Mission Briefing
SUBMIT SECRET:
SQL Query Monitor
query.sqlHackLab Monitor
1
-- Waiting for input...
Query Result
No queries executed yet.
Terminal
hacklab@megacorp:~$
http://portal.megacorp.internal
Enter a URL path above and press Go.
◆ PIXELMART SECURITY REVIEW

5 Advanced Missions Await

MegaCorp just acquired PixelMart. Security review starts today. The dev team was rushed and the platform is riddled with flaws. Find every vulnerability before it goes live.

06Price Manipulation
07Directory Traversal
08Server-Side Request Forgery
09Mass Assignment
10Password Reset Poisoning
$0.99 one-time unlock · instant access
◆ OPERATION BLACKSITE UNLOCKED

Access Granted.

Five new vulnerabilities. One acquisition. Zero time to waste.

06Price Manipulation
07Directory Traversal
08Server-Side Request Forgery
09Mass Assignment
10Password Reset Poisoning
STAGE COMPLETE

HACKLAB COMPLETE

Mission Accomplished

You've identified all 5 vulnerabilities in the MegaCorp portal.

01
Information Leakage
OWASP A05 — Security Misconfiguration
02
Broken Access Control (IDOR)
OWASP A01 — Broken Access Control
03
Cross-Site Scripting (XSS)
OWASP A03 — Injection
04
SQL Injection
OWASP A03 — Injection
05
Command Injection
OWASP A03 — Injection