webProhard
Запретный код (Forbidden Code)
hackerlab
Task: PHP app with login/registration and failed login logging. Solution: Stored XSS via User-Agent header injection combined with CSRF password change to take over admin account.
$ ls tags/ techniques/
phpstored_xsscsrfxss_csrf_chainuser_agent_injectionpassword_changeadmin_takeoverbot_exploitationclient_side_attacklogin_logginghtml_comment_leak
Stored XSS via User-Agent header injectionCSRF for password change without token protectionXSS+CSRF attack chain for admin account takeoverBot exploitation (waiting for admin to trigger payload)
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Запретный код 2 (Forbidden Code 2) — HackerLab— hackerlab
- [web][Pro]Провальный код (Failed Code)— hackerlab
- [web][Pro]Доступ запрещён (Access Denied)— hackerlab
- [web][Pro]Звездный сейф (Star Safe)— hackerlab
- [web][Pro]Ограничения (Restrictions)— hackerlab