Overview

30 labs solved across 16 vulnerability categories in one marathon session. Each technique below is directly applicable to real-world bug bounty hunting.

Quick Reference — All 30 Labs

#CategoryLabKey Technique
1SSRFBasic SSRFstockApi=http://localhost/admin
2SSRFBlacklist bypass127.1 + double-encode %2561
3SQLiBlind time delay`'
4SSTIBasic ERB<%= system("cmd") %>
5Access ControlX-Original-URLHeader overrides blocked path
6File UploadPath traversalfilename="..%2fshell.php"
7NoSQLBoolean extractionthis.password[N]=='X' per char
8CSRFMethod bypassPOST to GET skips token check
9Cache DeceptionPath delimiters/my-account;wcd.js cached as static
10-12LLM3 labsAPI enum, OS cmd injection, XSS via output
13Info Disclosure.git historyAdmin password in deleted commit
14AuthenticationUsername enumTrailing space vs period in error
15XXEFile retrieval<!ENTITY xxe SYSTEM "file:///etc/passwd">
16Access ControlIDOR transcript/download-transcript/1.txt
17Info DisclosureError messagesApache Struts version in stack trace
18Info DisclosureDebug pageSECRET_KEY in phpinfo environment
19Info DisclosureBackup filesDB password in .java.bak
20Info DisclosureAuth bypassX-Custom-IP-Authorization: 127.0.0.1
21Logic FlawClient-side trustChange price=133700 to price=1
22AuthenticationPassword resetEmpty token + change username
23XXESSRF to AWSTraverse 169.254.169.254 for IAM creds
24DeserializationPHP objectadmin";b:0 to admin";b:1
25Access ControlMass assignmentAdd "roleid":2 to JSON body
26Access ControlIDOR password?id=administrator shows password
27CORSOrigin reflectionXHR from exploit server steals API key
28CORSNull originSandboxed iframe sends null Origin
29WebSocketXSSRaw <img onerror> bypasses client encoding
30Access ControlIDOR UUIDFind UUID from blog, access account

Key Learning Gaps Fixed

1. Subtle Response Detection: Never .strip() error messages when enumerating. A trailing space vs period is a valid signal.

2. Web Cache Poisoning: Duplicate Host headers require Burp’s HTTP stack. Raw sockets get rejected with 400.

3. PHP Deserialization: Session cookies can contain serialized objects. Decode base64, flip boolean flags, re-encode.

Bug Bounty Severity Cheat Sheet

TechniqueSeverityWhere to Look
SSRF to cloud metadataP1URL params, webhooks, imports
SSTI to RCEP1Error pages, email templates, PDF generators
XXE to file readP1-P2XML parsers, DOCX/SVG uploads
IDORP1-P3Sequential IDs, UUIDs in URLs/APIs
DeserializationP1Session cookies, API payloads
NoSQL injectionP1-P2JSON APIs with MongoDB
File upload RCEP1Any upload feature
Mass assignmentP2JSON API update endpoints
CORS misconfigurationP2-P3Check ACAO header reflection
CSRF bypassP2-P3State-changing actions
WebSocket XSSP2Live chat, real-time features
Info disclosureP3-P4.git, backup files, error pages, debug endpoints

30 labs, one session, zero sleep. Techniques for authorized testing only.