Track
Secrets & Auth
Investigate auth headers, IAM failures, rotated secrets, webhook signatures, and authorization regressions.
11Ready
2Planned
Skills trained
- checkFollow auth flows
- checkCheck secret loading
- checkAudit signature timing
Recommended path
terminalAccessDenied at 3AM
Mediumchevron_right
terminalCORS origin parsing bug
Mediumchevron_right
terminalThe Token That Never ExpireChecked
Easychevron_right
terminalThe Constant-Time Compare That Compounded The Opposite
Hardchevron_right
terminalThe Payment Key That Ended Up In The Logs
Mediumchevron_right
Ready incidents
Playable now through the existing challenge engine.
terminalAccessDenied at 3AM
Mediumchevron_right
terminalCORS origin parsing bug
Mediumchevron_right
terminalThe Permission That Outlived the User
Mediumchevron_right
terminalThe File That Left the Vault
Mediumchevron_right
terminalThe Redirect That Left the Building
Mediumchevron_right
terminalThe Webhook That Trusted Silence
Mediumchevron_right
terminalCORS startsWith() allows lookalike origins
Easychevron_right
terminalCORS allows the null origin unconditionally
Hardchevron_right
terminalThe Token That Never ExpireChecked
Easychevron_right
terminalThe Payment Key That Ended Up In The Logs
Mediumchevron_right
terminalThe Constant-Time Compare That Compounded The Opposite
Hardchevron_right
Planned Debugging 50 patterns
Visible for roadmap context only. These entries are not playable.
41Webhook Signature Timestamp Drift
Planned
52Log Redaction Missing
Planned