This website has an unauthenticated admin panel at
/admin
, but a front-end system has been configured to block external access to that path. However, the back-end application is built on a framework that supports theX-Original-URL
header.To solve the lab, access the admin panel and delete the user
Lab link.carlos
.
We try to access the /admin URL. We can’t access and we are blocked.
data:image/s3,"s3://crabby-images/8affb/8affb2bb75565a192d3a06b59621b207b7dbc282" alt=""
data:image/s3,"s3://crabby-images/c660f/c660f9dfc456461a777a336f04c67b5b87bd4acb" alt=""
We send the request to the repeater. We clear the Get request URL and add the “X-Original-URL: /admin” parameter to the request.
data:image/s3,"s3://crabby-images/c5d84/c5d845033609acb13ad12085c6fc681626094d8f" alt=""
data:image/s3,"s3://crabby-images/80429/804292c4a0bcbdf2484e8a2696c1f67516bc0813" alt=""
We delete user Carlos and the lab is solved.
data:image/s3,"s3://crabby-images/c8af2/c8af285d5cb33408400e99b9731f60b564b5d221" alt=""