Exercises

Exercise Avg. Time Difficulty Solved by Tier
AI Fundamentals: Large Language Models hard 37 PRO
AI Fundamentals: Inference & Sampling hard 37 PRO
AI Fundamentals: Training an LLM hard 37 PRO
AI Fundamentals: Limitations & Hallucinations hard 36 PRO
AI Fundamentals: Prompting hard 36 PRO
AI Fundamentals: Classic ML Algorithms hard 47 PRO
AI Fundamentals: Deep Learning hard 44 PRO
AI Fundamentals: Evaluating Models hard 53 PRO
AI Fundamentals: Overfitting & Generalization hard 58 PRO
AI Fundamentals: Embeddings & Vectors hard 42 PRO
AI Fundamentals: Transformers & Attention hard 39 PRO
AI Fundamentals: Neural Networks hard 46 PRO
AI Fundamentals: Tokenization hard 42 PRO
AI Fundamentals: Introduction hard 97 PRO
AI Fundamentals: How Models Learn hard 68 PRO
AI Fundamentals: Types of Machine Learning hard 71 PRO
AI Fundamentals: Data, Features & Labels hard 80 PRO
GHSA-69X8-B
This challenge covers the review of a vulnerability in a python codebase and its patch
hard 40 PRO
GHSA-69X8-A
This challenge covers the review of a vulnerability in a python codebase and its patch
hard 45 PRO
PHP eval() Class Hoisting RCE
This challenge covers an unauthenticated remote code execution reproducing MantisBT CVE-2026-49273: a value is validated with eval('return; ...'), but PHP hoists class declarations past the return; at compile time, letting an attacker pre-declare the class the app then autoloads and instantiates.
< 1 Hr. medium 14 PRO
Fastjson @JSONType RCE on default embedded Tomcat (/proc/self/fd)
This challenge is the second in the fastjson @JSONType series. Unlike lab I it runs on a stock Spring Boot app on the latest JDK that parses on the Tomcat request thread with no classloader wiring. A direct jar:http payload only yields SSRF there; remote code execution comes from the two-request /proc/self/fd variant, whose file: class name has no '//', so Tomcat's own webapp classloader defines it on the request thread.
2-4 Hr. hard 9 PRO
Fastjson @JSONType jar: URL RCE
This challenge covers a remote code execution in fastjson 1.2.83 with autoType disabled, by abusing the @JSONType trust probe in ParserConfig.checkAutoType together with a jar:http:// class name loaded through Spring Boot's LaunchedURLClassLoader on JDK 8.
< 1 Hr. hard 10 PRO
wp2shell: CVE-2026-63030 & CVE-2026-60137 CVE-2026-63030 CVE-2026-60137 WordPress Remote Code Execution
This challenge covers gaining a shell on WordPress by chaining CVE-2026-63030 and CVE-2026-60137.
2-4 Hr. medium 18 PRO
H2 INIT Parameter RCE II < 1 Hr. hard 15 PRO
CVE-2026-XX792
This challenge covers the review of a CVE in a typescript codebase and its patch
hard 44 PRO
CVE-2026-XX957
This challenge covers the review of a CVE in a typescript codebase and its patch
< 1 Hr. hard 49 PRO
CVE-2026-XX464
This challenge covers the review of a CVE in a typescript codebase and its patch
hard 49 PRO
H2 INIT Parameter RCE < 1 Hr. hard 17 PRO
SAML: Transform RCE
This exercise covers the exploitation of an RCE in SAML by leveraging a vulnerable version of xmlsec
< 1 Hr. medium 18 PRO
Web Fundamentals: Proxy hard 105 PRO
1 2 3 4 5 27
Showing 31–60 of 805 exercises