Welcome to the AcmeCorp Staff Portal
Internal systems for AcmeCorp employees. This build is a training instance โ it contains real-world bug classes, isolated in a sandbox.
You are not signed in. Some challenges require a staff account. Try the portal as staff, or find your way in.
Your scorecard
You are training as student-anon ยท 0/18 flags captured. Progress is saved on this browser only.
Company announcements
Payday is the 28th. Payslips are in My Documents .
IT maintenance window Saturday 22:00โ02:00.
Reminder: report suspicious emails to security@acmecorp.example.
Training challenges 0/18 solved
All (18)
Beginner (6)
Intermediate (7)
Advanced (5)
SQL Injection intermediate
Injection
Show hint The staff directory builds its search query by string concatenation.
Open challenge โ
Reflected XSS beginner
XSS
Show hint The quick-search echo prints your input straight into the page.
Open challenge โ
Stored XSS intermediate
XSS
Show hint Ticket comments are saved and re-rendered without sanitising.
Open challenge โ
IDOR beginner
Access Control
Show hint Pay slips are fetched by numeric id with no ownership check.
Open challenge โ
Broken Authentication beginner
Authentication
Show hint Default admin credentials were never changed. The login form is also injectable.
Open challenge โ
Path Traversal beginner
Files
Show hint IT tools let you download a file by name.
Open challenge โ
Command Injection intermediate
Injection
Show hint The network diagnostic tool shells out to ping. (Simulated โ no real shell.)
Open challenge โ
SSRF intermediate
Injection
Show hint The URL preview tool fetches whatever host you give it. (Simulated โ no real network.)
Open challenge โ
Broken Access Control intermediate
Access Control
Show hint Your session token is unsigned and accepts alg:none. The admin panel trusts it.
Open challenge โ
Unrestricted File Upload beginner
Files
Show hint The resume uploader accepts any file extension.
Open challenge โ
Blind SQL Injection advanced
Injection
Show hint The blind directory search only tells you how many match โ infer data from yes/no answers.
Open challenge โ
Mass Assignment advanced
Access Control
Show hint The profile form only shows name/email, but the server binds every field you send.
Open challenge โ
XML External Entity (XXE) advanced
Injection
Show hint The XML importer resolves external entities. Declare one and reference it.
Open challenge โ
Server-Side Template Injection advanced
Injection
Show hint The greeting banner renders your input as a template. Try {{7*7}}.
Open challenge โ
Open Redirect beginner
Client-Side
Show hint The redirect helper trusts the ?next= value, even when it points off-site.
Open challenge โ
CRLF Injection intermediate
Injection
Show hint The language selector reflects your value into a response header.
Open challenge โ
Insecure Deserialization intermediate
Injection
Show hint Your preferences cookie is base64-encoded JSON the app decodes and trusts.
Open challenge โ
Encoded Path Traversal advanced
Files
Show hint The download tool decodes its argument a second time โ double-encode the traversal.
Open challenge โ