T3chnocr4t:~#

Looking 🔭 For Something Hidden....

View on GitHub

Access Control

Lab:~# User ID controlled by request parameter with data leakage in redirect

Guys 👋 welcome back! Here is another write-up on a web security academy lab. This lab contains an access control vulnerability where sensitive information is leaked in the body of a redirect response. Let’s get started and exploit it.

access-control


End Goals :~#


Testing For Vulnerabilities:

111

222

333

444

That’s all, friends. Thank you for reading up to this point. I would like to hear your feedback on anything not clear here. Here is my Twitter account @T3chnocr4t. Feel free to DM me if you have any issues with my write-up. Thanks!

Go Back Home