Vuln Code Depot
Premium Machine (Locked)
🧩 PurpleTeam
🖧 AD Network — PurpleTeam
Internal host — not internet-facing. Reach it from your cirt-gateway shell or the in-browser Pwnbox at code-review-lab.default.svc.cluster.local with the analyst account. A compromised developer's Flask + Node repository. The attacker planted vulnerabilities and accidentally left credentials in the git history. Find the vulns with static analysis tools, then dig through git log to uncover what was deleted.