[ OPEN SECURITY PLAYGROUND ] EST. 2024
BREAK IT.UNDERSTAND IT.SECURE IT.
Explore a system through its weakest point.
Experiment with vulnerabilities, read the code and learn to build more secure applications.
5 labs / real code / hands-on learning
❯ inspect --attack-surface
Inspecting the data flow
❯ understand. then secure.
01 / THE LABS
Find the weak point.
Five ways to break an application.
Five opportunities to understand its defenses.
SQL Injection
Queries under your control. Explore the boundary between data and code.
Command Injection
One text field. Shell access. Find where the risk begins.
File Upload
An extension is not enough. Test actual file validation.
XSS Reflected
See how URL input becomes an executable script.
XSS Stored
One comment, many visitors. Understand persistent script injection.
02 / THE MINDSET
Don’t guess.
Understand.
Basic programming knowledge and curiosity are enough to start. Each lab takes you from an attack mechanism to a concrete defense.
- 01
Read the system
Explore the code and find where data crosses a trust boundary.
- 02
Test your hypothesis
Try a payload in the form and observe the actual result.
- 03
Close the gap
Compare the variants and see why the protected code changes the result.
03 / YOUR ENVIRONMENT
Your local
testing ground.
The full lab runs on localhost. Download the project, start the containers and open your first exercise.
Source code on GitHubQUICK START / DOCKER
docker compose up --build -dOpen localhost:8080/vulnerability-vault/
Test accounts and requirements
Install Docker with Docker Compose. On Windows, enable Docker Desktop integration with WSL.
Accounts: admin/admin, test/test, user/user.
phpMyAdmin: localhost:8081. Data and uploads survive restarts.