Mossbrook Records · Security Labs est. 1887

Security Labs

A small shelf of self-contained web-security training labs. Each one is a separate service; pick a discipline and work through its challenges, then exchange what you find for a flag.

Labs

Lab 01 · Web

Content Discovery

7 challenges

Finding endpoints, files, and directories a site never linked. Each challenge hides one path and differs in exactly one observable property of the response.

status codetimingheaders reason phrasebody diffcache-control
enter the lab →
Lab 02 · Database

SQL Injection

17 challenges

Making a Microsoft SQL Server say more than it was asked. Every challenge concatenates your input into a query in a different place, exploitable by a different technique.

UNIONerror-basedboolean-blind time-blindstackedsecond-order WAF bypassOOB
enter the lab →

How it works. Open a lab and read its rules — each is self-guided. Solve a challenge to recover an artefact (a hidden path, or a secret token), then submit it on that lab's verification page to claim the flag, formatted flag{...}.

Rules of engagement. Everything you need is inside each lab. Submissions are rate-limited, so the intended solve — actually doing the work — is faster than brute force.