🐀🐀 0 pts earned

Vuln Code Depot

🧩 PurpleTeam

🖧 AD Network — PurpleTeam

CIRT Gateway 🔒 SIEM Station SOC Runbook Vuln Code Depot 🔒 Under Fire

Internal host — not internet-facing. Reach it from your cirt-gateway shell or the in-browser Pwnbox at code-review-lab.default.svc.cluster.local with the analyst account. A compromised developer's Flask + Node repository. The attacker planted vulnerabilities and accidentally left credentials in the git history. Find the vulns with static analysis tools, then dig through git log to uncover what was deleted.

🩸 First user blood: davidkarpinski1 🩸 First root blood: davidkarpinski1
Internal machine — reachable only by pivoting from the entry host. It is not directly scannable from the internet, so external scans return filtered. This is by design, not an outage.
Target IP Log in to reveal
User Flag Pending
Root Flag Pending

Community

Community Hints

Grade A · 1000 pts Grade B · 700 pts Grade C · 400 pts Grade D · 200 pts + 150 credits on accept

Short, stage-specific nudges — directional, spoiler-light, no exact commands.

Privilege Escalation

Development artifacts can elevate access suraj_pun_magar · B · 1 Jul 2026

Community

Community Walkthroughs

Grade A · 2500 pts Grade B · 1750 pts Grade C · 1000 pts Grade D · 500 pts + 300 credits on accept

🔒 Community walkthroughs are spoilers — capture the root flag on this machine to unlock them.