Turnstile
π§© Student Engagements
π ENGAGEMENT SCOPE OF WORK β CONFIDENTIAL You have been engaged by Turnstile Ticketing Systems Ltd. to perform an authorized penetration test of their customer web portal. This is your scope. Treat it as a real client engagement. β’ CLIENT: Turnstile Ticketing Systems Ltd. β’ ENGAGEMENT: Authorized black-box web-application penetration test. β’ IN SCOPE: The Turnstile customer portal at the target address above (30801/HTTP) β all application endpoints, authentication, session handling, and business logic. β’ OUT OF SCOPE: Denial-of-service, brute-force lockout of live users, network/infrastructure attacks, social engineering, physical access, and ANY host other than the in-scope target. Do not attack the hosting platform. β’ RULES OF ENGAGEMENT: The testing window is open 24/7 for the duration of the engagement. Do not destroy or exfiltrate real data beyond what is needed to prove impact. Record the exact request for every finding. Immediately flag any critical issue (RCE, full account takeover, mass data exposure) in your report. β’ OBJECTIVES: Enumerate the application, identify and safely exploit vulnerabilities, and assess the real business impact to Turnstile. β’ DELIVERABLES: (1) a PTES-aligned test PLAN before you begin, (2) a full professional REPORT, and (3) a short DEBRIEF video walking your methodology and top findings. All three are graded. AUTHORIZATION: You are hereby authorized to test the in-scope asset listed above for the duration of this engagement. Sign in, review the scope, and begin. Good luck.