ls -R labs/

Hands-on lab writeups, grouped by series. Each series is a set of related labs worked through in order.

PortSwigger: OS Command Injection

  1. OS Command Injection: Simple Case
  2. Blind OS Command Injection with Time Delays
  3. Blind OS Command Injection with Output Redirection

PortSwigger: Server-Side Template Injection

  1. Basic Server-Side Template Injection
  2. Basic Server-Side Template Injection (Code Context)
  3. Server-Side Template Injection in an Unknown Language
  4. Server-Side Template Injection Using Documentation
  5. Server-Side Template Injection in a Sandboxed Environment
  6. Server-Side Template Injection via User-Supplied Objects
  7. Server-Side Template Injection with a Custom Exploit

PortSwigger: XML External Entity Injection

  1. Exploiting XXE to Retrieve Files
  2. Exploiting XXE to Perform SSRF