Build Your Skills — Intermediate — hands-on

🧪 LabAdvanced✓ Free

Advanced SQL Injection

Second-order SQLi, stored procedures, and WAF bypass techniques.

Start lab →⏱ 3 hours
🧪 LabIntermediate✓ Free

Advanced XSS & CSRF

XSS chaining, CSP bypass, CSRF token theft, and SameSite attribute bypass.

Start lab →⏱ 1.5 hours
🧪 LabIntermediate✓ Free

Attacking Authentication Mechanisms

2FA bypass, brute force protection bypass, and credential stuffing.

Start lab →⏱ 1.5 hours
🧪 LabAdvanced✓ Free

Blind SQL Injection

Boolean-based and time-based blind SQLi with sqlmap and manual methods.

Start lab →⏱ 3 hours
🧪 LabIntermediate✓ Free

Broken Authentication & Sessions

Session fixation, prediction, and authentication logic flaws.

Start lab →⏱ 1.5 hours
🧪 LabMedium✓ Free

File Upload Vulnerabilities

Bypass extension filters, MIME type checks, and upload webshells.

Start lab →⏱ 55 minutes
🧪 LabIntermediate✓ Free

Injection Attacks: XPath, LDAP & HTML-to-PDF

Exploit XML XPath and LDAP directory injection vulnerabilities.

Start lab →⏱ 1.5 hours
🧪 LabMedium✓ Free

Local & Remote File Inclusion

Path traversal, null byte injection, PHP wrappers, and remote file inclusion.

Start lab →⏱ 60 minutes
🧪 LabIntermediate✓ Free

NoSQL Injection

MongoDB operator injection, authentication bypass, and data extraction.

Start lab →⏱ 1.5 hours
🧪 LabIntermediate✓ Free

OAuth & JWT Attacks

alg:none bypass, RS256→HS256 confusion, JWT cracking, and OAuth code theft.

Start lab →⏱ 2 hours
🧪 LabIntermediate✓ Free

Server-Side Template Injection (SSTI)

Detect and exploit Jinja2, Twig, and Freemarker SSTI for RCE.

Start lab →⏱ 2 hours
📖 WorkbookIntermediate🔒 Free account

SQL Injection Fundamentals

In-band, blind, and out-of-band SQLi with manual and automated exploitation.

Read →⏱ ~4 hours
🧪 LabIntermediate✓ Free

SSRF Attacks

Internal service access, cloud metadata exploitation, and SSRF filter bypasses.

Start lab →⏱ 1.5 hours
🧪 LabIntermediate✓ Free

Subdomain Takeover

Enumerate dangling DNS, claim GitHub Pages and S3 buckets, exploit cookie scope.

Start lab →⏱ 1.5 hours
📖 WorkbookIntermediate🔒 Free account

Web Application Pentesting

OWASP Top 10, Burp Suite advanced usage, and web pentest methodology.

Read →⏱ 4 hours
🧪 LabIntermediate✓ Free

Web Attacks: IDOR, XXE & Verb Tampering

XXE external entity injection, blind XXE via OOB, and mass IDOR testing.

Start lab →⏱ 1.5 hours
🧪 LabBeginner✓ Free

WordPress Exploitation

WPScan, plugin CVEs, theme RCE, XML-RPC abuse, and brute force.

Start lab →⏱ 45 minutes

Go Advanced — Advanced — for practitioners