A small shelf of self-contained web-security training labs. Each one is a separate service; pick a discipline and work through its challenges, then exchange what you find for a flag.
Finding endpoints, files, and directories a site never linked. Each challenge hides one path and differs in exactly one observable property of the response.
Making a Microsoft SQL Server say more than it was asked. Every challenge concatenates your input into a query in a different place, exploitable by a different technique.
How it works. Open a lab and read its rules — each is
self-guided. Solve a challenge to recover an artefact (a hidden path, or a
secret token), then submit it on that lab's verification page to claim the
flag, formatted flag{...}.
Rules of engagement. Everything you need is inside each lab. Submissions are rate-limited, so the intended solve — actually doing the work — is faster than brute force.