live case files · vapt teaching lab
Two open case files. In each one, you'll operate a live, simulated web app exactly like a real user or attacker would — then walk forward and backward through every stage of what's happening behind the screen: in the request, on the server, and in the database.
// This entire lab runs client-side in your browser. There is no real server, database, or network request behind any of it — every "attack" is a scripted simulation built for teaching. Nothing here should be pointed at a system you don't own.
A login form trusts whatever you type into it. Learn how a single quote and two dashes can turn a password check into an open door — and how to extract an entire user table without logging in at all.
A comment box repeats back exactly what you type — including code. Watch a payload travel from the input field, into storage, and into another visitor's browser, where it quietly executes.
An AI support assistant follows instructions in a system prompt — and follows instructions typed by a stranger, in the exact same channel. Watch it hand over what it was told to keep secret.
Login succeeds, and a session token comes back. But what if that token is predictable, and nothing stops you from just guessing someone else's? Walk through a session hijack.
You're logged into your bank in one tab. A completely different site is open in another. Watch how that second tab can quietly spend the trust your browser already has.
A file viewer takes a filename and reads it off disk. Type ../../ a few times and "lecture1.pdf" becomes a request for anything else on the server.
A "ping this host" tool quietly hands your input to the operating system's shell. One semicolon later, you're not pinging anymore — you're running arbitrary commands.
You're logged in — the app checks that much. But does it check whether this invoice, or this record, actually belongs to you? Change one number in the URL and find out.
A live login form is wired to a simulated database below. Type into it like a real user — then step through what the backend actually does with what you typed.
A live comment box posts to a simulated discussion thread below. Type a comment like a real user — then step through what happens when it's stored and shown to someone else.
A live chat box talks to a simulated AI support assistant. Ask it something normal — then try to talk it out of its own instructions.
Log in below to get a real (simulated) session token — then try the session inspector to see what happens when tokens are predictable and unlimited guesses are allowed.
Two browser tabs, side by side. One is your real, logged-in bank session. The other is a page you've never trusted. Watch what the second one can do to the first.
🎉 You've won a free semester of cloud storage! Click below to claim.
A live file viewer reads course materials off the server's disk. Type a filename below like a real user — then try walking it out of the intended folder.
A live network diagnostic tool pings whatever host you give it. Type a hostname like a real admin — then try slipping the shell a second command.
You're logged in as a student. Below is a live record viewer showing your own invoice — try changing the ID in the URL to someone else's.