Mirage Track

Level 32 → Level 33

Schema Is the Map
900 pts+125 first-blood bonus

Objective

Apexgraph. Introspection is on and the resolvers don't check ownership — alias and batch your way across tenants (GraphQL BOLA).

How to play

Open the target in your browser, find the flaw, and exploit it. On success the page reveals the login for the next level — that password is this level's flag. Submit it on the track page (or /submit) to bank the points.

Target

Log in as l32 with the password you captured on the previous level, then:
https://mirage-l32.breachlab.org
Open target ↗
🩸
First Blood captured by
ACTIVE RECORD