πŸ›‘οΈ Security Lab static edition Β· one file per stage progress

Security Learning Lab

7 tracks Β· 45 challenges, fully client-side. Each stage is a single self-contained page β€” pick one and exploit it in your browser. Progress is saved in this browser only. For isolated learning use only; vulnerabilities are intentional and simulated.

Track A

Web Application Security

Stage 0
Cookie & localStorage Tampering
0 / 1 cleared
Stage 1
Recon: robots.txt, comments & hardcoded secrets
0 / 1 cleared
Stage 2
OS Command Injection, SQL Injection β€” Authentication Bypass
0 / 2 cleared
Stage 3
UNION-based SQL Injection, Blind Boolean SQL Injection
0 / 2 cleared
Stage 4
Reflected XSS, Stored XSS (guestbook), DOM-based XSS (location.hash)
0 / 3 cleared
Stage 5
Path Traversal / Local File Inclusion, Unrestricted File Upload β†’ RCE
0 / 2 cleared
Stage 6
IDOR β€” Insecure Direct Object Reference, Vertical Privilege Escalation
0 / 2 cleared
Stage 7
Weak JWT β€” alg=none / forgery, Cross-Site Request Forgery
0 / 2 cleared
Stage 8
SSRF to internal metadata, XML External Entity (XXE) injection
0 / 2 cleared
Stage 9
Insecure Deserialization (pickle), Server-Side Template Injection (Jinja2), Race Condition (double spend)
0 / 3 cleared
Track B

Network Security & Defense

Stage 0
Reading a pcap β€” cleartext credentials
0 / 1 cleared
Stage 1
Spotting an Nmap scan
0 / 1 cleared
Stage 2
Write an IDS rule to block the attack
0 / 1 cleared
Stage 3
Spot the C2 beacon
0 / 1 cleared
Stage 4
Harden the sshd_config
0 / 1 cleared
Track C

Cryptography

Stage 0
Caesar & Vigenère
0 / 1 cleared
Stage 1
Crack an unsalted MD5
0 / 1 cleared
Stage 2
AES-ECB byte-at-a-time decryption
0 / 1 cleared
Stage 3
Forge a JWT by cracking a weak HMAC secret
0 / 1 cleared
Track D

Authentication & Access Management

Stage 0
Brute-force a weak password
0 / 1 cleared
Stage 1
Predictable password-reset token
0 / 1 cleared
Stage 2
MFA bypass via broken flow
0 / 1 cleared
Stage 3
RBAC role escalation via mass assignment
0 / 1 cleared
Track E

Malware Analysis (defanged)

Stage 0
Strings & hashes of a (defanged) sample
0 / 1 cleared
Stage 1
Detonate a defanged sample in a sandbox
0 / 1 cleared
Stage 2
Write a YARA rule to detect the sample
0 / 1 cleared
Stage 3
Deobfuscate a (benign) dropper script
0 / 1 cleared
Track F

Incident Response / DFIR

Stage 0
Find the intrusion in the access log
0 / 1 cleared
Stage 1
Correlate multiple log sources
0 / 1 cleared
Stage 2
Carve a secret from a memory image
0 / 1 cleared
Stage 3
Triage SIEM alerts
0 / 1 cleared
Track G

Penetration Testing (capstone)

Stage 0
Full methodology mini-engagement
0 / 1 cleared
Stage 1
Chain: IDOR β†’ token β†’ admin
0 / 1 cleared
Stage 2
Chain: recon β†’ weak crypto β†’ access
0 / 1 cleared
Stage 3
Capstone: full multi-stage compromise + report
0 / 1 cleared