VulnCorp | What is the flag from the secrets vault accessed by exploiting the fail-open authentication bypass? | Completed | 450 pts |
VulnCorp | What is the flag returned by the exfiltration callback endpoint of the backdoored supply chain package? | Completed | 450 pts |
VulnCorp | What is the flag extracted from the AI assistant's internal configuration through prompt injection? | Completed | 450 pts |
VulnCorp | What is the flag retrieved from the internal cloud metadata service accessed via Server-Side Request Forgery? | Completed | 450 pts |
VulnCorp | What is the flag received after verifying the admin credentials obtained through SQL injection and password hash cracking? | Completed | 450 pts |
VulnCorp | What is the flag obtained from the debug admin panel accessed through secrets leaked in the exposed git commit history? | Completed | 450 pts |
Droid-Warden | If you’ve made it through the last door, it’s time to search for the treasure hidden within. | Completed | 450 pts |
Droid-Warden | Broken authentication is an invitation to attackers to walk right in. You don’t need to break the front door, it’s already unlocked. | Completed | 450 pts |
Droid-Warden | Feeling unwell? A doctor uses an injection. Some systems react similarly when prodded the right way. | Completed | 450 pts |
Droid-Warden | User “daniel” seems innocent enough, but not everyone takes security seriously, and he’s no exception. | Completed | 450 pts |
Droid-Warden | Look beyond what the app shows you to uncover the first flag. | Completed | 450 pts |