An intentionally vulnerable web application for learning web security, built by The PenTrix.
⚠️ WARNING: This application is intentionally vulnerable. Never deploy it to a public server or expose it to the internet. Run it only on your own machine or an isolated lab network.
docker compose up --build
# open http://localhost:3000Or without Docker (Node 20+):
npm install
npm start- Pick a module on the home page (XSS, SQLi, IDOR, SSRF, and more).
- Each module briefs you on what to attack, with hints when you're stuck.
- Exploit the vulnerability for real, capture the flag (
PENTRIX{...}). - Track your progress on the Scoreboard page.
- Full walkthroughs live in
SOLUTIONS.md. Try without them first. - Every vulnerability is marked in the source with
// VULN:comments so you can study the code after solving.
235 intentionally vulnerable challenges across 29 modules:
| Module | Highlights |
|---|---|
| xss – Cross-Site Scripting (11) | Reflected · Stored (guestbook, profile bio, SVG upload) · DOM XSS · Attribute and JS-string breakouts · DOM clobbering · Naive Markdown links |
| sqli – SQL Injection (12) | Auth bypass · UNION injection · Blind boolean · Error-based · ORDER BY · Second-order · LIKE wildcards · LIMIT/OFFSET · INSERT injection |
| auth – Broken Authentication (11) | No rate limiting · JWT alg=none · Predictable reset tokens · Username enumeration · Remember-me tampering · OTP brute force · API key in HTML comment |
| idor – Broken Access Control (11) | Profile and order IDOR · Invoice download · Cart and address IDOR · API key regeneration · Forced browsing · Comment deletion |
| ssrf – Server-Side Request Forgery (10) | Basic SSRF · Blocklist bypasses (decimal, hex, octal, integer IP, userinfo) · Open-redirect chain · Cloud metadata · file:// |
| upload – File Upload (10) | Stored XSS via SVG/HTML · Extension blacklist bypasses (double ext, case, strip-once) · MIME spoofing · Path traversal · Polyglot |
| cmdi – Command Injection (10) | Unfiltered ping gadget · Blacklist-bypass series ($IFS, ${IFS}, newline, backticks, glob wildcards, tab, pipe) |
| xxe – XXE Injection (8) | File read · SSRF via XXE · Billion laughs · External DTD exfiltration · XXE in SVG/SOAP · XInclude · Parameter-entity OOB |
| ssti – Server-Side Template Injection (10) | Basic {{7*7}} · Filter-bypass series (words, underscores, brackets, dots, braces, quotes) · SSTI to RCE |
| lfi – Path Traversal / LFI (10) | Basic traversal · Filter bypasses (nested, double-encoded) · Absolute paths · Log poisoning · /proc/self/environ · Config read |
| csrf – CSRF & Open Redirect (11) | State-changing GETs · Login CSRF · JSON CSRF via text/plain · Referer/Content-Type bypasses · Method override · 2FA disable via GET |
| api – API Security Flaws (11) | Mass assignment · Excessive data exposure · BOLA · Rate-limit bypass via X-Forwarded-For · Version bypass · ID enumeration |
| misconfig – Security Misconfiguration (11) | Verbose errors · Exposed .git/.env/backup/swap files · Directory listing · HTTP TRACE · Debug param · Default creds · HTTP PUT |
| jwt – JWT Attacks (8) | alg=none · Weak HMAC secret · kid SQL injection · Untrusted jku · RS256/HS256 confusion · Missing expiry/audience checks |
| session – Session Management (6) | Fixation · Logout without destruction · Predictable IDs · Session ID in URL · Never-expiring sessions · IDs in debug logs |
| race – Race Conditions (8) | Double coupon redeem · Double-spend · Double vote/registration · AV-scan TOCTOU · Rate-limit burst · Stock oversell |
| bizlogic – Business Logic Flaws (8) | Negative quantity · Price tampering · Coupon stacking · Client-side OTP · Workflow skipping · Currency confusion · Refund tampering |
| redirect – Open Redirect (6) | Protocol-relative //evil.com · javascript:/data: schemes · Backslash bypass · OAuth code theft · Parameter pollution |
| hostheader – Host Header Injection (6) | Reset-link poisoning · Cache poisoning · SSRF via Host · X-Forwarded-Host/X-Host-Override trust |
| cors – CORS Misconfiguration (6) | Reflected origin with credentials · null origin · Regex bypass · Wildcard on sensitive data · Exposed headers |
| proto – Prototype Pollution (6) | Query-string pollution · JSON body pollution · constructor bypass · toString DoS · Unicode-escape bypass |
| crypto – Cryptographic Failures (8) | Predictable PIN · ECB decryption oracle · CBC bit-flipping · Hash length extension · MD5 cracking · XOR crib dragging |
| oauth – OAuth Flaws (8) | Redirect-URI bypass · Code leakage · Missing state (login CSRF) · Implicit flow · Scope tampering · Code replay · PKCE skip |
| postmsg – postMessage Flaws (5) | Missing origin check · Wildcard targetOrigin leak · Unsanitized data to HTML · Substring origin bypass · Forged actions |
| csti – Client-Side Template Injection (5) | Basic {{7*7}} evaluation · Delimiter filter bypass · Constructor breakout · Attribute context · Stored template |
| http – HTTP Layer Flaws (6) | CRLF log injection · Method override · Verb tampering · X-Forwarded-For trust · Cache deception · Referer auth |
| jsonp – JSONP Injection (5) | Callback XSS · JSONP data theft · Callback filter bypass · Array-constructor hijack · MIME sniffing |
| formula – CSV Formula Injection (4) | Classic =cmd · DDE execution · HYPERLINK exfiltration · Pipe prefix |
| redos – ReDoS (4) | Catastrophic email/URL regexes · Nested-quantifier username · Regex-injection search |
- Attack only this application.
- Flags prove exploitation. Share write-ups, not just flags.
- Built for learning. If you find an unintended vulnerability, that's a bonus flag in spirit.
Educational use only. Built by The PenTrix.