Posts

Showing posts from April, 2024

HackTheBox-"Lame" [WRITE-UP] {EASY}

[Access Control] Lab 7: User ID controlled by request parameter with password disclosure

[Access Control] lab 6: User ID controlled by request parameter, with unpredictable user IDs

[Access Control] Lab 5: User role controlled by request parameter

[Access Control] Lab 4: Unprotected admin functionality with unpredictable URL

[Access Control] Lab 2: Unprotected admin functionality