pwnPromedium

Хаос на АЗС (Chaos at the Gas Station)

hackerlab

Task: Web app for gas station management with admin panel. Solution: User enumeration via different error messages, password bruteforce, then SQL injection via backup upload to change superadmin password and access secret section.

$ ls tags/ techniques/
password_bruteforceuser_enumeration_via_error_messagessql_injection_via_backup_uploadhash_algorithm_analysis

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups