pwnPromedium
Хаос на АЗС (Chaos at the Gas Station)
hackerlab
Task: Web app for gas station management with admin panel. Solution: User enumeration via different error messages, password bruteforce, then SQL injection via backup upload to change superadmin password and access secret section.
$ ls tags/ techniques/
password_bruteforceuser_enumeration_via_error_messagessql_injection_via_backup_uploadhash_algorithm_analysis
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Tokens— hackerlab
- [web][Pro]Запретный код (Forbidden Code)— hackerlab
- [web][Pro]Dosie X (Dossier X)— hackerlab
- [web][Pro]Ограничения (Restrictions)— hackerlab
- [web][Pro]Powergrid Challenge— necronet