HackThisSite

Visit platform ↗

FreeBeginnerIntermediateRarely updated

Specifications

Specifications
FormatChallenges
LevelBeginner, Intermediate
PriceFree
AccessRegistration required
ActivityRarely updated
LanguageEN
CategoryWeb

A web quest running since 2003, climbing from malformed HTML through XSS and SQL injection to access-control bypasses. Every level ships with a writeup, and the sequence was laid out when such bugs were still live on most stacks. The code has barely moved since.

Pros & cons

Pros

  • A proven chain of web bug classes, in an order somebody thought about
  • A writeup per level explaining the check rather than just printing the flag
  • Free, and the explanations have aged better than the code

Cons

  • Last code change was in 2016, so some checks still assume an old stack
  • The interface reads as a 2000s hobby project and the checkers are quirky
  • The migration and recode announced for spring 2026 had not landed when checked

Who it fits

Fits as a web baseline, especially for people who learned from parameter handling and want the ordered version of it. Less use once you can read a modern framework, though the low levels still hold up.

Getting started

  1. Register and clear the first ten levels in sequence, later ones lean on the earlier ones
  2. Read the writeup after each level rather than before, it explains why the check failed
  3. Note the checks that surprised you, those are the ones you will misremember

History

The site has run since 2003, a year it states itself, and the code was last updated in 2016 at version 3.2.5. A December 2025 post announced a server migration and a recode planned for spring 2026; at the check, that recode was still not in place, which is why activity reads as slowing rather than abandoned.