uncrypt // practice range
Find out what an attacker would.
74 hands-on labs across five attack tracks — a Burp Suite primer, the OWASP Top 10, other modern web attacks and two AI/LLM tracks. Every lab opens in a sandbox built to be attacked; the proxy tracks expect you to bring Burp. Capture the flag, then read why it worked — and earn certificates of completion along the way.
move your pointer — recon reveals the range
Attack tracks
Pick your track. One at a time.
Burp Suite 101
Learn the proxy the hands-on way: intercept, repeat, edit and decode real requests against friendly targets. Finish this track first — every other one assumes these moves.
0/6 Open → Track 02OWASP Top 10
The classic attack paths of the OWASP Top 10 (2021), grouped by category — broken access control, injection, security misconfiguration, integrity failures and SSRF. Mostly proxy-driven.
0/36 Open → Track 03Other Modern Web Attacks
Real-world bugs that fall outside the Top 10 list: CSRF in all its flavours and open redirects that survive modern defences.
0/12 Open → Track 04OWASP AI Top 10
The OWASP Top 10 for LLM applications, live: supply chain, RAG weaknesses, unbounded consumption, misinformation, plugin design and runaway agency — against simulated models.
0/10 Open → Track 05More AI/ML Sec Labs
Hands-on AI attacks beyond the numbered list — jailbreaks, unsafe output rendering, tool abuse, classifier evasion and memorised-data extraction.
0/10 Open →