webProeasy

Neighbour

tryhackme

Task: Web application with login form and profile page. Solution: Found guest credentials in HTML comments, logged in, then exploited IDOR vulnerability by changing user parameter in URL from guest to admin to access admin profile and retrieve flag.

$ ls tags/ techniques/
IDOR via URL query parameter manipulationHTML source code inspection for leaked credentialsSession-authenticated horizontal privilege escalation

πŸ”’

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups