The guided, module-by-module learning path.
A module lab is a small but realistic app that hides an entire CWAP bug class inside believable features — nothing is labelled “vulnerable”. You open it, read the short goal hint on each page, and hunt every finding. There are no flags; a built-in /progress page tallies what you’ve found (e.g. “7 / 13 found”).
Recommended flow per topic: 1) do the module lab here to learn the class → 2) drill it in the matching Practice Pack → 3) prove it on an Exam Simulation.
Route everything through Burp so nothing you touch is lost, and keep a running attack map (endpoints, params, roles) as you go — that map is what every later module builds on.
More hands-on practice → HackXpert Labs ↗