Security Practice
Practice security evidence, not exploit memorization
Compare security evidence, select the decisive clues, and retest the original defect, a bypass variant, and legitimate behavior.
Start free with Injection
Complete the Injection trainer for free, including all retests and your review. The other eight trainers are included in one 7-day Pro pass, with no per-trainer charge or automatic renewal.
Core OWASP pack
Security trainers
Each simulator is local, deterministic, and limited to inert allowlisted presets.
Injection investigation
FreeCompare normal and injected searches, choose the evidence of a tenant leak, and select a fix and retest.
Cross-site scripting investigation
ProTrace untrusted profile content into an HTML context, distinguish execution from reflection, and verify contextual encoding plus CSP defense in depth.
Authentication failure investigation
ProInvestigate account enumeration, brute-force controls, reset behavior, and session lifecycle using deterministic authentication evidence.
Authorization boundary investigation
ProTest object, role, and tenant boundaries through direct API access and prove that server-side policy remains authoritative.
Security misconfiguration investigation
ProReview deployment responses for unsafe defaults, verbose errors, CORS and header gaps, then define configuration evidence and regression gates.
File and export security investigation
ProInvestigate formula injection, unsafe filenames, type confusion, and sensitive export behavior without uploading executable content.
Server-side request forgery investigation
ProTest URL-fetch boundaries, redirects, address validation, and metadata protection through a deterministic fetch simulator.
Vulnerable component triage
ProTurn SBOM and advisory evidence into an exploitability decision, upgrade plan, and regression proof.
OWASP API abuse investigation
ProCompare bounded and unlimited exports, identify resource abuse, and choose quotas and retest coverage.