webProhard

Запретный код (Forbidden Code)

hackerlab

Task: PHP app with login/registration and failed login logging. Solution: Stored XSS via User-Agent header injection combined with CSRF password change to take over admin account.

$ ls tags/ techniques/
Stored XSS via User-Agent header injectionCSRF for password change without token protectionXSS+CSRF attack chain for admin account takeoverBot exploitation (waiting for admin to trigger payload)

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups