Exercises

Exercise Avg. Time Difficulty Solved by Tier
CVE-2018-11235: Git Submodule RCE
This exercise details the exploitation of a vulnerability in Git Sub module that can be used to get command execution
< 1 Hr. hard 536 PRO
CVE-2018-0114 JWT
This exercise details the exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT
< 1 Hr. hard 1941 PRO
CBC-MAC Crypto
This exercise covers the exploitation of signature of non-fixed size messages with CBC-MAC
< 1 Hr. hard 1762 PRO
MongoDB Injection 02
This exercise is one of our challenges on vulnerabilities related to MongoDB
< 1 Hr. hard 8760 PRO
ECDSA Crypto
This exercise covers the exploitation of a weakness in the usage of ECDSA
< 1 Hr. hard 373 PRO
Unickle
This challenge was written for Ruxcon CTF 2015. It's an SQL injection mixed with a remote code execution.
< 1 Hr. hard 688 PRO
Luhn
This challenge was written for Ruxcon CTF 2015. It's an SQL injection with a twist
< 1 Hr. hard 637 PRO
CVE-2014-1266
This exercise covers how to intercept an HTTPs connection
< 1 Hr. hard 1081 PRO
CVE-2011-0228
This exercise covers how to intercept an HTTPs connection
< 1 Hr. hard 1235 PRO
API to Shell API
This exercise covers the exploitation of PHP type confusion to bypass a signature and the exploitation of unserialize.
< 1 Hr. hard 3554 PRO
CVE-2012-6081: MoinMoin code execution
This exercise explains how you can exploit CVE-2012-6081 to gain code execution. This vulnerability was exploited to compromise Debian's wiki and Python documentation website
hard 0 FREE
Rack Cookies and Commands injection
After a short brute force introduction, this exercise explains the tampering of rack cookies and how you can even manage to modify a signed cookie (if the secret is trivial). Using this issue, you will be able to escalate your privileges and gain command execution
hard 1 FREE
Linux Host Review
This exercise explains how to perform a Linux host review, what and how you can check the configuration of a Linux server to ensure it is securely configured. The reviewed system is a traditional Linux-Apache-Mysql-PHP (LAMP) server used to host a blog.
hard 1 FREE
CVE-2012-2661: ActiveRecord SQL injection
This exercise explains how you can exploit CVE-2012-2661 to retrieve information from a database
hard 0 FREE
1 2 3
Showing 61–74 of 74 exercises