Learn
Login
ChallengesLearn
Scoreboard
Teams
Profile

Preferences

Truesapiens

Learn

Learning library

All courses

Multi-lesson tracks organised by vulnerability class. Every lesson includes a live simulation you can break, fix, and learn from.

6 courses · 71 lessons
SQL Injection

A 20-lesson hands-on course on the most prevalent web vulnerability. Each lesson includes a live, interactive sandbox and a step-by-step diagram you can break.

20 lessons
fund1SQL Injection: FundamentalsBeginner12mfund2SQL Injection: How databases workBeginner10mfund3SQL Injection: Why it's possibleBeginner10mfund4SQL Injection: Authentication bypassIntermediate16mcore5SQL Injection: Comment injectionBeginner8mcore6SQL Injection: UNION-based extractionIntermediate18mcore7SQL Injection: Error-based extractionIntermediate14mcore8SQL Injection: Blind injection overviewIntermediate12mdeep9SQL Injection: Boolean-based blindIntermediate14mdeep10SQL Injection: Time-based blindAdvanced16mdeep11SQL Injection: Database enumerationIntermediate16mdeep12SQL Injection: Extracting dataIntermediate18mdef13SQL Injection: Finding it in the wildAdvanced18mdef14SQL Injection: Secure coding practicesBeginner12mdef15SQL Injection: Prepared statementsIntermediate14mdef16SQL Injection: ORM securityIntermediate13mdef17SQL Injection: WAF & detectionAdvanced20mcaps18SQL Injection: Real-world case studiesIntermediate22mcaps19SQL Injection: Modern challengesAdvanced18mcaps20SQL Injection: Review & practiceIntermediate25m
Cross Site Scripting

From reflected alert() to full account takeover. Understand how unescaped user input turns the browser into an execution host.

12 lessons
fund1XSS: The Browser is the DatabaseBeginner12mfund2Reflected XSSBeginner10mfund3Stored XSSBeginner10mcore4DOM-based XSSIntermediate12mdef5XSS DefenseIntermediate14mcore6XSS Payload TechniquesIntermediate14mcore7Blind XSSAdvanced14mdeep8Context-Based XSS EscapesAdvanced15mdeep9CSP Bypass TechniquesAdvanced16mdef10XSS Detection & AuditingAdvanced14mcaps11XSS Case StudiesIntermediate18mcaps12XSS Review & PracticeIntermediate22m
Access Control

When the server trusts the client to say who they are. IDOR, privilege escalation, path traversal — the missing check that leaks everything.

12 lessons
fund1IDOR: The Missing CheckBeginner10mfund2Path TraversalBeginner10mfund3Privilege EscalationIntermediate12mcore4Mass AssignmentIntermediate10mdef5Access Control HardeningIntermediate14mfund6API Access ControlIntermediate12mcore7JWT AttacksIntermediate14mcore8CSRFIntermediate13mdeep9Rate Limit & Auth BypassAdvanced14mdef10Session ManagementIntermediate14mcaps11Access Control Case StudiesIntermediate18mcaps12Access Control Review & PracticeIntermediate22m
Ssrf

From a single URL parameter to the entire cloud metadata service. Understand how server-side request forgery turns the server into a proxy for internal attacks.

8 lessons
fund1SSRF: The Server Makes the RequestBeginner12mfund2Finding SSRF in the WildBeginner10mcore3Cloud Metadata AttacksIntermediate14mcore4Internal Network PivotIntermediate14mcore5Blind SSRFAdvanced14mdeep6SSRF Bypass TechniquesAdvanced16mdef7SSRF DefenseIntermediate14mcaps8SSRF Review & PracticeIntermediate22m
API Security

REST, GraphQL, and the flaws that live in the contract itself. Broken object auth, excessive data exposure, mass assignment — the OWASP API Security Top 10 in practice.

11 lessons
fund1API Security OverviewBeginner12mfund2API ReconnaissanceBeginner12mcore3Broken Object Level AuthorizationIntermediate14mcore4Broken AuthenticationIntermediate14mcore5Excessive Data ExposureIntermediate12mdeep6API Mass AssignmentAdvanced12mdeep7API Rate Limiting & AbuseAdvanced14mdef8API Automated Security TestingIntermediate14mdef9API Security HardeningIntermediate14mcaps10API Security Review & PracticeIntermediate22mdeep11GraphQL Security Deep DiveAdvanced16m
WEB Protocols

HTTP/1.1 to HTTP/3, DNS, TLS, CDN, CORS, WebSockets — the plumbing that powers every web application. Understand how the web actually works under the hood.

8 lessons
fund1HTTP/1.1 FundamentalsBeginner14mfund2HTTP/2 & HTTP/3Beginner14mcore3DNS Deep DiveBeginner14mcore4TLS & SSLIntermediate16mdeep5CDN & CachingBeginner14mdeep6CORS & Same-Origin PolicyIntermediate14mdef7WebSockets & Real-TimeIntermediate14mcaps8Web Protocols ReviewBeginner20m

© 2026 Truesapiens.

Terms of ServicePrivacy PolicyCookie Policy