webPromedium

Magic Link 3

bluehensctf

Task: a Magic Link Login Service where POST /login leaks the magic-link UUID in the JSON response. Solution: request a login link for [email protected], extract the UUID from the response, visit /login/<uuid> to authenticate as admin, access /dashboard to retrieve the flag.

$ ls tags/ techniques/
magic_link_uuid_extractionauthentication_token_reuseadmin_account_takeover

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups