Hintru ENES ← All labs
✎

Improve lab

Improved version of MesaNet Portal β€” Rail Broadcasts

You are creating a new version of this lab. The original stays untouched. Your version will be signed by a cryptographic key generated in your browser β€” no email, no password. If you clear browser data without exporting your identity, you lose authorship over your contributions.

You do not have a signing identity yet in this browser.
1
Map the gateway API surface
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

2
Locate the locked confidential note
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

3
Understand the oversight bot
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

4
Confirm the HTML injection sink in broadcast creation
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

5
Craft the exfiltration payload
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

6
Flood the broadcast table to guarantee bot trigger
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

7
Trigger the oversight bot
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

8
Recover the flag from the bot-created announcement
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.