webmedium

Доступ запрещён (Access Denied)

hackerlab

Task: Web application with IP filtering and PHP cookie-based authentication. Solution: Bypass IP filter with X-Forwarded-For header, then exploit PHP type juggling by replacing password with boolean true in serialized cookie data.

$ ls tags/ techniques/
X-Forwarded-For header IP spoofingPHP insecure deserializationPHP type juggling (boolean true vs string)Cookie-based authentication bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]