New Series

Blacksite Webapp

Five web applications running inside a classified internal portal. SQLi, command injection, broken file upload, SSTI, and XXE — the classic OWASP top-ten gauntlet, no CTF cheese required.

SQL Injection Command Injection File Upload Bypass SSTI XXE
5 Machines
Free No Paywall
OWASP Focus
5/5 Online Now

The Machines

Five apps. Five vulns. Every one a paycheck in the wild.

Attack Chain

Recommended order of attack.

Start Here
Machine 01
Blacksite DB
SQLi
Machine 02
Blacksite Tools
CMDi
Machine 03
Blacksite Media
Upload
Machine 04
Blacksite Reports
SSTI
Machine 05
Blacksite Import
XXE

Ready to exploit?

Five web vulns. Five real-world payloads. OSCP web module covered in one series.

Launching 27 June 2026 — web exploitation series covering the OWASP Top 10 attack categories.