>_

HACKSLAB

live case files · vapt teaching lab

simulation running · sandboxed environment

Watch an attack happen, step by step, from the keystroke to the breach.

Two open case files. In each one, you'll operate a live, simulated web app exactly like a real user or attacker would — then walk forward and backward through every stage of what's happening behind the screen: in the request, on the server, and in the database.

// This entire lab runs client-side in your browser. There is no real server, database, or network request behind any of it — every "attack" is a scripted simulation built for teaching. Nothing here should be pointed at a system you don't own.

01
Case File 01Injection

SQL Injection

A login form trusts whatever you type into it. Learn how a single quote and two dashes can turn a password check into an open door — and how to extract an entire user table without logging in at all.

6 stageslive login form
02
Case File 02Injection

Cross-Site Scripting

A comment box repeats back exactly what you type — including code. Watch a payload travel from the input field, into storage, and into another visitor's browser, where it quietly executes.

6 stageslive comment box
03
Case File 03LLM / AI

Prompt Injection

An AI support assistant follows instructions in a system prompt — and follows instructions typed by a stranger, in the exact same channel. Watch it hand over what it was told to keep secret.

6 stageslive chat box
04
Case File 04Session / Auth

Broken Authentication

Login succeeds, and a session token comes back. But what if that token is predictable, and nothing stops you from just guessing someone else's? Walk through a session hijack.

6 stageslive session inspector
05
Case File 05Trust Exploit

CSRF

You're logged into your bank in one tab. A completely different site is open in another. Watch how that second tab can quietly spend the trust your browser already has.

6 stagestwo live browser tabs
06
Case File 06Filesystem

Path Traversal

A file viewer takes a filename and reads it off disk. Type ../../ a few times and "lecture1.pdf" becomes a request for anything else on the server.

6 stageslive file viewer
07
Case File 07Remote Code Execution

Command Injection

A "ping this host" tool quietly hands your input to the operating system's shell. One semicolon later, you're not pinging anymore — you're running arbitrary commands.

6 stageslive diagnostic tool
08
Case File 08Authorization

Broken Access Control

You're logged in — the app checks that much. But does it check whether this invoice, or this record, actually belongs to you? Change one number in the URL and find out.

6 stageslive record viewer
Case File 01 / Injection

SQL Injection

A live login form is wired to a simulated database below. Type into it like a real user — then step through what the backend actually does with what you typed.

STEP 1 / 6
Live Interface — login.app
https://portal.university-lms.edu/login
username password
Backend — Query Builder
Case File 02 / Injection

Cross-Site Scripting

A live comment box posts to a simulated discussion thread below. Type a comment like a real user — then step through what happens when it's stored and shown to someone else.

STEP 1 / 6
Live Interface — coursediscuss.app
https://discuss.university-lms.edu/thread/482
new comment
Backend — Storage & Render
Case File 03 / LLM · AI

Prompt Injection

A live chat box talks to a simulated AI support assistant. Ask it something normal — then try to talk it out of its own instructions.

STEP 1 / 6
Live Interface — support.ai
https://support.university-lms.edu/chat
message to the assistant
Backend — Context Window
Case File 04 / Session · Auth

Broken Authentication

Log in below to get a real (simulated) session token — then try the session inspector to see what happens when tokens are predictable and unlimited guesses are allowed.

STEP 1 / 6
Live Interface — portal.app
https://portal.university-lms.edu/login
username password
Backend — Session Store
Case File 05 / Trust Exploit

Cross-Site Request Forgery

Two browser tabs, side by side. One is your real, logged-in bank session. The other is a page you've never trusted. Watch what the second one can do to the first.

STEP 1 / 6
Live Interface — two open tabs
https://bank.university-cu.edu/transfer
✓ logged in as shaunak · session cookie active
transfer to account amount (₹)
https://free-wallpapers-4u.example/win-a-prize

🎉 You've won a free semester of cloud storage! Click below to claim.

<form id="f" action="https://bank.university-cu.edu/transfer" method="POST" style="display:none"> <input name="to" value="attacker-acct-2291"> <input name="amount" value="45000"> </form> <script>document.getElementById('f').submit()</script>
Backend — Request Received
Case File 06 / Filesystem

Path Traversal

A live file viewer reads course materials off the server's disk. Type a filename below like a real user — then try walking it out of the intended folder.

STEP 1 / 6
Live Interface — materials.app
https://portal.university-lms.edu/view?file=lecture1.pdf
file to view
Backend — File Resolver
Case File 07 / Remote Code Execution

Command Injection

A live network diagnostic tool pings whatever host you give it. Type a hostname like a real admin — then try slipping the shell a second command.

STEP 1 / 6
Live Interface — admin-tools.app
https://portal.university-lms.edu/admin/diagnostics
host to ping
Backend — Shell Command
Case File 08 / Authorization

Broken Access Control

You're logged in as a student. Below is a live record viewer showing your own invoice — try changing the ID in the URL to someone else's.

STEP 1 / 6
Live Interface — portal.app
https://portal.university-lms.edu/invoice?id=1044
record id in the URL
Backend — Authorization Check