Ethical Root
Vulnerability
Simulator
Train on real attack patterns. Deploy real defenses. Earn your rank.
Script Kiddie
0 / 1950 Points
NEXT: White Hat Apprentice
+300 more points needed
OWASP Top 10 Modules
SQL Injection
A03:2021 – Injection
PTS
Inject malicious SQL queries through input fields to manipulate backend databases. Extract, modify, or destroy sensitive data.
XSS
A03:2021 – Injection
PTS
Inject malicious scripts into web pages viewed by other users. Steal cookies, session tokens, or redirect to phishing pages.
IDOR
A01:2021 – Broken Access Control
PTS
Access unauthorized resources by manipulating direct object references in URLs or API parameters.
Misconfig
A05:2021 – Security Misconfiguration
PTS
Exploit default credentials, exposed admin panels, debug endpoints, and verbose error messages left enabled in production.
Broken Auth
A07:2021 – Identification and Authentication Failures
PTS
Exploit weak authentication mechanisms — credential stuffing, session prediction, and brute force attacks against login systems.
CSRF
A01:2021 – Broken Access Control
PTS
Trick authenticated users into executing unwanted actions on web applications where they are currently logged in.
Data Exposure
A02:2021 – Cryptographic Failures
PTS
Intercept sensitive data transmitted over unencrypted channels. Capture passwords, credit cards, and personal information in transit.
XXE
A05:2021 – Security Misconfiguration
PTS
Exploit XML parsers that process external entities to read internal files, perform SSRF, or cause denial of service.
Deserialization
A08:2021 – Software and Data Integrity Failures
PTS
Exploit deserialization flaws to trigger remote code execution by crafting malicious serialized objects.
SSRF
A10:2021 – Server-Side Request Forgery
PTS
Trick the server into making requests to internal resources, cloud metadata endpoints, or other restricted networks.