Free labs
Everything you can do without a Pro pass: online labs, downloadable offline labs, and the Pro labs that are free this month.
Online free labs
do them right here on the platform| Exercise | Difficulty | Tier |
|---|---|---|
|
How HTTP Works
Read a real request and response, learn the method and status-code vocabulary, and see why the browser is a place attackers control. |
Easy | Free |
|
Where Web Bugs Come From
One idea sits underneath almost every web vulnerability: the application trusted input it should have checked. Learn to see that pattern everywhere. |
Easy | Free |
|
SQL Injection
Watch a login form turn an attacker's text into database logic, bypass it with a classic payload, and learn the one fix that actually closes the hole. |
Medium | Free this month |
|
Cross-Site Scripting (XSS)
Get your own JavaScript to run in someone else's browser. Learn the three types, why stealing a cookie is the usual prize, and how output encoding shuts it down. |
Medium | Free this month |
|
Scope & Rules of Engagement
The difference between a penetration tester and a criminal is permission. Learn what authorisation and scope mean, what a rules-of-engagement document covers, and why it comes first. |
Easy | Free |
Offline free labs
download a target and run it on your own machineOffline labs mirror how a real target works: you set up a deliberately-vulnerable application locally (using well-known, free open-source tools), attack it with your own tooling, and submit the keys here. Nothing to attack on the public internet — everything stays on your machine.
| Lab | Difficulty | Tier |
|---|---|---|
| Offline Lab: Your First Local Target (DVWA)
Download and run a deliberately-vulnerable web app on your own machine, then practise the bugs you have learned against it. No internet target involved. |
Easy | Free |
| Offline Lab: A Modern Target (OWASP Juice Shop)
Run OWASP Juice Shop — a modern single-page web app full of real-world bugs — on your own machine and learn to recon and poke a live application you control. |
Medium | Free |
| Offline Lab: See & Edit Real Requests (Intercepting Proxy)
Install a local intercepting proxy, route your browser through it, and watch — then modify — the real HTTP requests behind a page you control. The tool every web tester lives in. |
Easy | Free |
Free this month
Pro labs, free for a limited time| Exercise | Difficulty | Free until |
|---|---|---|
| SQL Injection
Watch a login form turn an attacker's text into database logic, bypass it with a classic payload, and learn the one fix that actually closes the hole. |
Medium | Nov 30, 2026 |
| Cross-Site Scripting (XSS)
Get your own JavaScript to run in someone else's browser. Learn the three types, why stealing a cookie is the usual prize, and how output encoding shuts it down. |
Medium | Nov 30, 2026 |
Want everything?
Pro unlocks every lab, the written solutions, the video walkthroughs and certificates.