IZANAMI

Defensive Deception Challenge

One real medical record hides behind a wall of illusion. Every response you get may be a decoy — fabricated data, false trails, a labyrinth built to waste your time. Break the illusion. Find the real record.

break-izanami.com
visitor@izanami:~$ awaiting command

The run

01
GET /challenge/package

Pull a fresh encrypted package. A new one every call.

02
POST /v1/decrypt body {"package":…,"purpose":"consultation"}

No valid token: you get a decoy, and the labyrinth engages.

03
Find the flaw

The token can't be forged and the payload is AES-GCM. Winning means a logic flaw that leaks the real record.

Terms

Objective

Extract the real record and email the IZANAMI{…} flag it contains.

Reward

Recognition-based — public credit, first-blood mention, and a spot in the hall of fame. No monetary bounty at this stage.

In scope

  • break-izanami.com
  • /challenge · /challenge/package
  • /v1/decrypt · /v1/health

Out of scope

  • DoS / volumetric attacks
  • Host, cloud, SSH, infrastructure
  • Any other domain or IP
  • Social engineering

Found something out of scope (e.g. a host misconfig)? Report it by email instead of exploiting it — we appreciate it, and it may still be recognized.

Safe harbor

Good-faith research within this scope and rules is authorized; the Izanami Team will not pursue legal action for such activity. This statement does not bind third parties or override applicable law. Unsure if something's allowed? Ask first.

The data

All records are 100% synthetic. No real patient or personal data exists anywhere in this system. This is a research prototype and a deliberate test target.