Lv 1–10
Web App Wilds
The unguarded edge of the internet — apps shipped without much thought to who might be reading.
Footprint Wisp · Lv 1
Recon & Enumeration
IDOR Imp · Lv 2-3
Broken Access Control / IDOR
locked
Reflection Wraith · Lv 3-4
Reflected XSS
locked
Injector Serpent · Lv 5-6
SQL Injection
locked
Session Snatcher · Lv 6-7
JWT / Session Forgery
locked
Gatecrasher · Lv 7-8
Server-Side Request Forgery
locked
BOSS · Log4Shell Revenant · Lv 9-10
Two-phase: Remote Code Execution via JNDI Injection, then forge the containment rule.
clear all 6 pairs first