webeasy
Тетрис (Tetris)
hackerlab
Task: Flask web app with password reset functionality. Solution: Bruteforce weak reset token (only 729 combinations using characters b, c, d) to take over admin account and access admin panel.
$ ls tags/ techniques/
flaskbruteforcesession_hijackingauthentication_bypasspythonwerkzeugweak_tokenpassword_resettoken_generationpredictable_token
Weak token bruteforce (729 combinations)Password reset token exploitationSession cookie hijackingAdmin account takeover
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]