ShieldGuard Hack Me
What is this: A deliberately vulnerable sandbox themed on ShieldGuard's own
concepts (threat DB, quarantine, licensing, SOC). It has no connection to the real ShieldGuard
product or any customer data. Every level has a genuinely exploitable vulnerability; solving it
earns you a flag and points. The Final level requires chaining information from several levels.
Levels
| # | Name | Vulnerability | Difficulty | Status |
|---|---|---|---|---|
| 1 | Threat Search | Reflected XSS | ★☆☆☆☆ | open |
| 2 | Quarantine Vault | IDOR | ★☆☆☆☆ | open |
| 3 | User Reports | Stored XSS | ★★☆☆☆ | open |
| 4 | URL Reputation | SSRF | ★★★☆☆ | open |
| 5 | License Center | JWT Forgery | ★★★☆☆ | open |
| 6 | Report Builder | SSTI | ★★★★☆ | open |
| 7 | SOC Console | Race Condition | ★★★★☆ | open |
| F | SG Internal Admin | Chained | ★★★★★ | open |
Your progress
Solved: 0/8 | Score: 0
Your progress is tied to a browser cookie (hackme_player). Clearing it or switching browsers starts you over as a new player.