Exercises
| Exercise | Avg. Time | Difficulty | Solved by | Tier | |
|---|---|---|---|---|---|
|
|
API Payments 07
This exercise covers a way to manipulate a shopping cart to lower the total amount
|
< 1 Hr. | 1034 | PRO | |
|
|
CVE-2021-22204: Exiftool RCE II
This exercise covers how you can gain code execution when an application uses exiftool on user-controlled files
|
< 1 Hr. | 90 | PRO | |
|
|
XSL PHP IV
This exercise covers the exploitation of a PHP application using XSL
|
< 1 Hr. | 167 | PRO | |
|
|
API Payments 06
This exercise covers a simple payments bypass.
|
< 1 Hr. | 1067 | PRO | |
|
|
CVE-2022-39224
This exercise covers the exploitation of CVE-2022-39224
|
< 1 Hr. | 116 | PRO | |
|
|
XSL PHP III
This exercise covers the exploitation of a PHP application using XSL
|
< 1 Hr. | 188 | PRO | |
|
|
DOMPDF RCE II
This exercise covers the exploitation of a vulnerability in the DOMPDF library
|
< 1 Hr. | 83 | PRO | |
|
|
DOMPDF RCE
This exercise covers the exploitation of a vulnerability in the DOMPDF library
|
< 1 Hr. | 171 | PRO | |
|
|
XSL PHP II
This exercise covers the exploitation of a PHP application using XSL
|
< 1 Hr. | 256 | PRO | |
|
|
API Payments 04
This exercise covers how to abuse a shopping cart allowing users to apply a voucher..
|
< 1 Hr. | 1288 | PRO | |
|
|
XSL PHP
This exercise covers the exploitation of a PHP application using XSL
|
< 1 Hr. | 301 | PRO | |
|
|
API Payments 03
This exercise covers a simple payments bypass.
|
< 1 Hr. | 1401 | PRO | |
|
|
CVE-2020-13xxx
This challenge covers the review of a CVE and its patch
|
< 1 Hr. | 722 | PRO | |
|
|
Code Review 18
This exercise is one of our challenges to help you learn how to review real source code
|
< 1 Hr. | 431 | PRO | |
|
|
API Payments 02
This exercise covers a simple payments bypass.
|
< 1 Hr. | 1570 | PRO | |
|
|
GCM Nonce Reuse
This challenge covers the impact of nonce reuse on GCM
|
< 1 Hr. | 199 | PRO | |
|
|
CVE-2019-5x2x
This challenge covers the review of a CVE and its patch
|
< 1 Hr. | 659 | PRO | |
|
|
Java Snippet #09
This challenge covers the review of a snippet of code written in Java
|
< 1 Hr. | 1446 | PRO | |
|
|
CVE-2022-26xx9
This challenge covers a vulnerable snippet in a real Java application
|
< 1 Hr. | 672 | PRO | |
|
|
Mongo IDOR
This challenge covers how to exploit an IDOR when Mongo IDs are used
|
< 1 Hr. | 1253 | PRO | |
|
|
CVE-2008-5x8x_ii
This challenge covers the review of a CVE and its patch
|
< 1 Hr. | 690 | PRO | |
|
|
Java Snippet #06
This challenge covers the review of a snippet of code written in Java
|
< 1 Hr. | 1467 | PRO | |
|
|
CVE-2022-21449
JWT
This exercise covers the exploitation of CVE-2022-21449 against a Java Application relying on JWT
|
< 1 Hr. | 195 | PRO | |
|
|
CVE-2021-33564 Argument Injection in Ruby Dragonfly
This exercise covers how you can get arbitrary file read using CVE-2021-33564 against Refinery CMS
|
< 1 Hr. | 160 | PRO | |
|
|
Mongo IDOR II
This challenge covers how to recover a Mongo ID to leverage an IDOR
|
< 1 Hr. | 406 | PRO | |
|
|
PHP Snippet #09
This challenge covers the review of a snippet of code written in PHP
|
< 1 Hr. | 1624 | PRO | |
|
|
CVE-2022-21724: JDBC RCE PostgreSQL
This challenge covers how to gain code execution by leveraging a JDBC connection string with PostgreSQL
|
< 1 Hr. | 212 | PRO | |
|
|
HTTP 41
This challenge covers how to send specific HTTP requests
|
< 1 Hr. | 2772 | PRO | |
|
|
HTTP 43
This challenge covers how to send specific HTTP requests
|
< 1 Hr. | 2703 | PRO | |
|
|
HTTP 42
This challenge covers how to send specific HTTP requests
|
< 1 Hr. | 2800 | PRO |
Showing 61–90 of 269 exercises
Free Labs of the Month