Web
Intro to Web Security
Learn how attackers see the web, then find your first flags.
webhttpdevtools
// pick your next challenge
8 rooms match your filters.
Learn how attackers see the web, then find your first flags.
Requests, responses, methods and status codes — the foundation every web hacker needs.
Capture a real hidden flag on this very website, step by step. No tools required.
The three bugs you will find on almost every web app.
Understand why SQL injection happens, bypass a login, and extract data with UNION.
Run JavaScript in someone else's browser — and learn the one rule that stops it.
Test the API-first attack surface: IDOR, broken auth, and server-side request forgery.
Turn a login form into a database dump.