Exercises

Exercise Avg. Time Difficulty Solved by Tier
HTTP 09
This challenge covers how to send specific HTTP requests
< 1 Hr. medium 4071 PRO
HTTP 07
This challenge covers how to send specific HTTP requests
< 1 Hr. easy 4167 PRO
HTTP 06
This challenge covers how to send specific HTTP requests
< 1 Hr. easy 4258 PRO
HTTP 08
This challenge covers how to send specific HTTP requests
< 1 Hr. easy 4153 PRO
HTTP 03
This challenge covers how to send specific HTTP requests
< 1 Hr. easy 4626 PRO
HTTP 04
This challenge covers how to send specific HTTP requests
< 1 Hr. easy 4454 PRO
HTTP 05
This challenge covers how to send specific HTTP requests
< 1 Hr. easy 4372 PRO
HTTP 02
This challenge covers how to send specific HTTP requests
< 1 Hr. medium 4863 PRO
HTTP 01
This challenge covers how to send specific HTTP requests
< 1 Hr. easy 5129 PRO
API 01 API
This exercise is the API version of an exercise you already solved in the Essential Badge. You should use it to get more confident with discovering vulnerabilities without any hint on what to look for.
< 1 Hr. easy 3793 PRO
JWT Algorithm Confusion with RSA Public Key Recovery JWT
This exercise covers the exploitation of algorithm confusion when no public key is available
< 1 Hr. hard 244 PRO
SAML: Comment Injection II
This exercise covers the exploitation of a comment injection vulnerability in SAML
< 1 Hr. medium 676 PRO
Recon 24
In this challenge, you need to look for a file named key.txt in the place used to serve the assets for the main website
< 1 Hr. medium 5656 FREE
Recon 25
In this challenge, you need to look for a file named key2.txt in the place used to serve the assets for the main website
< 1 Hr. easy 3424 FREE
Recon 26
In this challenge, you need to look for a key in the JavaScript used by the website
< 1 Hr. medium 5363 FREE
SSRF via FFMPEG
This exercise covers how you can read arbitrary files when an application uses ffmpeg to render videos from a video you provide
< 1 Hr. medium 264 PRO
SAML: Signature Wrapping II
This exercise covers how to use Signature Wrapping to become an arbitrary user
< 1 Hr. hard 518 PRO
RCE via argument injection
This exercise covers a remote command execution vulnerability via argument injection
< 1 Hr. hard 70 PRO
Code Review 16
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. easy 569 PRO
Code Review 17
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. medium 443 PRO
SAML: Signature Wrapping
This exercise covers how to use Signature Wrapping to become an arbitrary user
< 1 Hr. hard 625 PRO
Recon 20
In this challenge, you need to look at the branches in repo3
< 1 Hr. easy 5693 FREE
Recon 21
In this challenge, you need to look at the information in the branches for repo4
< 1 Hr. easy 5564 FREE
Recon 22
In this challenge, you need to look in repo9 for deleted files
< 1 Hr. medium 5345 FREE
Recon 23
In this challenge, you need to look for sensitive information in commit messages
< 1 Hr. easy 5332 FREE
SAML: SAMLResponse forwarding
This exercise covers how to pass the SAMLResponse from one Service Provider to another
< 1 Hr. medium 559 PRO
CGI and Signature
This exercise covers the exploitation of a vulnerable CGI.
< 1 Hr. medium 250 PRO
Recon 17
In this challenge, you need to look at the name of the developer used in the repository test1
< 1 Hr. medium 6051 FREE
Recon 18
In this challenge, you need to look at the public repository of the developers in the organisation
< 1 Hr. medium 5730 FREE
Recon 19
In this challenge, you need to look at the email addresses used for commits in the repository repo7
< 1 Hr. medium 5402 FREE
1 14 15 16 17 18 19 20 27
Showing 481–510 of 805 exercises