Exercises

Exercise Avg. Time Difficulty Solved by Tier
SAML: Signature Stripping
This exercise covers the exploitation of a signature stripping vulnerability in SAML
< 1 Hr. medium 2197 PRO
GraphQL Introspection
This exercise covers how to use introspection to get access to additional information in GraphQL.
< 1 Hr. easy 2471 PRO
Gogs RCE
This exercise covers how to get code execution against the Git self hosted tool: Gogs.
< 1 Hr. hard 701 PRO
Android 07
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
< 1 Hr. hard 1510 PRO
Android 08
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
< 1 Hr. hard 1432 PRO
Android 06
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
< 1 Hr. hard 1770 PRO
Android 05
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
< 1 Hr. medium 2079 PRO
Ruby 2.x Universal RCE Deserialization Gadget Chain
This exercise covers how to get code execution by using a Ruby Universal Gadget when an attacker controls the data passed to Marshal.load()
< 1 Hr. medium 1453 PRO
Android 04
This exercise will guide you through the process of reversing a simple Android code
< 1 Hr. medium 2625 PRO
Android 03
This exercise will guide you through the process of extracting simple information from an APK
< 1 Hr. medium 3469 PRO
From SQL injection to Shell III SQL Injection
This exercise covers how to gain access to an administration interface using SQL injection followed by how to get command execution using ImageTragick
< 1 Hr. hard 1171 PRO
IDOR to Shell
This exercise covers how to get code execution by chaining vulnerabilities in a Ruby-on-Rails application
< 1 Hr. hard 1096 PRO
Android 01
This exercise will guide you through the process of extracting simple information from an APK
< 1 Hr. easy 4066 PRO
JWT V JWT
This exercise covers the exploitation of a trivial secret used to sign JWT tokens.
< 1 Hr. medium 3210 PRO
JWT IV JWT
This exercise covers the exploitation of a vulnerability similar to the recent CVE-2017-17405 impacting Ruby Net::FTP
< 1 Hr. medium 2792 PRO
SAML: Introduction
This exercise covers the exploitation of a signature stripping vulnerability in SAML
< 1 Hr. easy 3042 PRO
CVE-2016-10033: PHPMailer RCE
This exercise covers a remote code execution vulnerability in PHPMailer
< 1 Hr. medium 3855 PRO
Cipher block chaining Crypto
This exercise details how to tamper with data encrypted using CBC
< 1 Hr. medium 3034 PRO
Struts s2-045
This exercise covers a Remote Code Execution in Struts 2.
< 1 Hr. medium 2856 PRO
CVE-2016-2098
This exercise covers a remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data
< 1 Hr. medium 3763 PRO
ECDSA Crypto
This exercise covers the exploitation of a weakness in the usage of ECDSA
< 1 Hr. hard 375 PRO
Werkzeug DEBUG
This challenge was written for Ruxcon CTF 2015 and cover the Debug mode of Werkzeug/Flask
< 1 Hr. medium 1639 PRO
Unickle
This challenge was written for Ruxcon CTF 2015. It's an SQL injection mixed with a remote code execution.
< 1 Hr. hard 691 PRO
CVE-2015-3224
This exercise is a challenge written for Nullcon CTF in 2015
< 1 Hr. medium 1649 PRO
Luhn
This challenge was written for Ruxcon CTF 2015. It's an SQL injection with a twist
< 1 Hr. hard 639 PRO
Introduction 00
This exercise will guide you through the process of scoring on an exercise to get it marked as completed
< 1 Hr. easy 32196 PRO
Introduction 03
This exercise will guide through the process of scoring an exercise to mark it as completed. However, this time, you will run commands on the underlying operating system. You will need to run the score command with your UUID.
< 1 Hr. easy 29969 PRO
Introduction 02
This exercise will guide through the process of scoring an exercise to mark it as completed. Finding the key is just a little bit harder than the previous exercise.
< 1 Hr. easy 30690 PRO
Introduction 01
This exercise will guide through the process of scoring an exercise to mark it as completed
< 1 Hr. easy 31107 PRO
CVE-2013-0156: Rails Object Injection
This exercise covers the exploitation of a code execution in Ruby-on-Rails using XML and YAML.
< 1 Hr. medium 4091 PRO
1 2 3 4
Showing 61–90 of 104 exercises