webhard

Запретный код (Forbidden Code)

hackerlab

Task: PHP app with login/registration and failed login logging. Solution: Stored XSS via User-Agent header injection combined with CSRF password change to take over admin account.

$ ls tags/ techniques/
Stored XSS via User-Agent header injectionCSRF for password change without token protectionXSS+CSRF attack chain for admin account takeoverBot exploitation (waiting for admin to trigger payload)

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]