Exercises

Exercise Avg. Time Difficulty Solved by Tier
RCE via argument injection
This exercise covers a remote command execution vulnerability via argument injection
< 1 Hr. hard 73 PRO
SAML: Signature Wrapping
This exercise covers how to use Signature Wrapping to become an arbitrary user
< 1 Hr. hard 628 PRO
Code Review 13
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 477 PRO
OAuth2: Predictable State II
This exercise covers the exploitation of a predictable state in an OAuth2 Client
< 1 Hr. hard 294 PRO
Code Review 11
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 420 PRO
OAuth2: Predictable State
This exercise covers the exploitation of a predictable state in an OAuth2 Client
< 1 Hr. hard 319 PRO
CVE-2020-8163: Rails local name RCE
This exercise details the exploitation of CVE-2020-8163 to gain code execution
< 1 Hr. hard 240 PRO
Code Review 09
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 463 PRO
OAuth2: Client Server XSS
This exercise covers the exploitation of a Cross-Site Scripting in an OAuth2 Client and Server
< 1 Hr. hard 398 PRO
Code Review 07
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 485 PRO
Cross-Site Leak
This exercise covers how to use Cross-Site Leak to recover sensitive information
1-2 Hr. hard 602 PRO
Code Review 05
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 485 PRO
Code Review 04
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 609 PRO
Code Review 03
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 526 PRO
OAuth2: Github HTTP HEAD
This exercise covers the exploitation of the HTTP HEAD issue impacting Github in 2019
< 1 Hr. hard 482 PRO
Length Extension Attack
This exercise covers how to use a length extension attack to exploit a directory traversal vulnerability
< 1 Hr. hard 797 PRO
CVE-2019-5418
This exercise details the exploitation of CVE-2019-5418 to get code execution
< 1 Hr. hard 533 PRO
JWT XII JWT
This exercise covers how to use the x5u header to bypass an authentication based on JWT.
< 1 Hr. hard 724 PRO
JWT XI JWT
This exercise covers how to use the jku header to bypass an authentication based on JWT.
< 1 Hr. hard 719 PRO
cve-2019-5420 II
This exercise details the exploitation of CVE-2019-5420 to gain code execution
< 1 Hr. hard 592 PRO
JWT X JWT
This exercise covers how to use the jku header to bypass an authentication based on JWT.
< 1 Hr. hard 816 PRO
JWT IX JWT
This exercise covers how to use the jku header to bypass an authentication based on JWT.
< 1 Hr. hard 944 PRO
Gogs RCE II
This exercise covers how to get code execution against the Git self hosted tool: Gogs.
< 1 Hr. hard 628 PRO
JWT VIII JWT
This exercise covers how to use the jku header to bypass an authentication based on JWT.
< 1 Hr. hard 1022 PRO
Gogs RCE
This exercise covers how to get code execution against the Git self hosted tool: Gogs.
< 1 Hr. hard 704 PRO
Android 07
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
< 1 Hr. hard 1514 PRO
Android 08
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
< 1 Hr. hard 1435 PRO
Android 06
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
< 1 Hr. hard 1774 PRO
From SQL injection to Shell III SQL Injection
This exercise covers how to gain access to an administration interface using SQL injection followed by how to get command execution using ImageTragick
< 1 Hr. hard 1176 PRO
IDOR to Shell
This exercise covers how to get code execution by chaining vulnerabilities in a Ruby-on-Rails application
< 1 Hr. hard 1102 PRO
‹ 1 2 3 ›
Showing 31–60 of 74 exercises