Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Challenges

Level 1

  • (*---) Log in.
  • (*---) Provoke an XSS attack on a specific page.
  • (*---) Give a feedback comment on the behalf of someone else.
  • (*---) Enter a reimbursement request with an invalid IBAN.

Level 2

  • (**--) Provoke an XSS attack that triggers a new reimbursement request.
  • (**--) Log in as someone else without using the login screen.
  • (**--) Check other people’s holidays.

Level 3

  • (***-) Delete a profile picture.
  • (***-) Provoke an XSS attack on any page.

Level 4

  • (****) Leak the database schema.
  • (****) Leak any database table.
  • (****) Log in as an administrator.
  • (****) Retrieve a user’s password.
  • (****) Read ELEFAN’s config remotely.