Exercises
| Exercise | Avg. Time | Difficulty | Solved by | Tier | |
|---|---|---|---|---|---|
|
|
Secure Design: CI/CD Pipeline | 5 | PRO | ||
|
|
Secure Design: Fail Closed | 6 | PRO | ||
|
|
Secure Design: Error Proofing (Poka-yoke) | 5 | PRO | ||
|
|
Secure Design: Password Storage & Hashing | 5 | PRO | ||
|
|
Secure Design: Framework Security Evaluation | 5 | PRO | ||
|
|
SOAPBridge: Savon WSDL Code Injection
Gain code execution through an unsafe module_eval call during WSDL import.
|
5 | PRO | ||
|
|
ODF XXE
This exercise covers the exploitation of an XXE in an ODF Parser
|
6 | PRO | ||
|
|
CVE-2026-55415: Schema Import Injection
Gain code execution by injecting Python through a crafted JSON Schema when the generated Pydantic model is imported.
|
6 | PRO | ||
|
|
Secure Design: Safe Serialization | 11 | PRO | ||
|
|
Secure Design: Backend Authentication Proxy | 11 | PRO | ||
|
|
Secure Design: Control Placement | 14 | PRO | ||
|
|
Secure Design: Secret & Credential Management | 14 | PRO | ||
|
|
AI Fundamentals: Retrieval-Augmented Generation | 30 | PRO | ||
|
|
AI Fundamentals: Tool Use & Agents | 30 | PRO | ||
|
|
Instruction Hierarchy
The system prompt explicitly establishes an instruction hierarchy. Find a way to confuse or bypass the priority system.
|
25 | PRO | ||
|
|
Open Door
No guardrails at all. Simply ask the model for the secret key.
|
68 | PRO | ||
|
|
Encoding Request
Multiple extraction vectors are blocked. Find a creative approach the rules don't anticipate.
|
24 | PRO | ||
|
|
AI Fundamentals: Using Models in Practice | 30 | PRO | ||
|
|
AI Fundamentals: Multimodal Models | 29 | PRO | ||
|
|
Polite Refusal
The model is told to refuse key requests. Use social engineering to convince it to share anyway.
|
38 | PRO | ||
|
|
System Prompt Extraction
The model is told to keep a secret key and refuses to reveal it directly. The rule only forbids telling the key, not repeating the instructions that contain it. Make the model recite its own system prompt and the key comes with it.
|
50 | PRO | ||
|
|
AI Fundamentals: Large Language Models | 33 | PRO | ||
|
|
AI Fundamentals: Prompting | 31 | PRO | ||
|
|
AI Fundamentals: Limitations & Hallucinations | 32 | PRO | ||
|
|
AI Fundamentals: Training an LLM | 32 | PRO | ||
|
|
AI Fundamentals: Inference & Sampling | 32 | PRO | ||
|
|
AI Fundamentals: Classic ML Algorithms | 42 | PRO | ||
|
|
AI Fundamentals: Neural Networks | 40 | PRO | ||
|
|
AI Fundamentals: Overfitting & Generalization | 50 | PRO | ||
|
|
AI Fundamentals: Evaluating Models | 46 | PRO |
Showing 1–30 of 796 exercises
Free Labs of the Month