Exercises
| Exercise | Avg. Time | Difficulty | Solved by | Tier | |
|---|---|---|---|---|---|
|
|
Code Review 15
This exercise is one of our challenges to help you learn how to review real source code
|
< 1 Hr. | 537 | PRO | |
|
|
Code Review 14
This exercise is one of our challenges to help you learn how to review real source code
|
< 1 Hr. | 564 | PRO | |
|
|
CVE-2020-14343: PyYAML unsafe loader
This exercise covers how you can gain code execution when an application use a vulnerable version of PyYAML and relies on load()
|
< 1 Hr. | 375 | PRO | |
|
|
OAuth2: State Fixation
This exercise covers the exploitation of a state fixation in an OAuth2 Client
|
< 1 Hr. | 439 | PRO | |
|
|
Code Review 13
This exercise is one of our challenges to help you learn how to review real source code
|
< 1 Hr. | 473 | PRO | |
|
|
CVE-2020-7115: Aruba Clearpass RCE
This exercise covers a remote command execution issue on Aruba Clearpass RCE
|
< 1 Hr. | 239 | PRO | |
|
|
Code Review 12
This exercise is one of our challenges to help you learn how to review real source code
|
< 1 Hr. | 602 | PRO | |
|
|
OAuth2: Predictable State II
This exercise covers the exploitation of a predictable state in an OAuth2 Client
|
< 1 Hr. | 292 | PRO | |
|
|
Recon 13
In this challenge, you need to find the TXT record linked to key.z.hackycorp.com
|
< 1 Hr. | 7057 | FREE | |
|
|
Recon 14
In this challenge, you need to find a TXT record by doing a zone transfer on z.hackycorp.com
|
< 1 Hr. | 6345 | FREE | |
|
|
Recon 15
In this challenge, you need to find a TXT record by doing a zone transfer on the internal zone "int"
|
< 1 Hr. | 5775 | FREE | |
|
|
Recon 16
In this challenge, you need to find the version of Bind used
|
< 1 Hr. | 5931 | FREE | |
|
|
EDDSA vulnerability in Monocypher
Crypto
This exercise covers the exploitation of a vulnerability impacting Monocypher.
|
< 1 Hr. | 202 | PRO | |
|
|
Code Review 11
This exercise is one of our challenges to help you learn how to review real source code
|
< 1 Hr. | 416 | PRO | |
|
|
OAuth2: Predictable State
This exercise covers the exploitation of a predictable state in an OAuth2 Client
|
< 1 Hr. | 317 | PRO | |
|
|
Code Review 10
This exercise is one of our challenges to help you learn how to review real source code
|
< 1 Hr. | 525 | PRO | |
|
|
Recon 11 | < 1 Hr. | 6481 | FREE | |
|
|
Recon 12 | < 1 Hr. | 7035 | FREE | |
|
|
Unicode and NFKC
This exercise covers how to leverage unicode to exploit a directory traversal
|
< 1 Hr. | 342 | PRO | |
|
|
SAML: Trusted Embedded Key
This exercise covers the exploitation of a Service Provider (SP) that doesn't check the certificate provided in the SAMLResponse
|
< 1 Hr. | 556 | PRO | |
|
|
Recon 06
This exercise covers default vhost
|
< 1 Hr. | 12589 | FREE | |
|
|
Recon 07
This exercise covers default TLS vhost
|
< 1 Hr. | 11457 | FREE | |
|
|
Recon 08
This exercise covers aliases in TLS certificates
|
< 1 Hr. | 10414 | FREE | |
|
|
Recon 09 | < 1 Hr. | 11058 | FREE | |
|
|
CVE-2020-8163: Rails local name RCE
This exercise details the exploitation of CVE-2020-8163 to gain code execution
|
< 1 Hr. | 238 | PRO | |
|
|
SAML: Known Key
This exercise covers the exploitation of a known key in SAML
|
< 1 Hr. | 572 | PRO | |
|
|
Code Review 09
This exercise is one of our challenges to help you learn how to review real source code
|
< 1 Hr. | 459 | PRO | |
|
|
Recon 04
This exercise covers common interesting directories
|
< 1 Hr. | 17780 | FREE | |
|
|
Recon 05
This exercise covers simple directory bruteforcing
|
< 1 Hr. | 12977 | FREE | |
|
|
Recon 01
This exercise covers 404 error pages
|
< 1 Hr. | 23303 | FREE |
Showing 511–540 of 805 exercises
Free Labs of the Month