Online simulationPractice with fake data and guided SQL examples. No real database is exposed.
WEB SECURITY / HANDS-ON PLAYGROUND 04 CHALLENGES AVAILABLE

FOR THE ONES WHO ASK “WHAT IF?”

Break the
assumption.

The request looks innocent.
The server trusts you.
Find out what it overlooked.

Start your first lab ↗FREE TO PLAY / NO ACCOUNT REQUIRED

ANATOMY OF AN ASSUMPTION

EXHIBIT 001
CLIENT
YOU
GET/api/orders/1001One number. Whose order?
SERVER
THE TARGET
A REQUEST IS NOT PERMISSION.Inspect → question → capture

Choose your breach.

All 4 labs ↗
01
BROKEN ACCESS CONTROL

Not your data.
Still your request.

Question who gets access. Explore IDOR & BOLA.

02 LABS250 XP
02
SQL INJECTION

A search box.
A different conversation.

Discover what happens when input becomes SQL.

02 LABS350 XP

New to this? Every lab includes a clear goal, hints, and the fix.

NO LONG LECTURES.
JUST THE GOOD PART.
  1. 01 /

    Read the mission.

    A small target. A clear goal.

  2. 02 /

    Follow your hunch.

    Change a request. Use a hint.

  3. 03 /

    Capture. Then fix.

    Understand why it worked.

Desktop or laptop recommended. Some challenges use browser Developer Tools.