Exercises

Exercise Avg. Time Difficulty Solved by Tier
From SQL injection to Shell III: PostgreSQL Edition SQL Injection
This exercise covers how to gain access to an administration interface using a SQL injection, and how to get command execution using Ghostscript
2-4 Hr. medium 251 PRO
From SQL injection to Shell III SQL Injection
This exercise covers how to gain access to an administration interface using SQL injection followed by how to get command execution using ImageTragick
1-2 Hr. hard 1138 PRO
SQL Injection 06 SQL Injection
This exercise is one of our challenges on SQL Injections
< 1 Hr. medium 9499 PRO
SQL Injection 04 SQL Injection
This exercise is one of our challenges on SQL Injections
< 1 Hr. medium 10088 PRO
SQL Injection 05 SQL Injection
This exercise is one of our challenges on SQL Injections
< 1 Hr. easy 9992 PRO
SQL Injection 01 SQL Injection
This exercise is one of our challenges on SQL Injections
< 1 Hr. easy 11540 PRO
SQL Injection 02 SQL Injection
This exercise is one of our challenges on SQL Injections
< 1 Hr. easy 11044 PRO
SQL Injection 03 SQL Injection
This exercise is one of our challenges on SQL Injections
< 1 Hr. easy 10712 PRO
XSS and MySQL FILE XSS
This exercise explains how to exploit a Cross-Site Scripting vulnerability to obtain an administrator's cookies, and how you can use their session to gain access to the administration panel, and find a SQL injection to gain code execution
-- medium 0 FREE
From SQL Injection to Shell II SQL Injection
This exercise explains how you can, from a blind SQL injection, gain access to the administration console. Then once in the administration console, how you can run commands on the system.
1-2 Hr. medium 45 FREE
From SQL Injection to Shell: PostgreSQL edition SQL Injection
This exercise explains how you can from a SQL injection gain access to the administration console, and from there, how you can run commands on the underlying system
< 1 Hr. medium 19 FREE
From SQL Injection to Shell SQL Injection
This exercise demonstrates how to leverage a SQL injection to gain access to the admin console, and from there, how to execute commands on the underlying system
< 1 Hr. medium 8280 FREE
Showing 1–12 of 12 exercises