Avatar

Labs / Redis Cache Poisoner

  • Daily Challenge
  • Released 04 Sep 2025

💉 Can you inject Redis commands through their note caching system?

A note caching API constructs Redis commands using string concatenation, creating opportunities for CRLF injection attacks. When user input meets insufficient sanitization, even simple note storage can become a pathway to Redis command injection and session manipulation. 🎯 Time to test your protocol injection skills!

1
Flags
1
Points
Daily Challenge
Free Access
Start Lab Environment

Launch your dedicated AWS machine to begin hacking

~1-2 min setup
AWS dedicated
Private instance
Industry standard
No Community Writeups Yet

Be the first to share your writeup for this lab!