The XSS Rat Training Grounds

Own every lab. Master the methodology.

Training machines built by The XSS Rat — from basic enumeration to extreme multi-vector chains. Register once, unlock targets, submit flags, and track your progress on the leaderboard.

Active Challenges 40
Coming Soon 3
IP Visibility Locked Until Login
☠ The Burrow 3 reached it Can you?

⚡ New Series — Launching 31 May 2026

Project Meridian

5 new OSCP-prep machines inside SolarGate Energy's network. SUID abuse, cron hijacking, sudo escapes, and Linux capabilities — a full Linux privesc series.

View Project Meridian → 💡 Community suggestion by tumtum

Dropping in

--days
:
--hrs
:
--min
:
--sec

🛡 Purple Team Series — Launching 20 Jun 2026

Help me, I got compromised

Five connected hosts. One breach. Log forensics, SOC triage, code review, and a host under constant attack that you must defend — with a 30-minute auto-reset.

Dropping in

--days
:
--hrs
:
--min
:
--sec

Coming Soon

🕐 Upcoming Machines

See full schedule (5 total) →
🐀🐀 🕐 Launching soon

Blindspot

Blindspot is an internal URL validation tool. It checks whether endpoints are reachable — and it makes those requests from the server. There's an internal configuration service that wasn't supposed to be externally accessible.

In calculating...

🐀🐀 Premium 🕐 Launching soon

Foxhole

Foxhole's authentication system was written by a developer who read the documentation, just not all of it. The gate looks solid from the outside. The question is whether you understand how the lock actually works.

In calculating...

🐀🐀🐀 🕐 Launching soon

TokenSmith

TokenSmith is an internal OAuth 2.0 provider. It handles authorization flows and issues tokens to clients. There's a known issue in the tracker about redirect_uri validation — issue #214, filed months ago, still open.

In calculating...

Top Players

View full leaderboard

Want to go further?

All courses. All certs. All lives. One price — forever.

These labs are built around the same methodology taught in The XSS Rat's courses. If you want the full picture — recon, exploit chains, API hacking, business logic, CNWPP certification and everything in between — the Endless Bundle has 45+ courses, 3 cert paths, weekly live sessions, and every future release included. No subscriptions. No upsells.

10+Courses
3xCertifications
ALLLive lessons
80%Off right now