πŸ§ͺ CyberLab training instance. Intentionally vulnerable. Simulated only β€” there is no real shell, no real network access, and no host data behind these bugs.
Staff sign in

Lab Status

Your private scorecard, refreshed live against the class. connecting…

Your scorecard

… β€” 0 of 18 captured.

Give yourself a name so the class board can show you.

Class progress

β€”

Everyone attacking this instance. Auto-refreshes every 4 seconds.

Your challenges

ChallengeCategoryTierFlag
⬜ SQL Injection Injection intermediate β€” open
⬜ Reflected XSS XSS beginner β€” open
⬜ Stored XSS XSS intermediate β€” open
⬜ IDOR Access Control beginner β€” open
⬜ Broken Authentication Authentication beginner β€” open
⬜ Path Traversal Files beginner β€” open
⬜ Command Injection Injection intermediate β€” open
⬜ SSRF Injection intermediate β€” open
⬜ Broken Access Control Access Control intermediate β€” open
⬜ Unrestricted File Upload Files beginner β€” open
⬜ Blind SQL Injection Injection advanced β€” open
⬜ Mass Assignment Access Control advanced β€” open
⬜ XML External Entity (XXE) Injection advanced β€” open
⬜ Server-Side Template Injection Injection advanced β€” open
⬜ Open Redirect Client-Side beginner β€” open
⬜ CRLF Injection Injection intermediate β€” open
⬜ Insecure Deserialization Injection intermediate β€” open
⬜ Encoded Path Traversal Files advanced β€” open

Class leaderboard

#StudentCapturedProgress
Waiting for the class…

Rules of engagement