webPromedium
Lab 303 — DevGateway — Broken Access Control in Admin API
hackadvisor
Task: API management platform with exposed documentation revealing admin endpoints. Solution: Authenticated as regular user, accessed admin settings endpoint due to missing role-based authorization, retrieved flag from internal API secret.
$ ls tags/ techniques/
jwt_authenticationauthorization_bypassapi_endpoint_enumerationbola_exploitation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 330 — AuthVault — Blind LDAP Injection in Directory Lookup— hackadvisor
- [web][Pro]Lab 16 — FileGate — Authentication Bypass in API Login— hackadvisor
- [web][Pro]Lab 350 — VaultKeeper— hackadvisor
- [web][Pro]Lab 12 — NewsGrid — JWT Algorithm Confusion— hackadvisor
- [web][Pro]Lab 198 — PayrollSync — Broken Auth via GraphQL Introspection— hackadvisor