What you will learn
- Read HTTP requests and responses
- Understand why common web vulnerabilities occur
- Connect exploitation techniques to secure implementation
Learn HTTP, authentication, input validation, and common web vulnerabilities in isolated practice environments.
32 challenges available.
WebLevel 1Web pages contain a lot of information that isn't visible on the surface. Looking at HTML source code, you can often…
WebLevel 1This page has a password-protected area. However, because the password check is done in JavaScript, you can find the…
WebLevel 1Websites use a mechanism called cookies to store information in your browser. They're used for managing login states,…
WebLevel 1This login form has an SQL Injection vulnerability. Log in as admin without proper credentials and retrieve the flag.
WebLevel 1Websites often serve a robots.txt file for crawlers. In this challenge, check whether a file that robots.txt tells…
WebLevel 1When an Nginx server has directory index listing (autoindex) enabled, anyone can browse the full file listing of a…
WebLevel 1This application grants access based on the value of a specific HTTP header. Even values the browser never sends by…
WebLevel 1This page checks a URL GET parameter's value using client-side JavaScript and reveals a flag when the condition is…
WebLevel 1The login form contains a hidden input field that is invisible in the rendered page. Inspect it with developer tools…
WebLevel 1A protected area is guarded by HTTP Basic Authentication, but the developer accidentally left the credentials in an…
WebLevel 1Accessing a certain page immediately redirects you elsewhere. Browsers automatically follow redirects, so think about…
WebLevel 1This web application has a basic XSS vulnerability. Find where input is reflected in the guestbook and retrieve the…
WebLevel 2KinoGadget's internal "Employee Access Portal" runs on a legacy authentication system. The lead developer is rumored…
WebLevel 2BlogSearch is a simple search engine for blog articles. The search query is reflected back on the results page — check…
WebLevel 2ImageVault is an image hosting service that accepts JPG, PNG, and GIF uploads. If its validation only checks the end…
WebLevel 2This app is a diagnostic tool that runs ping against a host you supply. If the host input is passed straight into a…
WebLevel 2The UserProfile Service exposes an API that returns profile information for a given user ID. Check whether the service…
WebLevel 2Clues found after breaching the employee portal point to an isolated research lab system codenamed CHIMERA. It…
WebLevel 2FileShare lets users list and download files from a shared folder. Check whether the filename parameter passed to the…
WebLevel 2This contact form serializes its input as XML and sends it to the server, which parses it and echoes the result.…
WebLevel 2This banking app lets a logged-in user transfer money. Check whether CSRF protections exist by seeing if a separate…
WebLevel 2This URL Fetcher service retrieves and displays the content of any URL a user provides. Check whether it can be…
WebLevel 3This user search app only reports whether a username exists, without showing direct query results. Investigate whether…
WebLevel 3This comment board is protected by a Content Security Policy restricting script execution to the site itself and a…