Exercises

Exercise Avg. Time Difficulty Solved by Tier
From SQL injection to Shell III: PostgreSQL Edition SQL Injection
This exercise covers how to gain access to an administration interface using a SQL injection, and how to get command execution using Ghostscript
2-4 Hr. medium 251 PRO
SQL Injection 06 SQL Injection
This exercise is one of our challenges on SQL Injections
< 1 Hr. medium 9499 PRO
SQL Injection 04 SQL Injection
This exercise is one of our challenges on SQL Injections
< 1 Hr. medium 10088 PRO
XSS and MySQL FILE XSS
This exercise explains how to exploit a Cross-Site Scripting vulnerability to obtain an administrator's cookies, and how you can use their session to gain access to the administration panel, and find a SQL injection to gain code execution
-- medium 0 FREE
From SQL Injection to Shell II SQL Injection
This exercise explains how you can, from a blind SQL injection, gain access to the administration console. Then once in the administration console, how you can run commands on the system.
1-2 Hr. medium 45 FREE
From SQL Injection to Shell: PostgreSQL edition SQL Injection
This exercise explains how you can from a SQL injection gain access to the administration console, and from there, how you can run commands on the underlying system
< 1 Hr. medium 19 FREE
From SQL Injection to Shell SQL Injection
This exercise demonstrates how to leverage a SQL injection to gain access to the admin console, and from there, how to execute commands on the underlying system
< 1 Hr. medium 8280 FREE
Showing 1–7 of 7 exercises