Exercises
| Exercise | Avg. Time | Difficulty | Solved by | Tier | |
|---|---|---|---|---|---|
|
|
HTTP 09
This challenge covers how to send specific HTTP requests
|
< 1 Hr. | 4071 | PRO | |
|
|
HTTP 07
This challenge covers how to send specific HTTP requests
|
< 1 Hr. | 4167 | PRO | |
|
|
HTTP 06
This challenge covers how to send specific HTTP requests
|
< 1 Hr. | 4258 | PRO | |
|
|
HTTP 08
This challenge covers how to send specific HTTP requests
|
< 1 Hr. | 4153 | PRO | |
|
|
HTTP 03
This challenge covers how to send specific HTTP requests
|
< 1 Hr. | 4626 | PRO | |
|
|
HTTP 04
This challenge covers how to send specific HTTP requests
|
< 1 Hr. | 4454 | PRO | |
|
|
HTTP 05
This challenge covers how to send specific HTTP requests
|
< 1 Hr. | 4372 | PRO | |
|
|
HTTP 02
This challenge covers how to send specific HTTP requests
|
< 1 Hr. | 4863 | PRO | |
|
|
HTTP 01
This challenge covers how to send specific HTTP requests
|
< 1 Hr. | 5129 | PRO | |
|
|
API 01
API
This exercise is the API version of an exercise you already solved in the Essential Badge. You should use it to get more confident with discovering vulnerabilities without any hint on what to look for.
|
< 1 Hr. | 3793 | PRO | |
|
|
JWT Algorithm Confusion with RSA Public Key Recovery
JWT
This exercise covers the exploitation of algorithm confusion when no public key is available
|
< 1 Hr. | 244 | PRO | |
|
|
SAML: Comment Injection II
This exercise covers the exploitation of a comment injection vulnerability in SAML
|
< 1 Hr. | 676 | PRO | |
|
|
Recon 24
In this challenge, you need to look for a file named key.txt in the place used to serve the assets for the main website
|
< 1 Hr. | 5656 | FREE | |
|
|
Recon 25
In this challenge, you need to look for a file named key2.txt in the place used to serve the assets for the main website
|
< 1 Hr. | 3424 | FREE | |
|
|
Recon 26
In this challenge, you need to look for a key in the JavaScript used by the website
|
< 1 Hr. | 5363 | FREE | |
|
|
SSRF via FFMPEG
This exercise covers how you can read arbitrary files when an application uses ffmpeg to render videos from a video you provide
|
< 1 Hr. | 264 | PRO | |
|
|
SAML: Signature Wrapping II
This exercise covers how to use Signature Wrapping to become an arbitrary user
|
< 1 Hr. | 518 | PRO | |
|
|
RCE via argument injection
This exercise covers a remote command execution vulnerability via argument injection
|
< 1 Hr. | 70 | PRO | |
|
|
Code Review 16
This exercise is one of our challenges to help you learn how to review real source code
|
< 1 Hr. | 569 | PRO | |
|
|
Code Review 17
This exercise is one of our challenges to help you learn how to review real source code
|
< 1 Hr. | 443 | PRO | |
|
|
SAML: Signature Wrapping
This exercise covers how to use Signature Wrapping to become an arbitrary user
|
< 1 Hr. | 625 | PRO | |
|
|
Recon 20
In this challenge, you need to look at the branches in repo3
|
< 1 Hr. | 5693 | FREE | |
|
|
Recon 21
In this challenge, you need to look at the information in the branches for repo4
|
< 1 Hr. | 5564 | FREE | |
|
|
Recon 22
In this challenge, you need to look in repo9 for deleted files
|
< 1 Hr. | 5345 | FREE | |
|
|
Recon 23
In this challenge, you need to look for sensitive information in commit messages
|
< 1 Hr. | 5332 | FREE | |
|
|
SAML: SAMLResponse forwarding
This exercise covers how to pass the SAMLResponse from one Service Provider to another
|
< 1 Hr. | 559 | PRO | |
|
|
CGI and Signature
This exercise covers the exploitation of a vulnerable CGI.
|
< 1 Hr. | 250 | PRO | |
|
|
Recon 17
In this challenge, you need to look at the name of the developer used in the repository test1
|
< 1 Hr. | 6051 | FREE | |
|
|
Recon 18
In this challenge, you need to look at the public repository of the developers in the organisation
|
< 1 Hr. | 5730 | FREE | |
|
|
Recon 19
In this challenge, you need to look at the email addresses used for commits in the repository repo7
|
< 1 Hr. | 5402 | FREE |
Showing 481–510 of 805 exercises
Free Labs of the Month