Timed Engagement · No Flags

OpsNest

SaaS DevOps / internal admin console.

The intention

You're on a one-day scoped engagement against OpsNest, a DevOps control plane holding deploy secrets and API tokens. No flags — find and exploit every critical issue (secret theft, SSRF-to-metadata, RCE, privilege escalation), assess blast radius, and deliver a plan and report.

How it runs

  1. Qualify (50 MCQ, 70% to pass). Prove you know the CWAP material before you touch a live target. Score under 70% and you can't start.
  2. Plan (90 min). You must write and submit a pentest plan before the target unlocks — exactly like a real engagement. No plan, no access.
  3. Hack (24 h). Once your plan is in, the clock starts: you have 24 hours to compromise the target and identify every critical issue.
  4. Report & debrief. Write up your findings, then watch the hidden debrief video where the intended attack paths are walked.

There are no flags. Your deliverable is the plan and the report — the skills a real assessment demands.

🎓 CMWAP practice. This mirrors the CMWAP exam (Certified Modern Web App Pentester): a 24-hour window, a written report, and a ≤10-minute debrief video scored on your methodology. Treat it like the real thing.

Debrief video is available any time under /debrief.