HACKR.GG
▸ Web security, explained and practised

Learn how websites get hacked. And how to stop it.

85 modules of short lessons on real web attacks: SQL injection, cross-site scripting, broken logins, API flaws and more. Each lesson ends with a quick check, and many let you try the attack yourself right in your browser.

✓ 12 modules free✓ No credit card✓ Nothing to install
Try a practice exercise: log in as admin without the password.
admin.shoppr.test — inline labSQLi
Shoppr — staff sign-in
Log in as admin without the password.
admin' --' OR 1=1 --UNION SELECT …
SELECT username, role FROM users WHERE username = '' AND password = '…'
Awaiting input… the query above updates as you type.
Stuck? reveal a hint
85modules
628short lessons
1,340quiz questions
144practice exercises
~60hours of material
// What you'll learn

The attacks behind real breaches, one topic at a time.

Pick a topic, or follow a path that puts the modules in order.

Web Fundamentals

8 modules

Understand the web before you hack it. HTTP, auth, APIs, DevTools, and the OWASP Top 10 — the foundation every attacker needs.

Linux & CLI FundamentalsfreeHow the Web WorksfreeHow Authentication Worksfree

Injection Attacks

10 modules

Every way user input becomes a weapon. SQL, NoSQL, command, template, XML, and file-upload injection — from login bypass to full server compromise.

SQL Injectionfreesqlmap — Automated SQL InjectionNoSQL Injection

Mastering XSS

8 modules

Go beyond alert(1). Cover every XSS variant from reflected to blind, learn how attackers chain XSS into account takeovers, and understand why CSP often fails to stop it.

Cross-Site Scripting (XSS)freeStored XSS — Persistent Cross-Site ScriptingfreeDOM-Based XSSfree

Authentication Attacks

12 modules

Break login systems end to end. Brute force, session hijacking, password reset abuse, 2FA bypass, and OAuth flaws, practised on realistic banking and social app scenarios.

How Authentication WorksfreeBroken Authentication

API Security

8 modules

Attack the modern web. REST, GraphQL, JWT, OAuth, and mass assignment — the vulnerabilities that ship in every API.

APIs & Modern Web AppsJWT Attacks

Recon & OSINT

9 modules

Map the full attack surface before you fire a single request. Asset discovery, content enumeration, fingerprinting, secrets, and passive intel.

Recon — Content DiscoveryRecon — Tech Stack FingerprintingRecon — Asset Discovery

Hacker Toolkit

5 modules

Master the tools every hacker uses daily. sqlmap, ffuf, curl, and hashcat — learn them properly so they work for you, not against you.

Burp Suite — The Hacker's Proxycurl — HTTP from the Command Lineffuf — Web Fuzzing

Network & Systems Hacking

9 modules

Go beyond web apps. Scan networks, escalate Linux privileges, crack passwords, enumerate services, exploit server misconfigurations, and analyse captured traffic.

Network Scanning with NmapNetwork EnumerationSSH Attacks

LLM & AI Security

3 modules

Attack AI-powered products. Prompt injection, jailbreaking, and indirect attacks — the vulnerabilities that ship in every LLM integration.

Prompt InjectionfreeLLM JailbreakingIndirect Prompt Injection
// How it works

Read it, check it, try it.

Every lesson follows the same short loop. You earn XP as you go, badges for finishing topics, and a certificate for every module you complete.

STEP 01

Read a short lesson

Five to ten minutes each. What the bug is, the vulnerable code, how attackers use it, and the fix.

SELECT * FROM users
WHERE user = '
$input
'
# user input goes straight
# into the query. That is the bug.
STEP 02

Check you got it

Quick questions after the lesson. Wrong answers explain why, so you learn from them.

Q: What does  ' OR 1=1 --  do?
  a) crashes the database
✓ b) makes the check always true
  c) deletes the users table
STEP 03

Try it yourself

Many lessons end with an exercise in your browser: type the attack, run it against a practice app, see what happens.

username › admin' --
→ password check skipped
✓ logged in as admin
+50 XP
// Certification

Prove it with the HJPT exam.

  • A hands-on exam against Hexapay, a fictional fintech app, in six parts.
  • You exploit the bugs yourself in browser-based practice apps, then answer questions on what you found.
  • Pass and get a certificate anyone can check at hackr.gg/verify.
HJPT — hackr.gg Junior Pentester
// Start here

Start with the free modules.

12 modules are free, including SQL Injection, Cross-Site Scripting (XSS), OWASP Top 10. Pro unlocks all 85.