Browser Emulator
Built-in iframe sandbox for direct interaction with the challenge application
Browser-based web exploitation challenge platform powered by WASM — no backend required, ready to run instantly
WXL (Web Exploitation Laboratory) is a fully front-end Web security challenge platform powered by WebAssembly. Every challenge backend — Flask, FastAPI, PHP — runs entirely inside the browser, so realistic pentest practice needs zero server. A built-in HTTP Repeater, Python Code Editor, and Network Traffic Log together provide a complete attack toolchain.
A white-box assessment of Kestrel Press's editorial workspace, where contributors draft teaching materials and curriculum editors assemble selected excerpts into a course pack.
A white-box engagement against Corvid Labs' internal prompt library, whose editor tells authors that rendering a preview runs in a restricted environment.
A black-box engagement against Corkboard, an intranet noticeboard whose admin console is meant to open only for accounts carrying the administrator flag.
Open the challenges page and pick one by difficulty or category.
Use the tools the challenge offers — Browser, Code Editor, Network Traffic Log, and Repeater — to analyse and exploit the vulnerability.
Once you find the flag, paste it into the submit box on the challenge page to confirm your answer.