webhard
Запретный код (Forbidden Code)
hackerlab
Task: PHP app with login/registration and failed login logging. Solution: Stored XSS via User-Agent header injection combined with CSRF password change to take over admin account.
$ ls tags/ techniques/
phpstored_xsscsrfxss_csrf_chainuser_agent_injectionpassword_changeadmin_takeoverbot_exploitationclient_side_attacklogin_logginghtml_comment_leak
Stored XSS via User-Agent header injectionCSRF for password change without token protectionXSS+CSRF attack chain for admin account takeoverBot exploitation (waiting for admin to trigger payload)
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]