SaaS DevOps / internal admin console.
You're on a one-day scoped engagement against OpsNest, a DevOps control plane holding deploy secrets and API tokens. No flags — find and exploit every critical issue (secret theft, SSRF-to-metadata, RCE, privilege escalation), assess blast radius, and deliver a plan and report.
There are no flags. Your deliverable is the plan and the report — the skills a real assessment demands.
🎓 CMWAP practice. This mirrors the CMWAP exam (Certified Modern Web App Pentester): a 24-hour window, a written report, and a ≤10-minute debrief video scored on your methodology. Treat it like the real thing.
Debrief video is available any time under /debrief.