Exploit. Understand. Fix.
Real vulnerable machines, built to be broken. Exploit them, then fix what let you in. No shortcuts, just the skills that actually get you hired.

Exploit command injection and a cron wildcard mistake, then harden both vulnerabilities.

Investigate unsafe deserialization over a custom telemetry protocol and a Linux capability issue.

A guided room covering SQL, NoSQL, command, template, XPath, and other injection types.

Discover a vulnerable product lookup, enumerate its database, and replace concatenated SQL with parameters.

Reason through UNION enumeration, database behavior, and why blacklists are not fixes.

Extract information from a yes/no response signal when the application hides database output.

Follow stored referral data into a later SQL sink and patch the vulnerability where it is actually used.

Trace four generations of technical debt across one nonprofit archive.