// Breach the Portal

A live, genuinely vulnerable employee login page — find the flaw and read data you shouldn't be able to.

Stay in scope. Every artifact here is synthetic — built for this challenge, not captured from a real system. Apply the same techniques only against systems you own or are explicitly authorized to test.

// Target

// Your Toolbox

Your browser No special tools needed for any of this — your browser and its built-in DevTools are enough.
View Page Source / DevTools Ctrl+U (or right-click → View Page Source) shows the raw HTML, including anything left behind in comments that never renders on the page itself.

// Situation

A small internal tool for the campus IT team leaked its login URL. It's a basic username/password form — nothing fancy. Nothing about the page itself hints at a problem. Start by taking a look at what actually shipped in it.

// The Challenges

01 easy

Read Between the Lines

Developers leave things behind in HTML comments they forget are visible to anyone who looks — view the portal's page source and see what turns up.

Target file: /lab/web-exploitation-portal (page source)
02 medium

Bypass the Login

You don't have a valid password for any account — you're not supposed to. Get past the login anyway, land in the administrator's account, and read what's sitting in their notes.

03 medium

Broken Trust

The login form isn't the only way in. Something else this app does trusts you without ever really checking who you are.

04 hard

None the Wiser

There's a "Remember Me" feature now too, and it hands out tokens to anyone who asks. Not every token that looks signed actually gets checked.