WEB SECURITY / HANDS-ON PLAYGROUND 04 CHALLENGES AVAILABLE
FOR THE ONES WHO ASK “WHAT IF?”
Break the
assumption.
The request looks innocent.
The server trusts you.
Find out what it overlooked.
Start your first lab ↗FREE TO PLAY / NO ACCOUNT REQUIRED
ANATOMY OF AN ASSUMPTION
EXHIBIT 001CLIENT
YOU
YOU
GET
/api/orders/1001One number. Whose order?SERVER
THE TARGET
THE TARGET
A REQUEST IS NOT PERMISSION.Inspect → question → capture
Choose your breach.
All 4 labs ↗BROKEN ACCESS CONTROLNot your data.
02Not your data.
Still your request.
Question who gets access. Explore IDOR & BOLA.
SQL INJECTIONA search box.
A search box.
A different conversation.
Discover what happens when input becomes SQL.
New to this? Every lab includes a clear goal, hints, and the fix.
JUST THE GOOD PART.
- 01 /
Read the mission.
A small target. A clear goal.
- 02 /
Follow your hunch.
Change a request. Use a hint.
- 03 /
Capture. Then fix.
Understand why it worked.
Desktop or laptop recommended. Some challenges use browser Developer Tools.