webProhard
Code Control
undutmaning
Task: Code review service with XSS via HTML entity encoding to bypass lowercase filter. Solution: Exfiltrate admin JWT via stored XSS, access database backup from admin todos, extract PostgreSQL WAL file to find plaintext admin password.
$ ls tags/ techniques/
html_entity_encoding_bypassstored_xssjwt_token_exfiltrationdocker_layer_extractionpostgresql_wal_analysis
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][free]BaseCamp— alfactf
- [web][Pro]bawker— bluehensctf
- [web][free]OpenSecret— hackthebox
- [web][Pro]Lab 12 — NewsGrid — JWT Algorithm Confusion— hackadvisor
- [web][Pro]Запретный код (Forbidden Code)— hackerlab