webeasy

Neighbour

tryhackme

Task: Web application with login form and profile page. Solution: Found guest credentials in HTML comments, logged in, then exploited IDOR vulnerability by changing user parameter in URL from guest to admin to access admin profile and retrieve flag.

$ ls tags/ techniques/
IDOR via URL query parameter manipulationHTML source code inspection for leaked credentialsSession-authenticated horizontal privilege escalation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]