Threat modeling lab - Last Flag

Complete the threat modeling lab several times, but I always get the same answer.

Could you please get the last flag so I can continue learning?

Hey there - as noted in the instructions, if you believe your model is correct but the grader says otherwise, please upload your JSON to pastebin and post it here so we can review it.

Hello
Thank you for your cooperation

pastebin.com/D5dwjeB2

Note that the route in the guide is wrong since the /Guided/ is missing.


Hey there - we’ve reviewed your JSON and confirmed that the grader was failing for the following reasons:

  • Your “Workshop API” was outside of the “Data Center (Protected)” trust boundary.
  • You spelled “access” as “acces” in two places in the “Server-Side Request Forgery” threat.

That said, your model was correct otherwise, so I’ve messaged the flag to you.

1 Like

I am also having issues getting the last flag. Here is my JSON for review. It’s saying I’ve done everything wrong but I can’t find any issues in my work

Hey there - we reviewed your JSON and it looks like you didn’t save the file properly before running the grader. This is what’s represented in the JSON.

1 Like

I do have the same problem to get last flag to continue my learning.Help..?

Hey there - as noted in the lab guide, you’ll need to upload the JSON to pastebin and share the link in order for us to help troubleshoot. Additionally, please share a screenshot of the message that the grader produces when you execute grade-guided.

i also have the same issue

Kindly upload the JSON to pastebin and share the link in order for us to help troubleshoot :slight_smile:

I am having a similar issue.

In addition to the pastebin above, can you confirm the message that the grader is outputting?

It looks like you had the Web Traffic flow set to HTTPS rather than HTTP. This gets set in Part 3, Step 8 and is not modified later in the lab.

Hi, I’m pretty sure I’ve done everything correct, however I’m still not getting the flag. I’m being told the SSRF threat is incorrect, but it looks exactly how the instructions describe it. Here’s my pastebin link. { “version”: “2.2.0”, “summary”: { “title”: “My Premium Dealership”, - Pastebin.com - Please can you take a look?

Thank you. That was the problem.

1 Like