Web Application Hacking Challenges Pack
Versionv2.5
Difficulty Beginner
Updated2025-03-20
CategoryTraining & Courses

Web Application Hacking Challenges Pack

$19.99

Web Application Hacking Challenges Pack

n

25 self-contained web challenges in Docker:

n
    n
  • SQLi (5 challenges) — Union-based, blind boolean, blind time-based, second-order, filter bypass.
  • n
  • XSS (4 challenges) — Reflected, stored, DOM-based, CSP bypass with dangling markup.
  • n
  • SSTI (3 challenges) — Jinja2, Twig, Freemarker with sandbox escape progresivo.
  • n
  • SSRF (3 challenges) — Basic, with redirect bypass, cloud metadata (AWS/GCP).
  • n
  • Deserialization (3 challenges) — PHP unserialize, Java ObjectInputStream, Python pickle.
  • n
  • Auth bypass (4 challenges) — JWT none algorithm, JWT key confusion, OAuth redirect, IDOR chain.
  • n
  • Misc (3 challenges) — Race condition, HTTP request smuggling, prototype pollution.
  • n
  • Each challenge: docker-compose.yml, README with hints progresivos, writeup complete.
  • n