Application Security Division

Operation Mirage

OWASP Top Ten Web Security Expert Training - 3 to 5-Day Investigation

MRG

On June 20, 2025, Souk Digital, Morocco's largest online marketplace, receives a fraud notification: 3,000 customer cards flagged. Common point: all victims shopped on Souk Digital in the past 60 days. The attack ran for 8 weeks before detection. The attackers probed every endpoint, found multiple vulnerabilities, and exploited them in sequence. The Application Security Division is called in to reconstruct the attack. 20 missions covering the OWASP Top 10 - SQL injection, XSS, IDOR, SSRF, authentication bypass. Analyze HTTP logs, decode payloads, and identify exfiltrated data.

OWASP Top 10
Web Security
HTTP Analysis
Attack Pattern Recognition
Log Forensics
SQL Injection Detection
XSS Analysis
3
days
20
missions
Difficulty intermediate
Status Registration Closed
Initiate Operation