Injection badge
Input that becomes code. SQL injection, cross-site scripting, OS command injection and path traversal — how each one happens, how to find it, and the fix that closes it.
| # | Exercise | Difficulty | Tier |
|---|---|---|---|
| 1 |
SQL Injection
Watch a login form turn an attacker's text into database logic, bypass it with a classic payload, and learn the one fix that actually closes the hole. |
Medium | Free this month |
| 2 |
Cross-Site Scripting (XSS)
Get your own JavaScript to run in someone else's browser. Learn the three types, why stealing a cookie is the usual prize, and how output encoding shuts it down. |
Medium | Free this month |
| 3 |
Command Injection
When an application builds a shell command out of user input, the input can stop being an argument and start being an instruction. Learn the pattern, the tell-tale sign, and the fix. |
Medium | 🔒 Pro |
| 4 |
Path Traversal
When a filename comes from the user, "../" can walk out of the folder the app meant and into the rest of the server. Learn how, how to spot it, and the canonical fix. |
Medium | 🔒 Pro |