Server-Side Attacks badge
Bugs that reach past the app into the server and the network: command injection, path traversal and server-side request forgery.
| # | Exercise | Difficulty | Tier |
|---|---|---|---|
| 1 |
Command Injection
When an application builds a shell command out of user input, the input can stop being an argument and start being an instruction. Learn the pattern, the tell-tale sign, and the fix. |
Medium | ๐ Pro |
| 2 |
Path Traversal
When a filename comes from the user, "../" can walk out of the folder the app meant and into the rest of the server. Learn how, how to spot it, and the canonical fix. |
Medium | ๐ Pro |
| 3 |
Server-Side Request Forgery (SSRF)
When an app fetches a URL you give it, you can point it at things you could never reach yourself โ internal services and cloud metadata. Learn the pattern and the defence. |
Hard | ๐ Pro |