Avatar

Labs / EVALANCHE

  • Hard
  • Released 01 Jul 2025

EVALANCHE

Start the machine, hack the system, and find the hidden flags to complete this challenge and earn points!

2
Flags
60
Points
Hard
Solution Available
Free Access
Start Lab Environment

Launch your dedicated AWS machine to begin hacking

~1-2 min setup
AWS dedicated
Private instance
Industry standard
Hard

Welcome to EVALANCHE, a sophisticated web application security challenge that tests your skills in multiple attack vectors.

This challenge presents a unique web application with legacy authentication systems, API endpoints, and administrative tools. The application appears to be a corporate system with various user roles and access levels.

Your mission is to:

  • Analyze the web application structure and identify potential vulnerabilities
  • Explore the authentication mechanisms and find ways to bypass security controls
  • Leverage discovered vulnerabilities to gain elevated access
  • Navigate through the system to find hidden functionality
  • Exploit privilege escalation opportunities to achieve full system compromise

This challenge requires a systematic approach, combining web application testing, authentication bypass techniques, and advanced privilege escalation methods. Pay close attention to the application's architecture, API documentation, and any hidden functionality that might provide the keys to success.

Remember: Sometimes the most obvious path isn't the correct one. Think outside the box and explore every possible avenue for exploitation.