{"id":17979132,"url":"https://github.com/thelicato/portswigger-labs","last_synced_at":"2026-01-18T16:32:13.293Z","repository":{"id":61611012,"uuid":"451964678","full_name":"thelicato/portswigger-labs","owner":"thelicato","description":"A collection of solutions for every PortSwigger Academy Lab (in progress)","archived":false,"fork":false,"pushed_at":"2022-02-22T17:08:43.000Z","size":421,"stargazers_count":107,"open_issues_count":0,"forks_count":45,"subscribers_count":4,"default_branch":"main","last_synced_at":"2025-10-06T23:51:37.357Z","etag":null,"topics":["academy","burp","labs","portswigger","security"],"latest_commit_sha":null,"homepage":"","language":"HTML","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/thelicato.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2022-01-25T16:56:32.000Z","updated_at":"2025-09-27T13:18:57.000Z","dependencies_parsed_at":"2022-10-19T19:45:13.379Z","dependency_job_id":null,"html_url":"https://github.com/thelicato/portswigger-labs","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/thelicato/portswigger-labs","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/thelicato%2Fportswigger-labs","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/thelicato%2Fportswigger-labs/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/thelicato%2Fportswigger-labs/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/thelicato%2Fportswigger-labs/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/thelicato","download_url":"https://codeload.github.com/thelicato/portswigger-labs/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/thelicato%2Fportswigger-labs/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28541570,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-18T14:59:57.589Z","status":"ssl_error","status_checked_at":"2026-01-18T14:59:46.540Z","response_time":98,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["academy","burp","labs","portswigger","security"],"created_at":"2024-10-29T17:36:32.916Z","updated_at":"2026-01-18T16:32:13.277Z","avatar_url":"https://github.com/thelicato.png","language":"HTML","funding_links":[],"categories":[],"sub_categories":[],"readme":"# 🧪 PortSwigger Labs\n\nThis repo contains the solutions for the PortSwigger Labs available in the **Academy** section of their website: https://portswigger.net/web-security/all-labs\n\n## Why\nThis repo has been created to keep in a single place all the solutions of the labs. It should be helpful when preparing for the *Burp Suite Certified Practitioner* (https://portswigger.net/web-security/certification).\n\n## Tools\nThe tools needed (other than Burp Pro) to complete the labs.\n\n- **SQL Injection**: ``sqlmap``;\n- **XSS**: ``dalfox``, ``xsstrike``;\n- **Clickjacking**: None;\n- **DOM-based**: None;\n- **CORS**: None;\n- **XXE**: None;\n- **SSRF**: None;\n- **OS Command Injection**: None;\n- **Server-Side Template Injection**: None;\n- **Directory Traversal**: None;\n- **Access Control**: None;\n- **Authentication**: None;\n- **WebSockets**: None;\n- **Web Cache Poisoning**: None;\n- **Information Disclosure**: None;\n- **OAuth authentication**: None;\n- **File Upload Vulnerabilities**: ``ExifTool``;\n\n## Roadmap\nThis primary goal is to add the **Apprentice** and **Practitioner** level labs (since are the ones suggested to complete before taking the exam):\n- [x] SQL Injection Labs\n- [x] XSS Labs\n- [x] CSRF Labs\n- [x] Clickjacking Labs\n- [x] DOM-based vulnerabilities Labs\n- [x] CORS Labs\n- [x] XXE Injection Labs\n- [x] SSRF Labs\n- [ ] HTTP Request Smuggling Labs\n- [x] OS Command Injection Labs\n- [x] Server-Side Template Injection Labs\n- [x] Directory Traversal Labs\n- [x] Access Control Vulnerabilities Labs\n- [x] Authentication Labs\n- [x] WebSockets Labs\n- [x] Web Cache Poisoning Labs\n- [ ] Insecure Deserialization Labs\n- [x] Information Disclosure Labs\n- [ ] Business Logic Vulnerabilities Labs\n- [ ] HTTP Host Header Attacks Labs\n- [x] OAuth Authentication Labs\n- [x] File Upload Vulnerabilities Labs","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fthelicato%2Fportswigger-labs","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fthelicato%2Fportswigger-labs","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fthelicato%2Fportswigger-labs/lists"}