webPromedium

Цирковой трюк (Circus Trick)

hackerlab

Task: Log in as administrator with PHP type juggling vulnerability. Solution: Used magic hash (34250003024812) that produces SHA256 starting with 0e, exploiting loose comparison (==) to bypass authentication.

$ ls tags/ techniques/
Source code analysisPHP Type Juggling (Magic Hash Attack)SHA256 magic hash collisionLoose comparison bypass (== vs ===)

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups