Bug Bounty Labs · a growing library of playable methodologies

Premium · CCLI

Every technique worth knowing, rebuilt as a lab you can fire.

Not writeups you skim — playable reconstructions. Each methodology is a self-contained, in-browser lab where you send the real probe against a sandboxed target and watch it break. New methods land as they're discovered and reverse-engineered.

🔒 Premium members Runs in your browser · nothing installed EN / ES

The library

Methodologies

One card per technique. Live ones open a full interactive lab; the rest are queued and land continuously.

#01

Server-Side Template Injection

The {{7×7}} → 49 tell. Fire probes at a real sandboxed template engine and watch reflection turn into evaluation.

● LIVEopen lab →
#02

ORM Leak

Coax a data-access layer into returning rows it never should — operator abuse and relationship traversal.

queued
#03

SSRF via Redirect Loops

Bounce a fetch through redirects to reach internal metadata endpoints past naive allow-lists.

queued
#13

HTTP/1.1 Desync Endgame

Split one connection into two views. Watch a smuggled request steal the next visitor's response.

queued
#10

Parser Differentials

Two parsers, one input, two readings. The gap between them is the vulnerability.

queued
#43

Passkey Auth Bypass

Where WebAuthn's promises meet real-world implementation gaps.

queued
How this grows. Every methodology that gets discovered, published, or reverse-engineered becomes a lab here. Members see the count climb — there's no fixed ceiling.