๐Ÿงช CyberLab training instance. Intentionally vulnerable. Simulated only โ€” there is no real shell, no real network access, and no host data behind these bugs.
Staff sign in

Welcome to the AcmeCorp Staff Portal

Internal systems for AcmeCorp employees. This build is a training instance โ€” it contains real-world bug classes, isolated in a sandbox.

You are not signed in. Some challenges require a staff account. Try the portal as staff, or find your way in.

Your scorecard

You are training as student-anon ยท 0/18 flags captured. Progress is saved on this browser only.

Company announcements

Staff self-service

Training challenges 0/18 solved

SQL Injection intermediate

Injection
Show hint

The staff directory builds its search query by string concatenation.

Open challenge โ†’

Reflected XSS beginner

XSS
Show hint

The quick-search echo prints your input straight into the page.

Open challenge โ†’

Stored XSS intermediate

XSS
Show hint

Ticket comments are saved and re-rendered without sanitising.

Open challenge โ†’

IDOR beginner

Access Control
Show hint

Pay slips are fetched by numeric id with no ownership check.

Open challenge โ†’

Broken Authentication beginner

Authentication
Show hint

Default admin credentials were never changed. The login form is also injectable.

Open challenge โ†’

Path Traversal beginner

Files
Show hint

IT tools let you download a file by name.

Open challenge โ†’

Command Injection intermediate

Injection
Show hint

The network diagnostic tool shells out to ping. (Simulated โ€” no real shell.)

Open challenge โ†’

SSRF intermediate

Injection
Show hint

The URL preview tool fetches whatever host you give it. (Simulated โ€” no real network.)

Open challenge โ†’

Broken Access Control intermediate

Access Control
Show hint

Your session token is unsigned and accepts alg:none. The admin panel trusts it.

Open challenge โ†’

Unrestricted File Upload beginner

Files
Show hint

The resume uploader accepts any file extension.

Open challenge โ†’

Blind SQL Injection advanced

Injection
Show hint

The blind directory search only tells you how many match โ€” infer data from yes/no answers.

Open challenge โ†’

Mass Assignment advanced

Access Control
Show hint

The profile form only shows name/email, but the server binds every field you send.

Open challenge โ†’

XML External Entity (XXE) advanced

Injection
Show hint

The XML importer resolves external entities. Declare one and reference it.

Open challenge โ†’

Server-Side Template Injection advanced

Injection
Show hint

The greeting banner renders your input as a template. Try {{7*7}}.

Open challenge โ†’

Open Redirect beginner

Client-Side
Show hint

The redirect helper trusts the ?next= value, even when it points off-site.

Open challenge โ†’

CRLF Injection intermediate

Injection
Show hint

The language selector reflects your value into a response header.

Open challenge โ†’

Insecure Deserialization intermediate

Injection
Show hint

Your preferences cookie is base64-encoded JSON the app decodes and trusts.

Open challenge โ†’

Encoded Path Traversal advanced

Files
Show hint

The download tool decodes its argument a second time โ€” double-encode the traversal.

Open challenge โ†’