web_api challenge
Crossed Accounts — Case 67AF
Harborline Logistics is investigating its dispatch console after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.
Incident briefing
Scenario
You have been brought in to help Harborline Logistics investigate its dispatch console after a controlled training incident exposed a realistic weakness in a synthetic environment. The environment is intentionally vulnerable and isolated for this exercise.
Objective
Use the assigned Kali workstation to identify and demonstrate the application weakness, then recover the synthetic audit flag.
Skills
What you will practice
- authorization
- HTTP
- IDOR
Tooling
Useful Kali tools
- Burp Suite
- curl
Ready to practice?
Launch an isolated target
Sign in to Locinode to receive a disposable lab environment and Kali workstation for this mission. Public pages never expose flags or intended solutions.
Enter range