Challenges
Six labs across four categories. Each one is a real CVE you exploit end to end.
6 challenges (loading latest…)
ERMS SQL injection auth bypass
Bypass the login of a PHP employee-records app with a classic SQL injection and read what only an admin should see.
Dirty Pipe
Abuse a Linux kernel page-cache flaw to overwrite a file you should only be able to read, then escalate to root.
zgrep arbitrary file write
A newline in a filename confuses zgrep into running your commands. Turn an archive search into code execution.
Spring4Shell RCE
Exploit Spring's data binding on a WAR-deployed app to drop a web shell and run commands on the server.
SHA-3 buffer overflow
Feed a huge input to Python's SHA-3 implementation and trip a buffer overflow in the _sha3 module.
Text4Shell RCE
Smuggle a ${script:...} lookup into Apache Commons Text and make the interpolator execute your payload.