The Labs
Every lab is a fully realized fictional company. Multiple services, real defenses, real exploit chains. Pick your difficulty.
Settle
Settle processes card payments for small shops. After a suspicious export and an admin action nobody owns up to, the team wants to know how far an outsider could get starting from a plain merchant signup, across the merchant site, the admin console, and the reporting database. Begin as a merchant and see how much of the stack you can take apart without ever being handed a credential.
Inkline
Inkline handles signed agreements for enterprises. An engineer doing a security pass flagged that an admin account had its password changed overnight, with no record of a reset email ever being sent, and a template pack imported right afterward that nobody recognises. Start from a normal account and work out how an outsider could take over the admin and turn a template import into code execution on the server.
Deskwell
Deskwell is the internal helpdesk a few teams share. During an incident review, an admin export job was seen running a command nobody added, right after some oddly named files showed up as ticket attachments. Come in as an outsider at the agent sign-in and work out how to become an admin without a password, then how an attachment could end up running on the server.
Proforma
Proforma keeps freelancers' invoicing tidy: fill in the client details, preview the invoice, and hit Download PDF to send it off. The web preview is careful about what it shows, so the obvious tricks in the bill-to field go nowhere. Come at Proforma as a user building an invoice, and pay attention to the difference between what you see in the browser and what comes out of the PDF.
Nodewell
Nodewell runs the homelab: a tidy dashboard over everything you self-host, plus a "reach my endpoint" check for when a service looks down. The person who built it was careful about the check, and stripped out the shell characters people use to break out of commands. Come at Nodewell from the dashboard, look closely at that reachability check, and work out what it will still let you do even with the dangerous characters gone.
EastVale
EastVale runs recreational soccer across the valley. Team managers upload a club crest and print a roster sheet for match day. A parent noticed their team's printed roster came out with a line of text on the crest that nobody had typed into the site. Look at EastVale the way a team manager would, starting from the crest upload, and work out how something the site was never given could end up printed on the roster.
TwinTone
TwinTone Books keeps the accounts for a small studio. During a review, a guest login that is only supposed to see the overview dashboard was found reaching parts of the app it was never granted, and touching records it should not have been able to see. You have the same guest login. Sign in as guest and work out how far that account can really get inside TwinTone Books.
Barked
Barked is a much loved little corner of the internet where people share pictures of their dogs. While tidying up the server the maintainer noticed a file sitting in the web root that nobody put there through the site, and cannot work out how it arrived. Look at Barked the way an outsider would, starting from the public gallery, and work out how a file could end up on the server that the site never meant to accept.
United
Ashgrove University runs its campus services behind one staff sign-on called United. During a records audit the Office of the Registrar noticed something odd, a recent graduate had signed into the registrar account even though nobody had issued them a reset or shared the password. You have been asked to look at the staff sign-in the way an outsider would, starting from the login page with no credentials, and work out how the registrar account could be reached.