This is what you will do during your lab time
| Battle | Vulnerabilities | Difficulty | What you will learn | |||
|---|---|---|---|---|---|---|
Poema reading club 1 They read and think But you know, what you see is not always what you get in life. Uncover their secrets and master the use of Burp Suite and Dirbuster. Learn how to crawl a website, find hidden files and analyze web applications. Oh, by the way, Cicero will be glad to help you during your battle giving the hints you want, when you need them. |
Hidden directories | Easy |
|
|||
Poema reading club 2 Fire up Burp Suite and analyze the website. |
XSS | Easy |
|
|||
Poema reading club 3 But you know how these web developers are, they try do it quick and dirty. Make sure that you find a way to get around their protection and produce a working exploit for the XSS that yes, is still there. |
XSS | Medium |
|
|||
Poema reading club 4 It's a system allowing Miss. Charlotte and the other chicks to comment on their latest readings. A new challenge for you, sharpen your sword, this one has tigers and fighters from the far east legions. |
XSS | Medium |
|
|||
Poema reading club 5 Yes, it' a new feature of the Poema reading club that requires your Fu to be tested. Guess what? There is some user input involved... |
SQL Injection | Medium |
|
|||
Poema reading club 6 The poema reading club is getting serious about their infrastructure and so should you with this new battle. Bring your best swords and your most shining sandles, this is gonna be epic! |
SQL Injection | Medium |
|
|||
Poema reading club 7 Are your tools finding these vulnerabilities? Prove your skills, use your advanced SQL injection techniques. |
SQL Injection Cookie manipulation |
Difficult |
|
|||
Arrogant Bank Arrogant bank inc. is not unlike any other bank in the world. Are you able to become the richest in the bank? Prove it! |
SQL Injection, Cookie Manipulation | Medium |
|
|||
Tomato Lovers 1 They recently became a new client of yours and you have to carry out a penetration test on their website. Find out any security issues related to their photo sharing application. |
Unrestricted File Upload | Easy |
|
|||
Tomato lovers 2 Please provide a proof of concept for the unfortunate web developer and demonstrate that their security mechanism is really pathetic. |
Unrestricted File Upload | Medium |
|
|||
Tomato lovers 3 Please find all the CSRF in their website and build a proof of concept for the admin. You know, they don't believe you until they see the danger. |
CSRF | Medium |
|
|||
Music shop 1 If you are Justin's fan you can make sure that the website is protected from haters. If you are a hater, you can make sure to do some Justice. |
Insecure Direct Object Reference, Cookie manipulation |
Medium |
|
|||
| Music shop 2 They fixed any logic flaw affecting their website. Or so they said. This time you have to really have the gut of an investigator to break in. |
Failure to restrict URL access | Medium |
|
|||
Soccer 1 The webmaster of this website is using Joomla to put together stats and news about Soccer. There's a tiny little thing he cares the most: how many Scudetti's FC Juventus actually have. Someone says 29, he says 27. |
Local File Inclusion |
Hard |
|
|||
or save $50 now...
Note: Our labs run on cloud servers so we are accepting the first 100 applicants at the launch price
Registration will reopen at regular prices later this summer.

