Exercises
| Exercise | Avg. Time | Difficulty | Solved by | Tier | |
|---|---|---|---|---|---|
|
|
AI Fundamentals: Large Language Models | 37 | PRO | ||
|
|
AI Fundamentals: Inference & Sampling | 37 | PRO | ||
|
|
AI Fundamentals: Training an LLM | 37 | PRO | ||
|
|
AI Fundamentals: Limitations & Hallucinations | 36 | PRO | ||
|
|
AI Fundamentals: Prompting | 36 | PRO | ||
|
|
AI Fundamentals: Classic ML Algorithms | 47 | PRO | ||
|
|
AI Fundamentals: Deep Learning | 44 | PRO | ||
|
|
AI Fundamentals: Evaluating Models | 53 | PRO | ||
|
|
AI Fundamentals: Overfitting & Generalization | 58 | PRO | ||
|
|
AI Fundamentals: Embeddings & Vectors | 42 | PRO | ||
|
|
AI Fundamentals: Transformers & Attention | 39 | PRO | ||
|
|
AI Fundamentals: Neural Networks | 46 | PRO | ||
|
|
AI Fundamentals: Tokenization | 42 | PRO | ||
|
|
AI Fundamentals: Introduction | 97 | PRO | ||
|
|
AI Fundamentals: How Models Learn | 68 | PRO | ||
|
|
AI Fundamentals: Types of Machine Learning | 71 | PRO | ||
|
|
AI Fundamentals: Data, Features & Labels | 80 | PRO | ||
|
|
GHSA-69X8-B
This challenge covers the review of a vulnerability in a python codebase and its patch
|
40 | PRO | ||
|
|
GHSA-69X8-A
This challenge covers the review of a vulnerability in a python codebase and its patch
|
45 | PRO | ||
|
|
PHP eval() Class Hoisting RCE
This challenge covers an unauthenticated remote code execution reproducing MantisBT CVE-2026-49273: a value is validated with eval('return; ...'), but PHP hoists class declarations past the return; at compile time, letting an attacker pre-declare the class the app then autoloads and instantiates.
|
< 1 Hr. | 14 | PRO | |
|
|
Fastjson @JSONType RCE on default embedded Tomcat (/proc/self/fd)
This challenge is the second in the fastjson @JSONType series. Unlike lab I it runs on a stock Spring Boot app on the latest JDK that parses on the Tomcat request thread with no classloader wiring. A direct jar:http payload only yields SSRF there; remote code execution comes from the two-request /proc/self/fd variant, whose file: class name has no '//', so Tomcat's own webapp classloader defines it on the request thread.
|
2-4 Hr. | 9 | PRO | |
|
|
Fastjson @JSONType jar: URL RCE
This challenge covers a remote code execution in fastjson 1.2.83 with autoType disabled, by abusing the @JSONType trust probe in ParserConfig.checkAutoType together with a jar:http:// class name loaded through Spring Boot's LaunchedURLClassLoader on JDK 8.
|
< 1 Hr. | 10 | PRO | |
|
|
wp2shell: CVE-2026-63030 & CVE-2026-60137
CVE-2026-63030
CVE-2026-60137
WordPress
Remote Code Execution
This challenge covers gaining a shell on WordPress by chaining CVE-2026-63030 and CVE-2026-60137.
|
2-4 Hr. | 18 | PRO | |
|
|
H2 INIT Parameter RCE II | < 1 Hr. | 15 | PRO | |
|
|
CVE-2026-XX792
This challenge covers the review of a CVE in a typescript codebase and its patch
|
44 | PRO | ||
|
|
CVE-2026-XX957
This challenge covers the review of a CVE in a typescript codebase and its patch
|
< 1 Hr. | 49 | PRO | |
|
|
CVE-2026-XX464
This challenge covers the review of a CVE in a typescript codebase and its patch
|
49 | PRO | ||
|
|
H2 INIT Parameter RCE | < 1 Hr. | 17 | PRO | |
|
|
SAML: Transform RCE
This exercise covers the exploitation of an RCE in SAML by leveraging a vulnerable version of xmlsec
|
< 1 Hr. | 18 | PRO | |
|
|
Web Fundamentals: Proxy | 105 | PRO |
Showing 31–60 of 805 exercises
Free Labs of the Month