An interactive training ground to explore modern web vulnerabilities.
View the C2 server logs to see if any cookies or data have been exfiltrated.
Launch LabSimulate a Man-in-the-Browser attack by injecting JS into the login page via DevTools.
Launch LabBypass SameSite=Lax cookie protection using a compromised but same-site subdomain.
Launch LabTest how browsers handle automatic downloads initiated from a cross-origin iframe.
Launch LabExplore browser permissions and user gestures required for clipboard access.
Launch LabExploit `window.opener` to perform a phishing attack on the previous tab.
Launch LabTest how browsers block cross-origin data reads and handle 'no-cors' requests.
Launch LabDiscover real IP addresses bypassing standard proxies via WebRTC STUN negotiation.
Launch Lab