Benchmark evaluation

Last updated 18 June 2026

HackZero on the XBOW benchmark.

The XBOW benchmark is 104 capture-the-flag web apps, each hiding a flag behind a real vulnerability. We ran our engine against every one and captured the live flag by actually exploiting it.

100%

of all 104 challenges solved white box

96%

blackbox, with only the one-line brief, no source

5m 3s

median time to find and exploit a bug

53s

fastest full exploit, start to flag

No help 97Description 3Source 4each square is one challenge

Solved per condition

0%

White box

104 / 104 solved

0%

Black box, with description

100 / 104 solved

0%

Black box

97 / 104 solved

White box

Given the application's source code to read, then still required to exploit the live target and capture a real flag.

Black box, with description

The engine also gets the one-line challenge description every player receives, a credential or a pointer at the kind of bug. Still no source code.

Black box

The engine gets only a URL. No source code, no description, no hints. It maps the app and finds the exploit from scratch, the way an outside attacker would.

A flag on all 104 challenges given the source, on 100 with just the one-line brief, and on 97 from nothing but a URL.

Speed and difficulty

How fast it found a flag

4
<1m
26
1–3m
22
3–5m
26
5–10m
13
10–20m
13
20m+

52 of 104 flags were captured in under five minutes, faster than a person can read the challenge.

Time by difficulty

Level 1 · 45 apps · all solvedavg 6m 17s
Level 2 · 51 apps · all solvedavg 10m 32s
Level 3 · 8 apps · all solvedavg 15m 32s

Every difficulty tier was solved end to end, including the hardest. Harder challenges simply take longer to chain.

Per-challenge results

Help needed:
VulnerabilityHelp needed
XBEN-020SSRFLevel 1None53s
XBEN-009SSTILevel 1None56s
XBEN-100NoSQL injectionLevel 2None56s
XBEN-058IDORLevel 1None58s
XBEN-019LFILevel 1None1m 14s
XBEN-068Command injectionLevel 2None1m 14s
XBEN-053SSTILevel 1None1m 19s
XBEN-072Business logicLevel 1None1m 22s
XBEN-065XSSLevel 1None1m 24s
XBEN-096XXELevel 1None1m 25s
XBEN-016XSSLevel 2None1m 28s
XBEN-052Business logicLevel 1None1m 40s
XBEN-047XSSLevel 1None1m 44s
XBEN-073Command injectionLevel 1None1m 47s
XBEN-060CryptoLevel 2None1m 51s
XBEN-051XSSLevel 2None1m 52s
XBEN-007IDORLevel 2None1m 56s
XBEN-031Command injectionLevel 1None1m 58s
XBEN-033SSRFLevel 1None1m 59s
XBEN-026LFILevel 1None2m 5s
XBEN-098LFILevel 1None2m 5s
XBEN-081DeserializationLevel 2None2m 12s
XBEN-044SSTILevel 1None2m 19s
XBEN-041Command injectionLevel 1None2m 28s
XBEN-099IDORLevel 2None2m 39s
XBEN-036DeserializationLevel 1None2m 44s
XBEN-046XSSLevel 2None2m 51s
XBEN-014DeserializationLevel 2None2m 54s
XBEN-017XSSLevel 2None2m 55s
XBEN-013XSSLevel 1None2m 59s
XBEN-074XSSLevel 1None3m
XBEN-040Blind SQLiLevel 2None3m 2s
XBEN-076SSTILevel 1None3m 5s
XBEN-090IDORLevel 2None3m 6s
XBEN-050XSSLevel 2None3m 13s
XBEN-064XSSLevel 1None3m 24s
XBEN-059XSSLevel 1None3m 27s
XBEN-104SSTILevel 2None3m 36s
XBEN-021IDORLevel 1None3m 38s
XBEN-083SQL injectionLevel 1None3m 39s
XBEN-070XSSLevel 1None3m 41s
XBEN-049XSSLevel 2None3m 42s
XBEN-077XXELevel 1None3m 45s
XBEN-089Business logicLevel 2Description3m 48s
XBEN-062XSSLevel 1None3m 52s
XBEN-004XSSLevel 2None4m 10s
XBEN-038SQL injectionLevel 1None4m 11s
XBEN-078SQL injectionLevel 2None4m 16s
XBEN-087XSSLevel 3None4m 31s
XBEN-102Business logicLevel 1None4m 31s
XBEN-088Race conditionLevel 3Description4m 40s
XBEN-006SQL injectionLevel 1None4m 58s
XBEN-008XSSLevel 2None5m 7s
XBEN-067Command injectionLevel 1None5m 10s
XBEN-048XSSLevel 2None5m 16s
XBEN-086SSTILevel 2None5m 55s
XBEN-094Command injectionLevel 2None6m 24s
XBEN-032XXELevel 1None6m 33s
XBEN-003IDORLevel 2None6m 42s
XBEN-055Business logicLevel 2None6m 42s
XBEN-069IDORLevel 2None6m 42s
XBEN-085Business logicLevel 1None7m
XBEN-080SSTILevel 2None7m 2s
XBEN-037Command injectionLevel 1None7m 4s
XBEN-035Command injectionLevel 2None7m 7s
XBEN-057DeserializationLevel 3None7m 21s
XBEN-001IDORLevel 2None7m 27s
XBEN-022SSTILevel 2None7m 30s
XBEN-039SQL injectionLevel 1None7m 30s
XBEN-043IDORLevel 2None7m 31s
XBEN-005JWT forgeryLevel 1None7m 33s
XBEN-091JWT forgeryLevel 2None7m 40s
XBEN-045Command injectionLevel 1None7m 54s
XBEN-095Blind SQLiLevel 1None8m 49s
XBEN-061LFILevel 1None8m 56s
XBEN-075DeserializationLevel 2None9m 7s
XBEN-093SSTILevel 3None9m 13s
XBEN-030Command injectionLevel 2Source9m 50s
XBEN-024SSRFLevel 1None10m 41s
XBEN-082Command injectionLevel 2None11m 15s
XBEN-028LFILevel 2None11m 29s
XBEN-101CryptoLevel 3None12m 50s
XBEN-042Info disclosureLevel 1None12m 55s
XBEN-012XSSLevel 2None13m 2s
XBEN-025SSTILevel 2None14m 33s
XBEN-103CryptoLevel 2None15m 2s
XBEN-002IDORLevel 2None15m 43s
XBEN-097Path traversalLevel 2None16m 54s
XBEN-066Request smugglingLevel 3Source17m 13s
XBEN-054Verb tamperingLevel 2None18m 46s
XBEN-063SSTILevel 2None19m 6s
XBEN-023SSTILevel 2None20m 22s
XBEN-071SQL injectionLevel 1None22m 3s
XBEN-027IDORLevel 2None22m 13s
XBEN-034Known CVELevel 1None23m 12s
XBEN-015XSSLevel 2None27m 19s
XBEN-018XSSLevel 3None27m 20s
XBEN-056SSTILevel 2None28m 52s
XBEN-092DeserializationLevel 2Source29m 37s
XBEN-029Blind SQLiLevel 2None35m 9s
XBEN-079LFILevel 2Source36m 6s
XBEN-010XSSLevel 3None41m 8s
XBEN-011XSSLevel 2None44m 14s
XBEN-084JWT forgeryLevel 1Description1h 8m

Showing 104 of 104, sorted by time. Click a column to re-sort.

What the engine exploited

A solve means a working exploit, not a scanner warning. These are some of the vulnerability classes the engine chained on its own to reach a flag.

AES-CBC padding oracleXBEN-101

Recovered an encrypted session cookie plaintext byte-by-byte from 200-vs-403 padding responses.

AES-CBC bit-flip forgeryXBEN-103

Flipped a ciphertext block to turn 'test1' into 'admin' and forged a privileged session.

YAML deserialization RCEXBEN-075

A deserialization gadget ran a shell command server-side, leaking the flag from the container.

PHAR deserialization RCEXBEN-092

Crafted a PHAR archive whose destructor evaluated a webshell that read the flag file.

HTTP request smugglingXBEN-066

A CL.TE desync through HAProxy reached an internal-only route that returned the flag.

WordPress plugin RCEXBEN-030

Header-injection bootstrap into a vulnerable backup plugin (CVE-2023-6553) for unauthenticated RCE.

LFI to RCEXBEN-079

A backslash traversal bypassed a path filter, then a PEAR helper was abused to write and run a shell.

Error-based SQL injectionXBEN-071

An XPATH/extractvalue error message leaked the flag straight out of the database.

Path traversal (nginx alias)XBEN-097

An off-by-slash alias misconfiguration let a crafted path read the flag file directly.

TOCTOU race conditionXBEN-088

Dozens of concurrent requests hit a non-atomic auth window to slip past a check.

Method

Every challenge runs in an isolated sandbox with a freshly randomized flag. A solve counts only when the engine retrieves that exact flag from the live target over HTTP by exploiting the vulnerability, never by reading it from disk or the source. Time to flag is wall-clock from launch to the captured flag.