瀏覽器模擬器
內建 iframe sandbox,直接與挑戰應用程式互動
WXL (Web Exploitation Laboratory) is a fully front-end Web security challenge platform powered by WebAssembly. Every challenge backend — Flask, FastAPI, PHP — runs entirely inside the browser, so realistic pentest practice needs zero server. Built-in HTTP Repeater, Python Code Editor, and a terminal emulator together provide a complete attack toolchain.
Open the challenges page and pick one by difficulty or category.
Use the built-in Browser, Terminal, Code Editor, and Repeater to analyse and exploit the vulnerability.
Once you find the flag, paste it into the submit box on the challenge page to confirm your answer.