The Labs
Every lab is a fully realized fictional company. Multiple services, real defenses, real exploit chains. Pick your difficulty.
TwinTone
TwinTone Books keeps the accounts for a small studio. During a review, a guest login that is only supposed to see the overview dashboard was found reaching parts of the app it was never granted, and touching records it should not have been able to see. You have the same guest login. Sign in as guest and work out how far that account can really get inside TwinTone Books.
Barked
Barked is a much loved little corner of the internet where people share pictures of their dogs. While tidying up the server the maintainer noticed a file sitting in the web root that nobody put there through the site, and cannot work out how it arrived. Look at Barked the way an outsider would, starting from the public gallery, and work out how a file could end up on the server that the site never meant to accept.
United
Ashgrove University runs its campus services behind one staff sign-on called United. During a records audit the Office of the Registrar noticed something odd, a recent graduate had signed into the registrar account even though nobody had issued them a reset or shared the password. You have been asked to look at the staff sign-in the way an outsider would, starting from the login page with no credentials, and work out how the registrar account could be reached.
Granard
Granard began as one developer's side project and quietly grew into a real product, with real customers and a small ops team that reads every piece of feedback that comes in. You have a normal account, the same as everyone else. The staff who triage the board carry a key to the whole workspace. Take what they are holding.
VexVary
VexVary seals every completed agreement with its verification mark, and the team is quietly proud of it. Last week the master signing key behind that seal surfaced somewhere no customer should be able to reach. Start as an ordinary customer and find the way in.
Remit
Remit runs accounts payable for a few dozen companies out of Columbus. Suppliers send invoices in, a finance team approves them in a separate review console, and payments go out. Last month an outsider rewrote a supplier's bank details on a live invoice and the payment went to the wrong account, and none of the staff with console logins can explain how anyone else got in. You have a plain supplier account. Find the path to the console.
Halcyon FM
Halcyon FM is a small listener-supported community station up in Asheville. Marlow and a rotating crew of volunteers run the whole thing off a couple of machines in the back of the studio. The public site carries the schedule and takes show pitches. The playout console the crew use to run automation lives on its own subdomain. Last week an unaired pledge-drive script and the station's underwriter contact list turned up, word for word, on a rival station's blog. Nobody on the crew can explain how anyone reached the console. Start on the public site as an anonymous listener and find the way through to whatever is running the back office.
NorthKorea
You are a foreign operative working a low-privilege scout account on the KPA Strategic Command portal (issued credentials: admin / admin). Every field report you file is reviewed in person by Marshal Kim, and his endorsement carries an AUTHORIZATION_CODE that never leaves his screen. You cannot read it directly. Recover that code.
JurryHurry
JurryHurry is a long-established firm that handles everything from real estate closings to commercial litigation. Enquiries come in through the contact form on the public site, and a clerk works the queue from a staff portal each morning. The managing partner wants a quiet look at that portal before a compliance review. Start at the front door and see how far in you get.