ROE / Rules of Engagement
Stay inside the lab
The activity trains observation and correlation. It is not a contest to see who can break things harder.
Allowed
- Inspect the page source.
- Open public files inside
/hunt/. - Use DevTools, simple decoding, and log reading.
- Test only the controlled XSS lab.
Not allowed
- Leave the
/hunt/ folder. - Use brute force, aggressive scanners, or destructive payloads.
- Modify or attack the real Day0 portal.
- Confuse flags with reporting: a flag without explanation is worth little.
First hint
Some information lives in files that are normally public but often ignored. The first evidence is not always visible in the rendered page.