Learn to exploit the bugs that shaped security.
A hands-on capture-the-flag built on real historical CVEs. Each challenge is a deliberately vulnerable app in its own isolated lab, so you learn to recognize and exploit a whole class of bug, safely.
- challenges
- 6
- categories
- 4
- points on offer
- 1,800
challenges
categories
points on offer
How it works
- 01
Pick a challenge
Each one wraps a real CVE from 2021 to 2022 in its own sandboxed, vulnerable app.
- 02
Exploit the bug
Reach the vulnerable endpoint, build the payload, and get code running or data leaking.
- 03
Submit the flag
Pull the flag off the box and submit it. Correct flags lock in your points once.
- 04
Climb the board
Points and solve times rank you against everyone else working the same labs.
Challenges
View allERMS SQL injection auth bypass
Bypass the login of a PHP employee-records app with a classic SQL injection and read what only an admin should see.
Dirty Pipe
Abuse a Linux kernel page-cache flaw to overwrite a file you should only be able to read, then escalate to root.
zgrep arbitrary file write
A newline in a filename confuses zgrep into running your commands. Turn an archive search into code execution.
Spring4Shell RCE
Exploit Spring's data binding on a WAR-deployed app to drop a web shell and run commands on the server.
SHA-3 buffer overflow
Feed a huge input to Python's SHA-3 implementation and trip a buffer overflow in the _sha3 module.
Text4Shell RCE
Smuggle a ${script:...} lookup into Apache Commons Text and make the interpolator execute your payload.