webPromedium
Привилегированный гость (Privileged Guest)
hackerlab
Task: Flask web app with terminal interface, user gets guest session, /get-flag requires admin. Solution: Bruteforce weak SECRET_KEY with flask-unsign, forge session cookie with _user_id=admin.
$ ls tags/ techniques/
flaskbruteforceauthentication_bypasspythoncookie_manipulationwerkzeugsecret_keyprivilege_escalationsession_cookieflask_unsignsession_forgery
Flask session cookie decodingSECRET_KEY bruteforce with wordlistSession forgery for privilege escalation (guest → admin)Cookie manipulation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Лысина админа (Admin's Bald Head)— duckerz
- [web][Pro]Доступ запрещён (Access Denied)— hackerlab
- [web][Pro]Bug Bounty-code— hackerlab
- [web][Pro]Печеньки с молочком (Cookies with Milk)— duckerz
- [web][Pro]Поздравительное приложение (Greeting App)— hackerlab