1. Secret Stash
There is a table nobody lists on the shop floor.
127.0.0.1 — don't put it online.
Quest board
Every flag is hidden behind a real vulnerability — no free reads. Exploit the app,
recover the VULNSHOP{...} token, and submit it here.
First player to all 10 takes the shelf.
Submit with curl:
curl -X POST http://127.0.0.1:5000/api/submit-flag -H "Content-Type: application/json" -d '{"player":"your-name","flag":"VULNSHOP{...}"}'
See the standings: /leaderboard · JSON: /api/leaderboard
There is a table nobody lists on the shop floor.
The download shelf keeps stock out of reach of the rack.
Someone archived a flag and left it on the web root.
Config files should never ship with the app.
The back office badge can be forged if the algorithm is not checked.
An XML parser that resolves external entities can read files.
One receipt has a secret note. Try ids nobody told you about.
Password resets use a 4-digit token derived from the email.
The debug endpoint spills everything, including one quest.
If you can run code, read the flag file in /app/files.