ProofRange
SaaS-style financial ops app: stateful IDOR, blind SSRF, prototype pollution → RCE, JWT attacks, cache poisoning, and business-logic races. Built to stress scanners that only do unauthenticated crawl.
Open lab →Deliberately vulnerable applications for manual pentesting and benchmarking autonomous security tools. Each ring adds difficulty — from API logic to blind OOB chains.
⚠ Labs include real RCE and SSRF. Use isolated environments only. Never point scanners at systems you do not own.
SaaS-style financial ops app: stateful IDOR, blind SSRF, prototype pollution → RCE, JWT attacks, cache poisoning, and business-logic races. Built to stress scanners that only do unauthenticated crawl.
Open lab →
10 vulns on agent-style surfaces: GraphQL introspection, alias IDOR, mutation chains,
MCP http_fetch SSRF,
scope HPP, and double-refund logic. Run locally from ring2/; prod deploy pending.
Manual pentest — no scanner required. Log in to ProofRange, follow the guide, track your score.
Builders: GitHub · VULNGYM.md · Scanner benchmark (optional)