Browser Emulator
Built-in iframe sandbox for direct interaction with the challenge application
Browser-based web exploitation challenge platform powered by WASM — no backend required, ready to run instantly


WXL (Web Exploitation Laboratory) is a fully front-end Web security challenge platform powered by WebAssembly. Every challenge backend — Flask, FastAPI, PHP — runs entirely inside the browser, so realistic pentest practice needs zero server. A built-in HTTP Repeater, Python Code Editor, and Network Traffic Log together provide a complete attack toolchain.
A black-box engagement against Badgeline, the access request system at a research institute, where a door code is meant to reach nobody who has not been endorsed and cleared.
A black-box engagement against Stubhouse, a ticketing platform whose promotional codes are good for one use per customer and whose bookings are settled off-site.
A black-box engagement against Keyrack, a software licence reseller whose accounts can only ever spend the allowance Keyrack issued them.
Open the challenges page and pick one by difficulty or category.
Use the tools the challenge offers — Browser, Code Editor, Network Traffic Log, and Repeater — to analyse and exploit the vulnerability.
Once you find the flag, paste it into the submit box on the challenge page to confirm your answer.