webmedium

Привилегированный гость (Privileged Guest)

hackerlab

Task: Flask web app with terminal interface, user gets guest session, /get-flag requires admin. Solution: Bruteforce weak SECRET_KEY with flask-unsign, forge session cookie with _user_id=admin.

$ ls tags/ techniques/
Flask session cookie decodingSECRET_KEY bruteforce with wordlistSession forgery for privilege escalation (guest → admin)Cookie manipulation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]