Web & API Security

Surface LabsWeb & API Attack Surface Assessment

Practice discovering and exploiting vulnerabilities in modern web applications and APIs. Prepare for bug bounty hunting and web application penetration testing.

...
Surface Lab(s)
10+
Vulnerability Types
OWASP
Aligned

What You'll Practice

Surface Labs provide modern web and API environments for comprehensive security testing.

Modern Web Apps

Practice on React, Next.js, and other modern web frameworks with realistic vulnerabilities.

API Security

REST and GraphQL APIs with authentication flaws, IDOR, and injection vulnerabilities.

Bug Bounty Prep

Environments designed to simulate real bug bounty targets and attack surfaces.

Security Headers

Learn to identify and exploit misconfigurations in CSP, CORS, and other security headers.

Vulnerability Categories

Practice finding and exploiting real-world web vulnerabilities based on OWASP Top 10 and beyond.

SQL Injection
Critical
XSS (Cross-Site Scripting)
High
IDOR (Insecure Direct Object Reference)
High
SSRF (Server-Side Request Forgery)
High
Authentication Bypass
Critical
JWT Vulnerabilities
High
API Rate Limiting Issues
Medium
Information Disclosure
Medium
CORS Misconfiguration
Medium
Business Logic Flaws
High

Available Surface Labs

1 lab is free to get started. Modern web environments for comprehensive security testing.

Advanced

DevForge

2300 pts
13 Flags
10.15.13.11

Welcome to DevForge, a modern CI/CD platform used by development teams to manage their code repositories, automate build pipelines, and deploy applications. As a security researcher, you have been granted access to test the platform for vulnerabilities.

API security assessmentOAuth exploitation techniquesCI/CD pipeline securityMulti-stage attack chains
by Icex64
View Lab
FREEBeginner

HomeHub

1900 pts
14 Flags
10.15.13.10

Smart Home IoT Dashboard - A modern smart home management platform that allows users to control their IoT devices from a single, unified dashboard. The beta platform features device monitoring, automation rules, and family sharing. Your mission is to identify vulnerabilities before malicious actors discover them.

Web application reconnaissanceAuthorization bypass techniquesInjection attacks
by Icex64
View Lab

Perfect For

Bug Bounty Hunters

Sharpen your reconnaissance and exploitation skills before hunting on real platforms.

Web App Pentesters

Practice methodologies used in professional web application assessments.

Security Engineers

Understand vulnerabilities from an attacker's perspective to build more secure apps.

Start Finding Vulnerabilities

Practice web and API security testing in a safe environment. Build the skills that pay in bug bounties.