Exercises

Exercise Avg. Time Difficulty Solved by Tier
ObjectInputStream
This exercise covers the exploitation of a call to readObject in a Spring application
< 1 Hr. medium 4396 PRO
XMLDecoder
This exercise covers the exploitation of an application using XMLDecoder
< 1 Hr. medium 5497 PRO
CVE-2014-1266
This exercise covers how to intercept an HTTPs connection
1-2 Hr. hard 1081 PRO
CVE-2011-0228
This exercise covers how to intercept an HTTPs connection
1-2 Hr. hard 1235 PRO
Intercept 03
This exercise covers how to intercept an HTTPs connection with hostname verification.
< 1 Hr. medium 1520 PRO
Intercept 02
This exercise covers how to intercept an HTTPs connection.
< 1 Hr. medium 1674 PRO
Intercept 01
This exercise covers how to intercept an HTTP connection.
1-2 Hr. easy 1850 PRO
Struts devMode
This exercise covers how to get code execution when a Struts application is running in devMode
-- medium 0 PRO
JSON Web Token None Algorithm JWT
This exercise covers the exploitation of a signature weakness in a JWT library.
< 1 Hr. easy 10359 PRO
Cross-Origin Resource Sharing
This exercise covers Cross-Origin Resource Sharing and how it can be used to bypass CSRF protection if it's misconfigured
-- medium 0 PRO
API to Shell API
This exercise covers the exploitation of PHP type confusion to bypass a signature and the exploitation of unserialize.
2-4 Hr. hard 3553 PRO
Pickle Code Execution
This exercise covers the exploitation of Python's pickle when used to deserialize untrusted data
< 1 Hr. medium 6573 PRO
1 2 3 4
Showing 91–102 of 102 exercises