webhard

Запретный код 2 (Forbidden Code 2) — HackerLab

hackerlab

Task: Web app with login system that logs failed attempts with User-Agent. Solution: Stored XSS via User-Agent injection, bypassing WAF with string concatenation and bracket notation, stealing admin cookies via location redirect.

$ ls tags/ techniques/
string_concatenation_bypassbracket_notationsvg_onloadlocation_redirect

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]