Server-Side Attacks badge

3 exercisesEarned by 0Certificate of completion

Bugs that reach past the app into the server and the network: command injection, path traversal and server-side request forgery.

#ExerciseTypeAvg. timeDifficultyTier
1 Command Injection
When an application builds a shell command out of user input, the input can stop being an argument and start being an instruction. Learn the pattern, the tell-tale sign, and the fix.
Course 30 min Medium ๐Ÿ”’ Pro
2 Path Traversal
When a filename comes from the user, "../" can walk out of the folder the app meant and into the rest of the server. Learn how, how to spot it, and the canonical fix.
Course 25 min Medium ๐Ÿ”’ Pro
3 Server-Side Request Forgery (SSRF)
When an app fetches a URL you give it, you can point it at things you could never reach yourself โ€” internal services and cloud metadata. Learn the pattern and the defence.
Course 30 min Hard ๐Ÿ”’ Pro