webProhard
UUIDY
duckerz
Task: Notes app with Telegram auth, get admin password hash. Solution: Predict UUID tokens using extracted MAC address + race condition to get admin JWT, then boolean-based SQLi via f-string in is_user_exists() to extract hash character by character.
$ ls tags/ techniques/
race_condition_exploittoken_predictionboolean_based_sqli
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Форум предсказателей (Prediction Forum)— hackerlab
- [web][Pro]Print on Demand (Печать по запросу)— duckerz
- [web][Pro]Конкурс заметок— duckerz
- [crypto][Pro]Хмак! Будь здоров!— duckerz
- [web][Pro]165 - Klimat Kontrol (Climate Control)— duckerz