Skip to content

Repository files navigation

🧪 PenTrix VulnLab

An intentionally vulnerable web application for learning web security, built by The PenTrix.

⚠️ WARNING: This application is intentionally vulnerable. Never deploy it to a public server or expose it to the internet. Run it only on your own machine or an isolated lab network.

Quick start

docker compose up --build
# open http://localhost:3000

Or without Docker (Node 20+):

npm install
npm start

How it works

  • Pick a module on the home page (XSS, SQLi, IDOR, SSRF, and more).
  • Each module briefs you on what to attack, with hints when you're stuck.
  • Exploit the vulnerability for real, capture the flag (PENTRIX{...}).
  • Track your progress on the Scoreboard page.
  • Full walkthroughs live in SOLUTIONS.md. Try without them first.
  • Every vulnerability is marked in the source with // VULN: comments so you can study the code after solving.

Vulnerability inventory

235 intentionally vulnerable challenges across 29 modules:

Module Highlights
xss – Cross-Site Scripting (11) Reflected · Stored (guestbook, profile bio, SVG upload) · DOM XSS · Attribute and JS-string breakouts · DOM clobbering · Naive Markdown links
sqli – SQL Injection (12) Auth bypass · UNION injection · Blind boolean · Error-based · ORDER BY · Second-order · LIKE wildcards · LIMIT/OFFSET · INSERT injection
auth – Broken Authentication (11) No rate limiting · JWT alg=none · Predictable reset tokens · Username enumeration · Remember-me tampering · OTP brute force · API key in HTML comment
idor – Broken Access Control (11) Profile and order IDOR · Invoice download · Cart and address IDOR · API key regeneration · Forced browsing · Comment deletion
ssrf – Server-Side Request Forgery (10) Basic SSRF · Blocklist bypasses (decimal, hex, octal, integer IP, userinfo) · Open-redirect chain · Cloud metadata · file://
upload – File Upload (10) Stored XSS via SVG/HTML · Extension blacklist bypasses (double ext, case, strip-once) · MIME spoofing · Path traversal · Polyglot
cmdi – Command Injection (10) Unfiltered ping gadget · Blacklist-bypass series ($IFS, ${IFS}, newline, backticks, glob wildcards, tab, pipe)
xxe – XXE Injection (8) File read · SSRF via XXE · Billion laughs · External DTD exfiltration · XXE in SVG/SOAP · XInclude · Parameter-entity OOB
ssti – Server-Side Template Injection (10) Basic {{7*7}} · Filter-bypass series (words, underscores, brackets, dots, braces, quotes) · SSTI to RCE
lfi – Path Traversal / LFI (10) Basic traversal · Filter bypasses (nested, double-encoded) · Absolute paths · Log poisoning · /proc/self/environ · Config read
csrf – CSRF & Open Redirect (11) State-changing GETs · Login CSRF · JSON CSRF via text/plain · Referer/Content-Type bypasses · Method override · 2FA disable via GET
api – API Security Flaws (11) Mass assignment · Excessive data exposure · BOLA · Rate-limit bypass via X-Forwarded-For · Version bypass · ID enumeration
misconfig – Security Misconfiguration (11) Verbose errors · Exposed .git/.env/backup/swap files · Directory listing · HTTP TRACE · Debug param · Default creds · HTTP PUT
jwt – JWT Attacks (8) alg=none · Weak HMAC secret · kid SQL injection · Untrusted jku · RS256/HS256 confusion · Missing expiry/audience checks
session – Session Management (6) Fixation · Logout without destruction · Predictable IDs · Session ID in URL · Never-expiring sessions · IDs in debug logs
race – Race Conditions (8) Double coupon redeem · Double-spend · Double vote/registration · AV-scan TOCTOU · Rate-limit burst · Stock oversell
bizlogic – Business Logic Flaws (8) Negative quantity · Price tampering · Coupon stacking · Client-side OTP · Workflow skipping · Currency confusion · Refund tampering
redirect – Open Redirect (6) Protocol-relative //evil.com · javascript:/data: schemes · Backslash bypass · OAuth code theft · Parameter pollution
hostheader – Host Header Injection (6) Reset-link poisoning · Cache poisoning · SSRF via Host · X-Forwarded-Host/X-Host-Override trust
cors – CORS Misconfiguration (6) Reflected origin with credentials · null origin · Regex bypass · Wildcard on sensitive data · Exposed headers
proto – Prototype Pollution (6) Query-string pollution · JSON body pollution · constructor bypass · toString DoS · Unicode-escape bypass
crypto – Cryptographic Failures (8) Predictable PIN · ECB decryption oracle · CBC bit-flipping · Hash length extension · MD5 cracking · XOR crib dragging
oauth – OAuth Flaws (8) Redirect-URI bypass · Code leakage · Missing state (login CSRF) · Implicit flow · Scope tampering · Code replay · PKCE skip
postmsg – postMessage Flaws (5) Missing origin check · Wildcard targetOrigin leak · Unsanitized data to HTML · Substring origin bypass · Forged actions
csti – Client-Side Template Injection (5) Basic {{7*7}} evaluation · Delimiter filter bypass · Constructor breakout · Attribute context · Stored template
http – HTTP Layer Flaws (6) CRLF log injection · Method override · Verb tampering · X-Forwarded-For trust · Cache deception · Referer auth
jsonp – JSONP Injection (5) Callback XSS · JSONP data theft · Callback filter bypass · Array-constructor hijack · MIME sniffing
formula – CSV Formula Injection (4) Classic =cmd · DDE execution · HYPERLINK exfiltration · Pipe prefix
redos – ReDoS (4) Catastrophic email/URL regexes · Nested-quantifier username · Regex-injection search

Rules

  1. Attack only this application.
  2. Flags prove exploitation. Share write-ups, not just flags.
  3. Built for learning. If you find an unintended vulnerability, that's a bonus flag in spirit.

License

Educational use only. Built by The PenTrix.

About

🔬 Advanced vulnerability testing laboratory and Vulnerable Web App & Linux Machine | Comprehensive security research environment with pre-configured vulnerable apps, automated testing scenarios, and CVE analysis | The PenTrix flagship product for professional penetration testers

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages