webProhard
Запретный код 2 (Forbidden Code 2) — HackerLab
hackerlab
Task: Web app with login system that logs failed attempts with User-Agent. Solution: Stored XSS via User-Agent injection, bypassing WAF with string concatenation and bracket notation, stealing admin cookies via location redirect.
$ ls tags/ techniques/
string_concatenation_bypassbracket_notationsvg_onloadlocation_redirect
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Запретный код (Forbidden Code)— hackerlab
- [web][Pro]Авторизация 2.0 (Authorization 2.0)— hackerlab
- [web][Pro]Доступ запрещён (Access Denied)— hackerlab
- [web][Pro]Базовая авторизация 3 — HackerLab— hackerlab
- [web][Pro]Базовая авторизация 2 (Basic Auth 2)— hackerlab