Intro
Damn Good Looking is a cousin of DVWA / DIVA, not a reskin. You sign a call sheet, walk twelve rooms, and switch a difficulty called a season: Raw, Cut, Finish. Beauty is not a control — that is part of the lesson.
It concatenates SQL, renders markup, reads files, and talks to a shell on purpose. This page does not document attacks. Do not publish the package, bind the web server to a public interface, or sideload the Android build onto someone else’s phone.
Method
Web: Node 22, SQLite, npm start on 127.0.0.1:4141. Android: Compose, same house with device-shaped doors (exported activities, a provider, a deep link, a WebView). Director / Intern / Guest on the call sheet. Intern is the everyday walk. Director can recut the database.
Rooms are features, not a walkthrough: Ledger search, Guestbook notes, Marquee announcements, Vault invoices, Courier payout account, Darkroom uploads, Archive lookbooks, Concierge ping, Lookbook with a signed slip, Mannequin place-cards, Mirror fragment, Fitting profile. Study pattern: the same honest action on Raw, then Cut, then Finish.
Demo
On your machine only: npm start, intern + Raw, home, Ledger search for a name printed on the floor, repeat two rooms on Cut and Finish. Android: Android Studio, emulator you own, same walk. Screenshots here are the atelier UI, not a payload.
Conclusion
A pedagogy piece about how pretty software can still be a training studio. Keep it local. Keep exploits out of the README and off this site.


