Initializing secure environment
CYBERLABS Internal
NI
Cohort briefing — New Web Exploitation labs drop Friday. Finish the SQL Injection path this week to stay on track for the cohort challenge.
Good evening

Welcome back, Najeeb

najeeb@cyberlabs:~$
Lv 4
Operative62% to Specialist
1,240
Points
18
Solved
#7
Rank
5
Day streak

Skill map

Click a category to open
Web 85%
Crypto 55%
Forensics 45%
OS 60%
Pwn 30%
Reversing 50%
OSINT 70%
Stego 40%

Continue training

Web Exploitation · Intro

SQL Injection — Login Bypass

1 / 4 tasks · 100 pts

Recommended for you

See all
Course
Web Exploitation

Reflected XSS Basics

Find and exploit a reflected XSS flaw.

Easy100 pts
Cryptography

Classic Ciphers

Break Caesar, Vigenère & substitution.

Easy100 pts
Forensics

Phishing Triage

Analyse a suspicious email safely.

Easy100 pts

Weekly streak

5 days
·
·
Solve 1 task today to keep your streak alive.

Leaderboard

1MKm.karimova3,410
2ARa.rahimov2,980
3JTj.tashkent2,640
7NIYou1,240
Full leaderboard →

Recent activity

Solved “SQL Injection”
Web · +100 pts
2h
Solved “Classic Ciphers”
Crypto · +100 pts
1d
Unlocked tracks

Categories

Browse labs and challenges by category. Empty tracks are coming soon.

AI / ML
None yet
Soon
Binary Exploitation / Pwn
44 challenges
44
Blockchain / Smart Contracts
None yet
Soon
Cryptography
64 challenges
64
Forensics
48 challenges
48
Malware Analysis
11 challenges
11
Malware Engineering
None yet
Soon
Miscellaneous
37 challenges
37
Mobile
None yet
Soon
Networking
16 challenges
16
OS
81 challenges
81
OSINT
33 challenges
33
Reverse Engineering
44 challenges
44
Steganography
16 challenges
16
Web Exploitation
213 challenges
213

Labs

Download the files, follow the walkthrough, and submit your answers. Each lab has its own icon; filter by category below.

All My course Web Crypto Forensics OS Pwn Reversing OSINT Stego Malware
Course
Web Exploitation

Web Security Fundamentals

Read-along primer on the core web attack surface — no answer to submit.

5 min read
CourseSolved
Web Exploitation

SQL Injection — Login Bypass

Bypass a login form using unsanitised input; 4 guided tasks.

Easy100 pts
Course
Web Exploitation

Reflected XSS Basics

Find and exploit a reflected cross-site scripting flaw.

Easy100 pts
Course
Web Exploitation

Broken Access Control

Reach another user's data by tampering with an ID.

Medium200 pts
CourseSolved
Cryptography

Classic Ciphers

Break Caesar, Vigenère, and substitution ciphers.

Easy100 pts
Cryptography

Hashes & Cracking

Identify hash types and recover weak passwords.

Medium200 pts
Cryptography

Weak RSA

Recover a key from poorly chosen RSA parameters.

Hard350 pts
CourseSolved
Forensics

Phishing Email Triage

Analyse headers and payloads from a suspicious .eml.

Easy100 pts
Forensics

PCAP: Find the Exfil

Trace data exfiltration in a captured session.

Medium200 pts
OS

Linux Privilege Escalation

Escalate from a low-priv user to root on a Linux box.

Medium200 pts
OS

Windows Log Hunt

Spot the attacker's foothold in Windows event logs.

Hard350 pts
Binary Exploitation

Buffer Overflow 101

Smash the stack and redirect execution flow.

Hard350 pts
Reverse Engineering

Crackme #1

Reverse a small binary to recover the correct key.

Medium200 pts
OSINT

Trace the Handle

Pivot across public sources to identify an account.

Easy100 pts
Steganography

Hidden in Plain Sight

Extract a secret concealed inside an image file.

Easy100 pts
Malware Analysis

Static Triage

Profile a sample with static analysis — no detonation.

Medium200 pts

No matching labs

Try a different category or clear your search.

Capture the Flag

Challenges

Standalone CTF challenges — no walkthrough. Grab the files, find the flag, submit it for points.

Active event

Season 1 · Capture the Flag

Ends in 12d 04h
1,240
Points
3
Solved
#7
Rank
All Web Crypto Pwn Reversing Forensics OSINT Stego Misc
Web150 pts

Cookie Monster

Easy84 solves
Web300 pts

Algorithm: None

Medium41 solves
Crypto200 pts

XOR Me

Easy63 solves
Crypto450 pts

Faulty Signature

Hard9 solves
Pwn400 pts

Ret2Win

Hard12 solves
Reversing350 pts

Keygen Me

Medium22 solves
Forensics250 pts

Carve It Out

Medium38 solves
OSINT150 pts

Ghost Handle

Easy71 solves
Stego200 pts

Deep Pixel

Easy45 solves
Misc50 pts

Sanity Check

Easy120 solves

Leaderboard

Season 1 · ranked by points earned across all labs and challenges.

Overall My cohort
#2
AR
a.rahimov
2,980 pts
#1
MK
m.karimova
3,410 pts
#3
JT
j.tashkent
2,640 pts
RankStudentSolvedPoints
01
MKm.karimova
343,410
02
ARa.rahimov
312,980
03
JTj.tashkent
282,640
04
SDs.davron
252,300
05
NBn.bek
222,010
06
LTl.turgun
201,740
07
NInajeebibrahimmYOU
181,240
08
RSr.sultan
161,120
Ranking within your cohort · Tashkent 2026
RankStudentSolvedPoints
01
SDs.davron
252,300
02
LTl.turgun
201,740
03
NInajeebibrahimmYOU
181,240
04
RSr.sultan
161,120
05
AKa.komil
13910

Profile

Your progress, achievements and account.

NI

Najeeb Ibrahim

@najeebibrahimm · joined Jul 2026
Rank #7Top track: Web Exploitation5-day streak
Approved Cohort: Tashkent 2026 Operative · Lv 4
1,240
Points
18
Solved
5
Streak
#7
Rank

Skills breakdown

Web 85%
Crypto 55%
Forensics 45%
OS 60%
Pwn 30%
RE 50%
Web Exploitation12 / 213
Cryptography4 / 64
Forensics2 / 48

Achievements

First Blood
First solve
Web Warrior
10 web labs
On Fire
5-day streak
Cryptographer
Locked
Pathfinder
Locked
Top 3
Locked

Account & access

StatusApproved
RosterCohort Tashkent 2026
RoleStudent
Emailnajeeb@edu.cyberlabs-usa.com
Connected Google GitHub

Recent activity

Solved “SQL Injection”
Web · +100 pts
2h
Solved “Classic Ciphers”
Crypto · +100 pts
1d
Solved “Phishing Triage”
Forensics · +100 pts
3d

Preferences

Language
Interface language
Email notifications
New labs & results
Reduced motion
Dim background animation
Theme
Light or dark
Sign out
End this session
Prove your skills

Skillchecks

Per-track skill assessments — pass one to prove you've mastered a track. Submissions are verified and released by an instructor.

Passed

Web Exploitation

Skill assessment
6 · 60m · 300
Pending review

Cryptography

Skill assessment
5 · 45m · 300
Available

Forensics

Skill assessment
5 · 60m · 300
Available

Operating Systems

Skill assessment
6 · 90m · 350
Locked

Binary Exploitation

Skill assessment
4 · 120m · 450
Available

Reverse Engineering

Skill assessment
5 · 90m · 350
Instructor tools

Admin

Create students, release solves, and schedule content releases.

Students Solve reviews 3 Schedule

Create a user

Students can't self-register — accounts are provisioned here (closed registration).

Roster

StudentEmailCohortRoleStatusActions

Pending solve releases

When a student solves a lab or skillcheck it waits here until you release it.

StudentItemTrackSubmitted
ARa.rahimov
Ret2WinPwn12m
MKm.karimova
Web Exploitation (skillcheck)Web1h
LTl.turgun
SQL Injection — Login BypassWeb3h

All caught up

No submissions waiting for release.

Content release schedule

Schedule when labs, skillchecks and CTFs become visible to students.

ContentTypeTrackRelease date
Web Track — Final ChallengeCTFWebAug 12
Cryptography & Reversing pathPathCryptoAug 15
Malware Analysis packLabsMalwareAug 20
Web Exploitation SkillcheckSkillcheckWebAug 6Published

Settings

Manage your account, appearance and notifications.

Account & access

Display name
Emailnajeeb@edu.cyberlabs-usa.com
StatusApproved
ConnectedGoogleGitHub

Appearance

Theme
Light or dark
Language
Interface language
Reduced motion
Dim background animation

Notifications

New labs & challenges
Results & solves
Cohort announcements

Security

Two-factor authentication
Extra protection at sign-in
This device
Tashkent · Chrome

Danger zone

Delete account
Requires admin approval
All labs
Web Exploitation

SQL Injection — Login Bypass

Easy 100 pts Course
0/4
Tasks

Walkthrough

1. What is SQL injection?

Web apps often build a database query by pasting user input straight into the query string. If a login form builds its query like this, the input becomes part of the command:

SELECT * FROM users
WHERE user = '$username'
  AND pass = '$password';

2. Breaking out of the string

Enter ' OR '1'='1 as the password. The quote closes the string, and the always-true OR makes the whole condition true — so the database returns a row and the app logs you in.

3. Try it

Download the sample app, run it locally, and sign in with the payload above. Then answer the tasks on the right.

Try the tasks first — the walkthrough is optional and unlocks automatically once you finish the room.

Tasks

Download task files
sqli-login-lab.zip · 42 KB
1Where does the untrusted input end up?text
Hint −10 pts
It's the component that runs the query.
2Which payload makes the condition always true?text
Hint −10 pts
Close the string, then add an always-true OR.
3Which account do you land on after the bypass?text
Hint −10 pts
It's the first row in the users table.
4Submit the flag shown after loginflag
Hint −10 pts
It appears on the dashboard once you're in.
Room complete! You've answered every task.

How was this lab?

Your feedback helps our authors tune difficulty.

Too easy
Just right
Too hard
Thanks — feedback recorded!
All labs
Web Exploitation

Web Security Fundamentals

Walkthrough Course
5 min read 4 sections

How the web gets attacked

Almost every web attack comes down to the same root cause: data supplied by a user is treated as trusted code or commands. Before you exploit anything, it helps to see the whole attack surface at once.

The request/response you can bend

A browser sends an HTTP request — a method, a URL, headers, and often a body. The server trusts far too much of it. Every part of that request is attacker-controllable, so every part is a potential injection point.

POST /login HTTP/1.1
Host: shop.example
Content-Type: application/x-www-form-urlencoded

user=admin&pass=' OR '1'='1

Where trust breaks down

Input concatenated into a query becomes SQL injection; reflected into a page becomes XSS; used to build a file path becomes path traversal; used to pick a record becomes broken access control. Same cause, different sink.

What to do next

You don't need to submit anything for this lab — just make sure the model above makes sense. When you're ready, mark it complete and start the SQL Injection lab in this path.

Finished reading?

Marking complete records this lab on your profile and advances your training path.

Completed
Reference sheet
web-attack-surface.pdf · 180 KB
Guided curricula

Training paths

Follow an ordered set of labs, from fundamentals to challenge. Your progress is tracked automatically as you solve.

Web track

Web Exploitation Fundamentals

From the HTTP request up to injection, XSS and access control.

6 modules ~4h 600
3 / 6 · 50%Continue
Forensics track

Forensics & Network Analysis

Triage emails, carve files, and follow the packets to the exfil.

5 modules ~3h 500
0 / 5 · Not startedStart
Crypto & RE track

Cryptography & Reversing

Break classic ciphers, crack hashes, and reverse a small binary.

5 modules ~5h 750
0 / 5 · Not startedStart
Blue team track

Blue Team Starter

Log hunting, detection and incident triage.

4 modules ~3h
Soon
All paths
Web track

Web Exploitation Fundamentals

Path Progressive ~4h
3/6
Modules
Web Security Fundamentals
Walkthrough · 5 min read
Done
SQL Injection — Login Bypass
Answer lab · 100 pts
Done
Reflected XSS Basics
Answer lab · 100 pts
Done
4
Broken Access Control
Answer lab · 200 pts
Continue
Server-Side Template Injection
Answer lab · 200 pts
Locked
Web Track — Final Challenge
CTF challenge · 350 pts
Locked