Exercises

Exercise Avg. Time Difficulty Solved by Tier
OAuth2: Client Server XSS
This exercise covers the exploitation of a Cross-Site Scripting in an OAuth2 Client and Server
< 1 Hr. hard 397 PRO
Zip symlink
This exercise covers how you can create a malicious Zip file and use it to gain access to sensitive files.
< 1 Hr. medium 619 PRO
Code Review 08
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. easy 577 PRO
SAML: Comment Injection
This exercise covers the exploitation of a comment injection vulnerability in SAML
< 1 Hr. medium 1803 PRO
Unicode and Downcase
This exercise covers how you can use unicode to gain access to an admin account.
< 1 Hr. medium 624 PRO
Code Review 07
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 480 PRO
Recon 10
This exercise covers visual content discovery
< 1 Hr. medium 7061 FREE
Recon 00
This exercise covers the robots.txt file
< 1 Hr. easy 23353 FREE
Recon 02
This exercise covers the security.txt file
< 1 Hr. easy 19706 FREE
Recon 03
This exercise covers directory listing
< 1 Hr. easy 17627 FREE
Java Serialize 01
This exercise is one of our challenges to help you learn Java Serialisation exploitation
< 1 Hr. easy 463 PRO
Unicode and Uppercase
This exercise covers how you can use unicode to gain access to an admin account.
< 1 Hr. medium 703 PRO
Code Review 06
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. medium 429 PRO
Cross-Site Leak
This exercise covers how to use Cross-Site Leak to recover sensitive information
1-2 Hr. hard 600 PRO
From SQL injection to Shell III: PostgreSQL Edition SQL Injection
This exercise covers how to gain access to an administration interface using a SQL injection, and how to get command execution using Ghostscript
< 1 Hr. medium 274 PRO
OAuth2: Client CSRF II
This exercise covers the exploitation of a CSRF in an OAuth2 Client
1-2 Hr. medium 518 PRO
XSS Include XSS
This exercise covers how to use Cross-Site-Scripting Include to leak information
< 1 Hr. easy 1407 PRO
OAuth2: Client CSRF
This exercise covers the exploitation of a CSRF in an OAuth2 Client
< 1 Hr. medium 998 PRO
Code Review 05
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 481 PRO
Code Review 04
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 604 PRO
JS Prototype Pollution
This exercise covers how to exploit Prototype Pollution against a JavaScript application
< 1 Hr. easy 992 PRO
OAuth2: Authorization Server CSRF
This exercise covers the exploitation of a CSRF in an OAuth2 Authorization Server
1-2 Hr. easy 1204 PRO
Code Review 03
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. hard 522 PRO
SSRF in PDF generation
This exercise covers how you can read arbitrary files when an application generates pdfs from provided links
< 1 Hr. easy 940 PRO
OAuth2: Github HTTP HEAD
This exercise covers the exploitation of the HTTP HEAD issue impacting Github in 2019
< 1 Hr. hard 481 PRO
SVG XSS
This exercise covers how to use an SVG to trigger a Cross-Site-Scripting
< 1 Hr. medium 1922 PRO
Apache Pluto RCE
This exercise covers how to gain code execution on Apache Pluto 3.0.0 due to a flaw in the authorization logic
< 1 Hr. medium 573 PRO
JSON Cross-Site Request Forgery
This exercise details the exploitation of a Cross-Site Request Forgery when JSON is used
< 1 Hr. medium 1538 PRO
Cross-Site Request Forgery
This exercise details the exploitation of a Cross-Site Request Forgery to gain access to sensitive data
< 1 Hr. medium 1578 PRO
Code Review 02
This exercise is one of our challenges to help you learn how to review real source code
< 1 Hr. medium 704 PRO
1 16 17 18 19 20 21 22 27
Showing 541–570 of 805 exercises