← Back to ShopKart win CyberRange

CASE FILE · SK-2026-0914

Operation: Front Door

 

0 / 5 pieces of evidence logged

ShopKart's login form is the very first thing every visitor touches. Our tipster says it's not checking who it lets in as carefully as it should. Can you walk in without a key?

Open the Login page ↗

Not every door gets kicked in — sometimes someone just left a spare key under the mat. Our tipster mentions the team left themselves a note somewhere on the public site. Developers talk to each other in comments. Are you listening?

Open the About ShopKart page ↗

Anyone can leave a product review on ShopKart — and whatever they type gets shown to every single visitor afterwards, exactly as typed. Our tipster thinks that's a problem. Can you make the page run your own code, not just display your own text?

Open the Aurora Desk Lamp product page ↗

Modern websites constantly talk to invisible backend addresses (APIs) to fetch data behind the scenes. Our tipster suspects ShopKart built one of these to list customer accounts — and forgot to lock the door on it.

No page for this one — you'll have to guess the address

The very last thing before a launch: config files, backups, debug notes — the paperwork of building a website. All of it is meant to stay on the server, never on the public internet. Our tipster has a bad feeling ShopKart forgot to lock one of these away.

No page for this one — config files usually hide in plain sight

CASE CLOSED

Every piece of evidence, logged.

ShopKart launches in a few hours — and thanks to you, it launches a lot safer than it would have. You just walked through five of the most common ways real websites get broken into, start to finish.