webhard

Code Control

undutmaning

Task: Code review service with XSS via HTML entity encoding to bypass lowercase filter. Solution: Exfiltrate admin JWT via stored XSS, access database backup from admin todos, extract PostgreSQL WAL file to find plaintext admin password.

$ ls tags/ techniques/
html_entity_encoding_bypassstored_xssjwt_token_exfiltrationdocker_layer_extractionpostgresql_wal_analysis

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]