Activities

Advertising My Insecurities

Access it here!

A short exercise to use the browser developer tools to discover known vulnerabilities in an application.

Secrets of a Tester

Access it here!

Explore Insecure Direct Object Reference (IDOR) through this fun activity around accessing the secrets of a tester. These techniques may also be called URL manipulation and you're coming up with test cases for a URL.

Banana Fan Group Meetup

Access it here!

Explore how we can use browser developer tools to by pass client side validation. In this exercise you will be filling out an event registration but sending invalid values to find flags.

Cross Site Social

Access it here!

Explore Cross Site Scripting (XSS) through creating and modifying a profile.

Sea Quell

Access it here!

Find hidden treasures by using SQL injection in this helpful site for sea dogs.

Playground

Access it here!

Less deep than the usual activities, the Playground lets you play about with URL manipulation, validation, XSS and SQL injection in as open way as I was comfortable risking...

Security Testing Challenges

Access it here!

Get guided instructions to complete 10 challenges across a range of topics.

Tea Virus

Access it here!

In this activity you have a mission to complete. The Tea Virus is set to be unleashed upon the world and must be stopped. Another agents has implemented an exploit but you must trigger it.

Capture the Flag

Access it here!

Try to find 10 security defects hidden within a basic message posting application.


Created by Richard Adams Activities Home :: Resources