Code Review badge
Find the bug by reading the source. The source-to-sink method applied to SQL injection, XSS in templates, and the hardest one to see — the missing access-control check.
| # | Exercise | Difficulty | Tier |
|---|---|---|---|
| 1 |
SQL Injection: Code Review
Find the injection by reading the source, not just by poking the app. Learn to trace user input from a source to a dangerous sink and spot the fix. |
Medium | 🔒 Pro |
| 2 |
Secure Code Review
A repeatable way to read code for security: where to look first, the handful of risky functions to grep for, and how to write a finding a developer can act on. |
Medium | 🔒 Pro |
| 3 |
XSS: Code Review
Find cross-site scripting by reading templates, not by poking the page. Learn where output encoding is on by default, where it is switched off, and how to spot the unsafe line. |
Medium | 🔒 Pro |
| 4 |
Access Control: Code Review
Broken access control is a missing check, which makes it the hardest bug to see — there is nothing on the line, because the line is not there. Learn to review for the check that should exist. |
Medium | 🔒 Pro |