Exercises

Exercise Avg. Time Difficulty Solved by Tier
Gogs RCE II
This exercise covers how to get code execution against the Git self hosted tool: Gogs.
< 1 Hr. hard 620 PRO
JWT VIII JWT
This exercise covers how to use the jku header to bypass an authentication based on JWT.
1-2 Hr. hard 1008 PRO
SAML: Signature Stripping
This exercise covers the exploitation of a signature stripping vulnerability in SAML
< 1 Hr. medium 2169 PRO
GraphQL Introspection
This exercise covers how to use introspection to get access to additional information in GraphQL.
< 1 Hr. easy 2461 PRO
Gogs RCE
This exercise covers how to get code execution against the Git self hosted tool: Gogs.
1-2 Hr. hard 695 PRO
Android 07
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
1-2 Hr. hard 1501 PRO
Android 06
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
< 1 Hr. hard 1759 PRO
Android 08
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
1-2 Hr. hard 1423 PRO
Android 05
This exercise will guide you through the process of reversing a simple obfuscated Android code to recover the encrypted data
1-2 Hr. medium 2066 PRO
PCAP 26
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 6193 PRO
PCAP 27
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 6138 PRO
PCAP 28
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 6110 PRO
PCAP 29
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 6093 PRO
PCAP 30
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 6061 PRO
PCAP 31
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 6035 PRO
PCAP 32
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 5954 PRO
PCAP 33
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 5844 PRO
PCAP 34
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 5914 PRO
PCAP 35
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 5999 PRO
Ruby 2.x Universal RCE Deserialization Gadget Chain
This exercise covers how to get code execution by using a Ruby Universal Gadget when an attacker controls the data passed to Marshal.load()
< 1 Hr. medium 1446 PRO
CVE-2018-10933: LibSSH auth bypass
This exercise covers how to bypass authentication on an SSH server based on libssh to gain a shell on the affected system
-- medium 0 FREE
Android 04
This exercise will guide you through the process of reversing a simple Android code
< 1 Hr. medium 2612 PRO
Android 03
This exercise will guide you through the process of extracting simple information from an APK
< 1 Hr. medium 3453 PRO
From SQL injection to Shell III SQL Injection
This exercise covers how to gain access to an administration interface using SQL injection followed by how to get command execution using ImageTragick
1-2 Hr. hard 1160 PRO
PCAP 21
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 6235 PRO
PCAP 22
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 6228 PRO
PCAP 23
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 6214 PRO
PCAP 24
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 6201 PRO
PCAP 25
This exercise is one of our challenges to help you learn how to analyze PCAP files
< 1 Hr. easy 6200 PRO
Android 02
This exercise will guide you through the process of extracting data from a simple database used by an Android app
< 1 Hr. easy 3729 PRO
1 16 17 18 19 20 21 22 26
Showing 541–570 of 753 exercises