PentesterLab

Visit platform ↗

Paid tier existsAll levelsActive

Specifications

Specifications
FormatLabs, Learning
LevelBeginner, Intermediate, Advanced
PricePaid tier exists
AccessRegistration required
ActivityActive
LanguageEN
CategoryWeb, Secure code

Web labs grouped by OWASP topic, with a video walkthrough beside each one. The labs are built on real CVEs rather than invented bugs, so the fix you learn is the fix that shipped. The site advertises more than 700 hands-on labs; the free share covers most of the Top 10.

Pros & cons

Pros

  • Labs are built on real CVEs, so the pattern survives outside the lab
  • Video walkthroughs follow the same topics as the labs
  • The free share covers most of the OWASP Top 10 on its own

Cons

  • The video walkthroughs sit behind a Pro subscription
  • An account is required, and some exercises run on external infrastructure
  • The advertised 700-plus total is sales copy, and lab coverage still has gaps

Who it fits

Fits someone who wants theory and web practice in one place. Especially useful before an interview, because labs and videos follow one classification and a solved lab doubles as revision of it.

Getting started

  1. Register, then start in the free exercises and work them topic by topic
  2. Finish a lab topic before starting its video, otherwise it answers nothing
  3. Check which CVEs apply to your own stack and go look at the patches

History

Grew out of a web security course and still tracks the CVE stream, adding labs as advisories land. The front page advertises more than 700 hands-on labs and a matching set of videos; read that as a marketing total rather than a measured one. The free portion has not shrunk. Checked.