Back to Mission Brief
Public Launch
Tier 02
Intermediate
Lv.3

Mission launch sequence armed

Public operators can step into the live sandbox immediately. The start route now frames the run as a checkpoint mission with visible reward pressure and the next unlock already in view.

Mission HUD

Fingerprint the target

Checkpoint Progress
0 / 4
Reward Bar67% primed

Start with one clean request and read what the application leaks without forcing the issue yet.

XP Cache

+300 XP

Mission Window

~60 min

Final Proof

Captured findings, exploit screenshots, and a vuln-to-fix mapping.

What You Earn

Completion Badge

Exploit Chain Runner

Clearance Upgrade

Application Strike Clearance

Next Unlock

Active Directory Attack Paths

Objective Count

4 checkpoints

Unlock Requirement

Recommended after securing Linux escalation basics.

Live Mission Workspace
Browser sandbox is live
Booting
Public
Mission booting

One move is live at a time. Stage the current command, read the result, and earn the next unlock.

Active Stage
Stage 1/4
XP Banked

0/300 XP

Chain Streak

No chain yet

Mission Level

Lv.3 • Stage 1/4

Reward Meter

25% charged

0 min in session
http://10.10.26.12
Booting
mission-console@kyveraowasp-top10
[bootstrap] OWASP Top 10 - Web Exploitation session requested
[objective] Validate a real injection point, prove impact, and collect the remediation-ready artifact.
[connect] curl -I http://10.10.26.12
Toolkit Drop • Stage 1
Fingerprint the target

Only one move is armed. Stage it, read the output, then verify the exact clue you extracted.

Next Unlock
Surface mapped
+75 XP
Intel Packet

Start with one clean request and read what the application leaks without forcing the issue yet.

Reward Drop
Surface mapped
Lv.3
Toolkit Command
curl -s http://10.10.26.12/products?id=3
Field Notes

Notes persist in this browser immediately. Save the mission later if you want the protected member handoff.

Mission HUD
Validate a real injection point, prove impact, and collect the remediation-ready artifact.
Checkpoint Chain
0/4

No chain yet

Reward Charge
Artifact unlock25%
First Reward

Clear the first checkpoint to unlock your first debrief badge, XP drop, and the next sealed stage.

Fingerprint the target
Live
Surface mapped

Start with one clean request and read what the application leaks without forcing the issue yet.

Start with the public product endpoint to confirm the app surface.

curl -s http://10.10.26.12/products?id=3
Exploit the SQL injection
Locked
Database breach confirmed

Future stage stays sealed until the current checkpoint is verified.

Validate the broken object access
Locked
Privilege leak found

Future stage stays sealed until the current checkpoint is verified.

Capture the impact summary
Locked
Report stub unlocked

Future stage stays sealed until the current checkpoint is verified.

Toolkit + Intel
What You Earn
Badge
Exploit Chain Runner
Clearance
Application Strike Clearance
Proof Artifact
findings.md
Completion Unlock
Captured findings, exploit screenshots, and a vuln-to-fix mapping.
Target
Deliberately vulnerable web stack
Connection
curl -I http://10.10.26.12
Access
Web app seeded with OWASP Top 10 flaws
Success Artifact
findings.md
Current Objective
Fingerprint the target

Start with one clean request and read what the application leaks without forcing the issue yet.

Streak Continuity
Sign in after the run if you want checkpoint history and future streak preservation.
Continue in Member App

Sign in only if you want to continue inside the protected workspace after this public sandbox run.

Launch Sequence
1

Stage one checkpoint at a time instead of dumping the whole walkthrough at once.

2

Read the terminal output closely. Each checkpoint stays sealed until the verification signal matches.

3

Clear this mission to unlock the next queue tile: Active Directory Attack Paths.

Session Access

This public start flow lands in the same live mission workspace a member uses after auth. Authentication only gates saved notes, streak continuity, and the protected handoff inside /app/labs/owasp-top10.

Member Extras

Sign in when you want recruiter-facing proof, checkpoint history, saved streaks, and the protected next-mission queue.

Queue Active Directory Attack Paths