CVE-2025-6554
Learn, practice, and defend — ethically.
This repository contains course materials and labs for the Web Security module . Use only in controlled, legal environments (VMs, lab networks) and follow the Responsible Disclosure & Code of Conduct below.
This repo supports an offensive-security training track that teaches web vulnerability analysis, exploitation fundamentals, and defensive detection using a real-world case-study approach. Emphasis is on ethical learning, reproducible lab setups, and actionable mitigation/detection techniques.
By completing this module you will be able to:
This course uses a browser engine vulnerability as a teaching case. Materials focus on investigation, crash triage, and defensive countermeasures. No weaponized exploit code is included. All exercises are designed to be non-destructive and contained within lab VMs.
Each lab MUST be run on isolated, snapshot-based VM environments. Example labs:
Do not run exploits or PoCs that attempt remote code execution on production or third-party systems.
Snapshot before each exercise.
Contributions welcome (labs, defensive rules, detection content, documentation). Rules:
*Prepared by: Nihal MP