webeasy

Тетрис (Tetris)

hackerlab

Task: Flask web app with password reset functionality. Solution: Bruteforce weak reset token (only 729 combinations using characters b, c, d) to take over admin account and access admin panel.

$ ls tags/ techniques/
Weak token bruteforce (729 combinations)Password reset token exploitationSession cookie hijackingAdmin account takeover

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]