Lab Icon

Button Activator

πŸ”˜ Can you activate what was meant to stay disabled?

Challenge Updated Sep 10, 2026 Solution (Pro)
JavaScript Browser DevTools DOM Manipulation Client-Side Security

This web application has a mysterious button that holds the key to success, but there's just one problem - it's completely deactivated! 🚫 The developers thought they were clever by disabling it, but client-side restrictions are rarely as secure as they appear. πŸ’‘ Put your browser manipulation skills to the test and discover how to breathe life back into this dormant button! πŸ”“

1
Flags
50
XP
81%
Success Rate

Client-side security controls in web applications are among the first things security testers learn to bypass. When developers use JavaScript to disable buttons, hide form fields, or restrict user interactions, they create a false sense of security. These controls exist only in the browser and can be trivially overridden using built-in developer tools. Understanding client-side manipulation is a foundational web security skill.

Understanding the DOM and Client-Side Controls

The Document Object Model (DOM) is the browser's internal representation of a web page. Every HTML element - including buttons, forms, and input fields - exists as an object in the DOM that can be inspected and modified in real time. When a developer sets a button's disabled attribute or uses CSS to hide an element, these restrictions only exist in the DOM and can be removed or changed by anyone with access to browser developer tools.

Common Client-Side Restrictions and Bypasses

Web applications frequently implement client-side controls such as disabled form fields, hidden elements, JavaScript validation, read-only inputs, and maximum length restrictions. Each of these can be bypassed using the browser's developer console. For example, removing a disabled attribute is as simple as selecting the element in the Elements panel and deleting the attribute, or running a single JavaScript command in the console. Security professionals routinely test these controls during web application assessments to verify that server-side validation properly enforces all restrictions.

Why Server-Side Validation is Essential

The fundamental rule of web security is that anything happening in the browser can be manipulated by the user. Client-side controls should only be used for user experience - providing visual feedback, preventing accidental submissions, or improving form usability. All security-critical validation must happen on the server, where the user cannot modify the code. Applications that rely solely on client-side controls for security are vulnerable to trivial bypass attacks that require no specialized tools.

What You Will Learn

  • How the browser DOM represents web page elements
  • Using browser developer tools to modify HTML attributes and CSS
  • Common client-side restrictions and how to bypass them
  • JavaScript console techniques for DOM manipulation
  • Why server-side validation is essential for web application security

Prerequisites

Basic HTML and JavaScript Web browser with developer tools No programming experience required
~1-2 min setup
Dedicated server
Private instance
Standard power
30 min per session. Restart it for free, as often as you like.
New here? Here's what to do
1
Create a free account, then click "Start Lab" You'll get your own private machine with an IP address
2
Explore the target Open the IP in your browser and look for vulnerabilities
3
Find and submit flags Flags are secret text strings hidden in the system - paste them below to score