webeasy
Neighbour
tryhackme
Task: Web application with login form and profile page. Solution: Found guest credentials in HTML comments, logged in, then exploited IDOR vulnerability by changing user parameter in URL from guest to admin to access admin profile and retrieve flag.
$ ls tags/ techniques/
IDOR via URL query parameter manipulationHTML source code inspection for leaked credentialsSession-authenticated horizontal privilege escalation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]