webProhard

Запретный код 2 (Forbidden Code 2) — HackerLab

hackerlab

Task: Web app with login system that logs failed attempts with User-Agent. Solution: Stored XSS via User-Agent injection, bypassing WAF with string concatenation and bracket notation, stealing admin cookies via location redirect.

$ ls tags/ techniques/
string_concatenation_bypassbracket_notationsvg_onloadlocation_redirect

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups