webmedium
Цирковой трюк (Circus Trick)
hackerlab
Task: Log in as administrator with PHP type juggling vulnerability. Solution: Used magic hash (34250003024812) that produces SHA256 starting with 0e, exploiting loose comparison (==) to bypass authentication.
$ ls tags/ techniques/
sha256phpauthentication_bypassscientific_notationsource_code_analysistype_jugglingmagic_hashloose_comparison0e_hash
Source code analysisPHP Type Juggling (Magic Hash Attack)SHA256 magic hash collisionLoose comparison bypass (== vs ===)
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]