
This exercise covers the exploitation of a predictable state in an OAuth2 Client
< 1 Hr. hard 285 PRO
Code Review 11
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 401 PRO
OAuth2: Predictable State
This exercise covers the exploitation of a predictable state in an OAuth2 Client
< 1 Hr. hard 310 PRO
CVE-2020-8163: Rails local name RCE
This exercise details the exploitation of CVE-2020-8163 to gain code execution
< 1 Hr. hard 235 PRO
Code Review 09
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 441 PRO
OAuth2: Client Server XSS
This exercise covers the exploitation of a Cross-Site Scripting in an OAuth2 Client and Server
< 1 Hr. hard 389 PRO
Code Review 07
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 466 PRO
Cross-Site Leak
This exercise covers how to use Cross-Site Leak to recover sensitive information
1-2 Hr. hard 598 PRO
Code Review 05
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 463 PRO
Code Review 04
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 581 PRO
Code Review 03
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 502 PRO
OAuth2: Github HTTP HEAD
This exercise covers the exploitation of the HTTP HEAD issue impacting Github in 2019
< 1 Hr. hard 472 PRO
Length Extension Attack
This exercise covers how to use a length extension attack to exploit a directory traversal vulnerability
< 1 Hr. hard 791 PRO
CVE-2019-5418
This exercise details the exploitation of CVE-2019-5418 to get code execution
< 1 Hr. hard 527 PRO
JWT XII JWT
This exercise covers how to use the x5u header to bypass an authentication based on JWT.
< 1 Hr. hard 713 PRO
JWT XI JWT
This exercise covers how to use the jku header to bypass an authentication based on JWT.
< 1 Hr. hard 709 PRO
cve-2019-5420 II
This exercise details the exploitation of CVE-2019-5420 to gain code execution
< 1 Hr. hard 587 PRO
JWT X JWT
This exercise covers how to use the jku header to bypass an authentication based on JWT.
< 1 Hr. hard 805 PRO
JWT IX JWT
This exercise covers how to use the jku header to bypass an authentication based on JWT.
< 1 Hr. hard 936 PRO
Gogs RCE II
This exercise covers how to get code execution against the Git self hosted tool: Gogs.
< 1 Hr. hard 621 PRO
JWT VIII JWT
This exercise covers how to use the jku header to bypass an authentication based on JWT.
< 1 Hr. hard 1015 PRO
Gogs RCE
This exercise covers how to get code execution against the Git self hosted tool: Gogs.
< 1 Hr. hard 697 PRO
Android 07
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
< 1 Hr. hard 1505 PRO
Android 08
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
< 1 Hr. hard 1427 PRO
Android 06
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
< 1 Hr. hard 1764 PRO
From SQL injection to Shell III SQL Injection
This exercise covers how to gain access to an administration interface using SQL injection followed by how to get command execution using ImageTragick
< 1 Hr. hard 1166 PRO
IDOR to Shell
This exercise covers how to get code execution by chaining vulnerabilities in a Ruby-on-Rails application
< 1 Hr. hard 1094 PRO
1 2 3
Showing 31–60 of 74 exercises