web_api challenge
Trusted Header — Case 4F3E
Ironwood Energy is investigating its maintenance console after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.
Incident briefing
Scenario
You have been brought in to help Ironwood Energy investigate its maintenance console after a controlled training incident exposed a realistic weakness in a synthetic environment. The environment is intentionally vulnerable and isolated for this exercise.
Objective
Use the assigned Kali workstation to identify and demonstrate the application weakness, then recover the synthetic audit flag.
Skills
What you will practice
- API authorization
- HTTP headers
- JSON
Tooling
Useful Kali tools
- Burp Suite
- curl
- jq
Ready to practice?
Launch an isolated target
Sign in to Locinode to receive a disposable lab environment and Kali workstation for this mission. Public pages never expose flags or intended solutions.
Enter range