Cyfotok Labs · Isolated range

vuln.cyfotok.com

Semi-untrusted vulnerable simulators, sandboxed from production. Access is only via short-lived RS256 tokens issued by labs.cyfotok.com.

Trust boundary

  • No shared cookies with labs
  • Service role never exposed to the browser
  • Supabase used only for revocation + audit
  • Vulnerable code lives under /labs and fake APIs
quickstart

# Issue token on labs, then:

/lab/xss-basic?token=<jwt>

# Starter labs

xss-basic · sql-injection · auth-bypass