$ cat writeup.md…
$ cat writeup.md…
tryhackme
Task: Web application with login form and profile page. Solution: Found guest credentials in HTML comments, logged in, then exploited IDOR vulnerability by changing user parameter in URL from guest to admin to access admin profile and retrieve flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar