ISOLATED SIMULATION
DKHACK.TECH ↗
AUTHORIZED PRACTICE ENVIRONMENT

Assess a real commerce workflow.
Break nothing real.

Northstar Market behaves like a production e-commerce system while every account, file, service, and transaction remains synthetic and isolated.

NO ACCOUNT4-HOUR MAXIMUMSYNTHETIC DATA ONLY
engagement.scope
$ scope --show
TARGET       Northstar Market
MODE         Black-box web assessment
DATA         Synthetic / disposable
TOOLS        Browser · Burp · curl
AUTHORITY    Issued session only
OUTBOUND     Denied by design

✓ CONTROL PLANE PROTECTED
✓ SERVER EFFECTS VIRTUALIZED

A pentest workflow—not a scoreboard.

DISCOVER

Map the application

Explore storefront, identity, seller, support, administration, and API surfaces without challenge labels.

VALIDATE

Build evidence

Use ordinary requests, an intercepting proxy, browser tools, or scripts against your issued target.

REPORT

Write the finding

Capture impact and remediation in a professional journal instead of collecting flags or points.

Twenty-five realistic testing areas.

Identity · Authentication rate-control failureServer injection · Shipping diagnostic command injectionBrowser security · Profile update cross-site request forgeryFile handling · Unsafe seller template inclusionFile handling · Executable attachment uploadIdentity · Reusable promotional CAPTCHAServer injection · Storefront SQL injectionServer injection · Blind order-tracking SQL injectionSession · Predictable legacy session identifierBrowser security · DOM-based product-filter XSSBrowser security · Reflected search XSSBrowser security · Stored review XSSBrowser security · Legacy widget CSP bypassBusiness logic · Client-side checkout validation bypassAccess control · Order authorization bypassServer injection · Supplier import SSRFSession · Seller JWT verification weaknessAPI security · Mobile API object-level authorization failureBrowser security · Credentialed CORS origin reflectionServer injection · Supplier invoice XXEBusiness logic · Checkout business-logic abuseBusiness logic · Gift-card redemption raceConfiguration · Debug and backup information disclosureIdentity · Predictable password-reset tokenBrowser security · Frameable coupon approval
SAFE
BY
DESIGN

Real requests. Synthetic consequences.

Browser vulnerabilities execute only on the isolated target origin. Shells, SQL, filesystems, uploads, XML entities, and outbound services are deterministic virtual engines that cannot reach hosting infrastructure.