Exercises
| Exercise | Avg. Time | Difficulty | Solved by | Tier | |
|---|---|---|---|---|---|
|
|
Web Fundamentals: URL Parsing | < 1 Hr. | 237 | PRO | |
|
|
Web Fundamentals: Virtual Hosts | < 1 Hr. | 140 | PRO | |
|
|
Web Fundamentals: HTML Forms | < 1 Hr. | 171 | PRO | |
|
|
Web Fundamentals: JSON | < 1 Hr. | 151 | PRO | |
|
|
Web Fundamentals: URL Encoding | < 1 Hr. | 214 | PRO | |
|
|
Web Fundamentals: HTML | < 1 Hr. | 194 | PRO | |
|
|
Web Fundamentals: Cookies | < 1 Hr. | 159 | PRO | |
|
|
JS Sandbox: Keyword Blocklist Bypass
This exercise covers bypassing indexOf/includes blocklists with bracket notation and string concatenation.
|
< 1 Hr. | 37 | PRO | |
|
|
JS Sandbox: The Function Constructor
This exercise covers using Function(...)() as an eval alternative to execute arbitrary code in an app that blocks eval.
|
< 1 Hr. | 42 | PRO | |
|
|
JS Sandbox: From Sandbox Escape to RCE
This exercise covers the standard Node.js RCE chain: process -> mainModule -> require('child_process') -> execSync.
|
< 1 Hr. | 42 | PRO | |
|
|
JS Sandbox: Prototype Chain Navigation
This exercise covers navigating __proto__, .constructor, and .prototype from a string literal to reach the Function constructor.
|
< 1 Hr. | 50 | PRO | |
|
|
CVE-2026-XX953
This challenge covers the review of a CVE in a python codebase and its patch
|
< 1 Hr. | 88 | PRO | |
|
|
CVE-2026-XX928
This challenge covers the review of a CVE in a python codebase and its patch
|
< 1 Hr. | 68 | PRO | |
|
|
CVE-2026-XX230
This challenge covers the review of a CVE in a python codebase and its patch
|
< 1 Hr. | 76 | PRO | |
|
|
CVE-2026-XX977
This challenge covers the review of a CVE in a python codebase and its patch
|
< 1 Hr. | 80 | PRO | |
|
|
CVE-2026-XX762
This challenge covers the review of a CVE in a python codebase and its patch
|
< 1 Hr. | 75 | PRO | |
|
|
CVE-2026-XX790
This challenge covers the review of a CVE in a python codebase and its patch
|
< 1 Hr. | 74 | PRO | |
|
|
CVE-2026-XX130
This challenge covers the review of a CVE in a python codebase and its patch
|
< 1 Hr. | 78 | PRO | |
|
|
CVE-2023-51XX9
This challenge covers the review of a CVE in a python codebase and its patch
|
< 1 Hr. | 80 | PRO | |
|
|
JWT: Refresh Token Bypass
This exercise covers bypassing JWT refresh token validation to maintain unauthorized access.
|
< 1 Hr. | 74 | PRO | |
|
|
CVE-2026-2413X
This challenge covers the review of a CVE in a python codebase and its patch
|
< 1 Hr. | 75 | PRO | |
|
|
CVE-2026-21XX3
This challenge covers the review of a CVE in a Python codebase and its patch
|
< 1 Hr. | 73 | PRO | |
|
|
CVE-2023-3X829
This challenge covers the review of a CVE in a Python codebase and its patch
|
97 | PRO | ||
|
|
CVE-2025-X23XX
This challenge covers the review of a CVE in a javascript codebase and its patch
|
103 | PRO | ||
|
|
CVE-2025-X9X28
This challenge covers the review of a CVE in a typescript codebase and its patch
|
100 | PRO | ||
|
|
CVE-2024-X170X
This challenge covers the review of a CVE in a JavaScript codebase and its patch
|
126 | PRO | ||
|
|
CVE-2026-X189X
This challenge covers the review of a CVE in a python codebase and its patch
|
< 1 Hr. | 116 | PRO | |
|
|
CVE-2026-XX871
This challenge covers the review of a CVE in a python codebase and its patch
|
106 | PRO | ||
|
|
CVE-2026-XX951
This challenge covers the review of a CVE in a javascript codebase and its patch
|
102 | PRO | ||
|
|
CVE-2025-XX953
This challenge covers the review of a CVE in a typescript codebase and its patch
|
117 | PRO |
Showing 91–120 of 805 exercises
Free Labs of the Month