Learn the testing process one decision at a time.
BountyLabs guided drills present a scenario, request or code excerpt, and simulated response. Identify the flaw, explain your reasoning, and receive immediate feedback at your own pace.
How Guided Drills Work
Each drill follows a structured flow designed to build a repeatable reasoning process, not just memorization.
Select a Drill
Browse by vulnerability type or difficulty. Every drill states the skill you will practise and its expected time.
Follow the Prompts
Read the scenario, examine the supplied request or source excerpt, and reason through a simulated application response.
Submit Your Reasoning
Choose or enter the relevant test, payload pattern, or finding. The validator compares it with the drill’s expected answer.
Get Validation
Receive immediate feedback on the decision you made. Incorrect attempts include targeted guidance so you can iterate.
Unlock Hints
Stuck? Use the graduated hint system. Each hint nudges you closer without giving away the full answer prematurely.
Read the Explanation
After solving the drill, a detailed write-up explains the root cause, testing logic, and recommended remediation.
Drill Categories
Core vulnerability classes with guided scenarios ranging from introductory to advanced.
Cross-Site Scripting (XSS)
Practise reflected, stored, and DOM-based XSS. Learn to identify injection points, bypass filters, and craft effective payloads in realistic application contexts.
SQL Injection
Explore in-band, blind, and out-of-band SQLi. Extract data, escalate privileges, and understand how parameterised queries prevent injection.
Server-Side Request Forgery (SSRF)
Force servers to make requests to internal services. Labs cover cloud metadata endpoints, protocol smuggling, and partial-response read techniques.
IDOR & Access Control
Discover insecure direct object references and broken access control logic. Change IDs, manipulate tokens, and bypass role checks in multi-tenant apps.
API Security
Attack REST and GraphQL endpoints. Labs include broken object-level authorisation, excessive data exposure, rate-limit bypass, and endpoint enumeration.
Authentication Bypass
Defeat login flows, MFA implementations, and session management. Labs simulate flawed password reset, JWT manipulation, and cookie tampering scenarios.
Cross-Site Request Forgery (CSRF)
Forge state-changing requests on behalf of authenticated users. Practise token prediction, SameSite cookie analysis, and Clickjacking-based CSRF.
Command Injection
Inject OS commands through vulnerable input fields. Labs cover blind injection, output exfiltration, and evasion of basic input filters.
5-Tier Hint System
Every guided drill includes a graduated hint ladder. Use only what you need—the less you rely on, the more XP you earn.
Tier 1 — Concept
A gentle reminder of the vulnerability class and the general area to focus on. No specifics about the lab itself.
Tier 2 — Direction
Points you toward the vulnerable parameter or endpoint. Narrows the attack surface without naming the exact technique.
Tier 3 — Technique
Names the specific technique or payload pattern that applies. You still need to adapt it to the lab’s context.
Tier 4 — Near-Solution
Provides a nearly complete payload or approach. One small adjustment remains for you to figure out.
Tier 5 — Full Explanation
Complete walkthrough of the exploit, root cause analysis, and remediation steps. Available after lab completion regardless of hints used.
Difficulty Levels
Drills are tagged by complexity so you can match practice to your current skill level.
Beginner
Single-step exploits with clear injection points. Ideal for your first encounter with a vulnerability type. Minimal filter bypassing required. Completes in 10–20 minutes.
Intermediate
Multi-step scenarios with basic protections in place. Requires chaining observations or bypassing simple filters. Familiarity with the vulnerability class is assumed. Completes in 20–45 minutes.
Advanced
Complex, realistic scenarios with multiple protections. Demands creative thinking, chaining techniques, and deep understanding of how the protocol or application logic works. Completes in 45–90 minutes.
Example Guided Drill
Here is what a typical drill looks like from start to finish.
Drill: Reflected XSS in a Search Parameter
Difficulty: Beginner · Category: XSS · Time: ~15 min
The drill presents a product-search request and a simulated response that reflects the query without encoding. Your task is to identify the injection context and choose an appropriate test string.
You compare the rendered response with its source excerpt, notice the value is inserted inside a double-quoted attribute, and explain how the attribute boundary changes the payload shape.
The validator checks the relevant structure in your answer. The write-up then explains the missing output encoding and how textContent or auto-escaping templates prevent the flaw.
Frequently Asked Questions
Do the drills run real vulnerable applications?
No. The current drills use supplied scenarios and simulated responses to teach testing decisions. They do not provision live targets or isolated vulnerable applications.
Do I need prior bug bounty experience to start?
No. Beginner drills assume zero prior experience and walk you through the fundamentals. Intermediate and advanced drills are available whenever you are ready.
How does the XP and scoring system work?
You earn XP for each drill solved. Using fewer hints can award more XP. Daily streaks and quiz performance also contribute to your progress.
Can I replay a drill after completing it?
Yes. You can replay any solved drill at any time. Replays do not award additional XP but are useful for recalling the testing process.
Ready to practise the process?
Try a three-minute IDOR drill before deciding whether to create an account. No setup required.
Try a Guided Drill