Free labs

Everything you can do without a Pro pass: online labs, downloadable offline labs, and the Pro labs that are free this month.

Start the Bootcamp

Online free labs

do them right here on the platform
ExerciseTypeAvg. timeDifficultyTier
How HTTP Works
Read a real request and response, learn the method and status-code vocabulary, and see why the browser is a place attackers control.
Course 25 min Easy Free
Where Web Bugs Come From
One idea sits underneath almost every web vulnerability: the application trusted input it should have checked. Learn to see that pattern everywhere.
Course 25 min Easy Free
SQL Injection
Watch a login form turn an attacker's text into database logic, bypass it with a classic payload, and learn the one fix that actually closes the hole.
Course 35 min Medium Free this month
Cross-Site Scripting (XSS)
Get your own JavaScript to run in someone else's browser. Learn the three types, why stealing a cookie is the usual prize, and how output encoding shuts it down.
Course 35 min Medium Free this month
Scope & Rules of Engagement
The difference between a penetration tester and a criminal is permission. Learn what authorisation and scope mean, what a rules-of-engagement document covers, and why it comes first.
Course 20 min Easy Free

Offline free labs

download a target and run it on your own machine

Offline labs mirror how a real target works: you set up a deliberately-vulnerable application locally (using well-known, free open-source tools), attack it with your own tooling, and submit the keys here. Nothing to attack on the public internet — everything stays on your machine.

LabSet-upDifficultyTier
Offline Lab: Your First Local Target (DVWA)
Download and run a deliberately-vulnerable web app on your own machine, then practise the bugs you have learned against it. No internet target involved.
download & run Easy Free
Offline Lab: A Modern Target (OWASP Juice Shop)
Run OWASP Juice Shop — a modern single-page web app full of real-world bugs — on your own machine and learn to recon and poke a live application you control.
download & run Medium Free
Offline Lab: See & Edit Real Requests (Intercepting Proxy)
Install a local intercepting proxy, route your browser through it, and watch — then modify — the real HTTP requests behind a page you control. The tool every web tester lives in.
download & run Easy Free

Free this month

Pro labs, free for a limited time
ExerciseTypeAvg. timeDifficultyFree until
SQL Injection
Watch a login form turn an attacker's text into database logic, bypass it with a classic payload, and learn the one fix that actually closes the hole.
Course 35 min Medium Nov 30, 2026
Cross-Site Scripting (XSS)
Get your own JavaScript to run in someone else's browser. Learn the three types, why stealing a cookie is the usual prize, and how output encoding shuts it down.
Course 35 min Medium Nov 30, 2026

Want everything?

Pro unlocks every lab, the written solutions, the video walkthroughs and certificates.

See Pro plans