Live training range

Break real vulnerabilities.
Learn the OWASP Top 10 by hand.

Ten self-contained labs, one per vulnerability class. Every flag is verified server-side — no shortcuts, no answers in the page source.

Create an account →
Meet the target

Every lab in this range attacks the same fictional company — ShopFast Inc., a mid-size e-commerce and payments platform. As you clear labs, you're mapping out weaknesses across its actual systems: the storefront, the payments arm, the admin console, the CI/CD pipeline, and more. One target, ten different ways in — all under shopfast.io.

ShopFast Pay
payments API
A01 · A02
ShopFast Store
storefront + search
A03 · A06
ShopFast Accounts
auth + password reset
A04 · A07
Admin Console
internal tooling
A05
ShopFast Engineering
CI/CD pipeline
A08
ShopFast Monitoring
logging + alerting
A09
Orders API
order lookup service
A10

ShopFast systems under test

All ten OWASP Top 10 (2021) categories, A01–A10, one lab each — same company, different system each time.

Leaderboard

Ranked by points earned across cleared labs.