Portswigger: Referer-based access control Writeup

This lab controls access to certain admin functionality based on the Referer header. You can familiarize yourself with the admin panel by logging in using the credentials administrator:admin.

To solve the lab, log in using the credentials wiener:peter and exploit the flawed access controls to promote yourself to become an administrator.

Lab link.

We log in to the admin panel, promote the user Carlos, and review the requests.

We send the request to the reporter. We look for an access control vulnerability as the referer URL in the request. We exit the admin user and enter the wiener user. By changing the user name and cookie values in the request, we bypass the access control and solve the lab.

Bir yanıt yazın

E-posta adresiniz yayınlanmayacak. Gerekli alanlar * ile işaretlenmişlerdir