85 modules of short lessons on real web attacks: SQL injection, cross-site scripting, broken logins, API flaws and more. Each lesson ends with a quick check, and many let you try the attack yourself right in your browser.
Pick a topic, or follow a path that puts the modules in order.
Understand the web before you hack it. HTTP, auth, APIs, DevTools, and the OWASP Top 10 — the foundation every attacker needs.
Every way user input becomes a weapon. SQL, NoSQL, command, template, XML, and file-upload injection — from login bypass to full server compromise.
Go beyond alert(1). Cover every XSS variant from reflected to blind, learn how attackers chain XSS into account takeovers, and understand why CSP often fails to stop it.
Break login systems end to end. Brute force, session hijacking, password reset abuse, 2FA bypass, and OAuth flaws, practised on realistic banking and social app scenarios.
Attack the modern web. REST, GraphQL, JWT, OAuth, and mass assignment — the vulnerabilities that ship in every API.
Map the full attack surface before you fire a single request. Asset discovery, content enumeration, fingerprinting, secrets, and passive intel.
Master the tools every hacker uses daily. sqlmap, ffuf, curl, and hashcat — learn them properly so they work for you, not against you.
Go beyond web apps. Scan networks, escalate Linux privileges, crack passwords, enumerate services, exploit server misconfigurations, and analyse captured traffic.
Attack AI-powered products. Prompt injection, jailbreaking, and indirect attacks — the vulnerabilities that ship in every LLM integration.
Every lesson follows the same short loop. You earn XP as you go, badges for finishing topics, and a certificate for every module you complete.
Five to ten minutes each. What the bug is, the vulnerable code, how attackers use it, and the fix.
SELECT * FROM users WHERE user = ' $input ' # user input goes straight # into the query. That is the bug.
Quick questions after the lesson. Wrong answers explain why, so you learn from them.
Q: What does ' OR 1=1 -- do? a) crashes the database ✓ b) makes the check always true c) deletes the users table
Many lessons end with an exercise in your browser: type the attack, run it against a practice app, see what happens.
username › admin' -- → password check skipped ✓ logged in as admin +50 XP
Paths put the modules in a sensible order, from how the web works to advanced attacks.
Find real vulnerabilities in production systems and get paid. From how the web works to recon, the common bug classes, and writing a report a program will accept.
Conduct authorized security assessments of web applications. Build the methodology, tooling, and report quality expected on real client engagements.
Attack and probe AI/LLM systems. Find prompt injection flaws, jailbreaks, and indirect attack vectors in AI-powered products.

12 modules are free, including SQL Injection, Cross-Site Scripting (XSS), OWASP Top 10. Pro unlocks all 85.