Posts

Showing posts with the label burp suite certified practitioner

[Access Control] Lab 7: User ID controlled by request parameter with password disclosure

[Access Control] lab 6: User ID controlled by request parameter, with unpredictable user IDs

[Access Control] Lab 5: User role controlled by request parameter

[Access Control] Lab 4: Unprotected admin functionality with unpredictable URL

[Access Control] Lab 2: Unprotected admin functionality

[Access Control] Lab 1: Traversal Lab

[Brute-force] Lab 2: 2FA simple bypass

[Brute-force] Lab 1: Username enumeration via different responses