Specifications
| Format | Challenges |
|---|---|
| Level | Beginner, Intermediate |
| Price | Free |
| Access | Registration required |
| Activity | Rarely updated |
| Language | EN |
| Category | Web |
A web quest running since 2003, climbing from malformed HTML through XSS and SQL injection to access-control bypasses. Every level ships with a writeup, and the sequence was laid out when such bugs were still live on most stacks. The code has barely moved since.
Pros & cons
Pros
- A proven chain of web bug classes, in an order somebody thought about
- A writeup per level explaining the check rather than just printing the flag
- Free, and the explanations have aged better than the code
Cons
- Last code change was in 2016, so some checks still assume an old stack
- The interface reads as a 2000s hobby project and the checkers are quirky
- The migration and recode announced for spring 2026 had not landed when checked
Who it fits
Fits as a web baseline, especially for people who learned from parameter handling and want the ordered version of it. Less use once you can read a modern framework, though the low levels still hold up.
Getting started
- Register and clear the first ten levels in sequence, later ones lean on the earlier ones
- Read the writeup after each level rather than before, it explains why the check failed
- Note the checks that surprised you, those are the ones you will misremember
History
The site has run since 2003, a year it states itself, and the code was last updated in 2016 at version 3.2.5. A December 2025 post announced a server migration and a recode planned for spring 2026; at the check, that recode was still not in place, which is why activity reads as slowing rather than abandoned.