Exercises

Exercise Avg. Time Difficulty Solved by Tier
API Mass-Assignment 03 < 1 Hr. medium 424 PRO
API Mass-Assignment 01 < 1 Hr. medium 484 PRO
API Mass-Assignment 02 < 1 Hr. medium 457 PRO
API JWT REVOCATION JWT
This exercise covers how to bypass a weak JWT Revocation Mechanism.
< 1 Hr. easy 467 PRO
API 20
This exercise covers how to exploit an authorization issue in an API.
< 1 Hr. medium 518 PRO
API 19
This exercise covers how to exploit an authorization issue in an API.
< 1 Hr. medium 537 PRO
API 18
This exercise covers how to exploit an authorization issue in an API.
< 1 Hr. medium 550 PRO
API 17
This exercise covers how to exploit an authorization issue in an API.
< 1 Hr. medium 461 PRO
API 16
This exercise covers how to exploit an authorization issue in an API.
< 1 Hr. medium 552 PRO
API 15
This exercise covers how to exploit a leaked encrypted password with an API.
< 1 Hr. hard 624 PRO
API 13
This exercise covers a complex filter bypass in API.
< 1 Hr. hard 686 PRO
API 14
This exercise covers how to exploit a leaked encrypted password with an API.
< 1 Hr. medium 713 PRO
API 12
This exercise covers a common filter bypass in API.
< 1 Hr. medium 762 PRO
API 11
This exercise covers a common filter bypass in API.
< 1 Hr. medium 802 PRO
API 10
This exercise covers a common filter bypass in API.
< 1 Hr. medium 872 PRO
API 09
This exercise covers how one can inspect HTTP responses to identify information leaks.
< 1 Hr. medium 1007 PRO
API Payments 07
This exercise covers a way to manipulate a shopping cart to lower the total amount
< 1 Hr. medium 986 PRO
API Payments 06
This exercise covers a simple payments bypass.
< 1 Hr. medium 1019 PRO
API Payments 05
This exercise covers how to abuse a shopping cart allowing users to apply a voucher.
< 1 Hr. hard 926 PRO
API Payments 04
This exercise covers how to abuse a shopping cart allowing users to apply a voucher..
< 1 Hr. medium 1235 PRO
API Payments 03
This exercise covers a simple payments bypass.
< 1 Hr. medium 1342 PRO
API Payments 02
This exercise covers a simple payments bypass.
< 1 Hr. medium 1508 PRO
API Payments 01 API
This exercise covers a simple payments bypass.
< 1 Hr. easy 2009 PRO
API 08
This exercise covers how one can inspect HTTP responses to identify information leaks.
< 1 Hr. medium 1812 PRO
API 07 API Angular
This exercise covers how one can inspect JavaScript code to identify information leak.
< 1 Hr. medium 1906 PRO
API 06 API Angular
This exercise covers how one can inspect JavaScript code to identify unused endpoints.
< 1 Hr. easy 2038 PRO
API 05 API Angular
This exercise covers how one can inspect JavaScript code to identify unused endpoints.
< 1 Hr. easy 2355 PRO
API 04 API Angular
This exercise covers how one can inspect JavaScript code to identify unused endpoints.
< 1 Hr. easy 2547 PRO
API 03 API
This exercise is the API version of an exercise you already solved in another badge. You should use it to get more confident with discovering vulnerabilities without any hint on what to look for.
< 1 Hr. easy 2510 PRO
API 02 API
This exercise is the API version of an exercise you already solved in another badge. You should use it to get more confident with discovering vulnerabilities without any hint on what to look for.
< 1 Hr. easy 3176 PRO
1 2
Showing 1–30 of 32 exercises