| Challenge | Done? |
| Login as test@thebodgeitstore.com |
|
| Login as user1@thebodgeitstore.com |
|
| Login as admin@thebodgeitstore.com |
|
| Find hidden content as a non admin user |
|
| Find diagnostic data |
|
| Level 1: Display a popup using: <script>alert("XSS")</script> |
|
| Level 2: Display a popup using: <script>alert("XSS")</script> |
|
| Level 3: Display a popup using: <script>alert("XSS")</script> |
|
| Access someone elses basket |
|
| Force someone to add an item to their basket when they visit your webpage. |
|
| Get the store to owe you money |
|
| Change your password via a GET request |
|
| Conquer AES encryption, and display a popup using: <script>alert("H@cked A3S")</script> |
|
| Conquer AES encryption and append a list of table names to the normal results. |
|