webPromedium
Цирковой трюк (Circus Trick)
hackerlab
Task: Log in as administrator with PHP type juggling vulnerability. Solution: Used magic hash (34250003024812) that produces SHA256 starting with 0e, exploiting loose comparison (==) to bypass authentication.
$ ls tags/ techniques/
sha256phpauthentication_bypassscientific_notationsource_code_analysistype_jugglingmagic_hashloose_comparison0e_hash
Source code analysisPHP Type Juggling (Magic Hash Attack)SHA256 magic hash collisionLoose comparison bypass (== vs ===)
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Магическая админка — hackerlab— hackerlab
- [web][Pro]Секретный ключ (Secret Key)— hackerlab
- [web][Pro]Ограничения (Restrictions)— hackerlab
- [web][Pro]Лысина админа (Admin's Bald Head)— duckerz
- [web][Pro]Мистер Дино (Mr. Dino)— hackerlab