This lab has user account page that contains the current user’s existing password, prefilled in a masked input.
To solve the lab, retrieve the administrator’s password, then use it to delete the user
carlos
.You can log in to your own account using the following credentials:
Lab link.wiener:peter
When we login with the given user information, we see the username in the id parameter in the URL.
data:image/s3,"s3://crabby-images/74318/743181af5c6a815faf15f6b35bae9258f79bca27" alt=""
If we look at the request, we see that the password is an information disclosure.
data:image/s3,"s3://crabby-images/d39d0/d39d08a9db26dacfa0927efa666622c515882f41" alt=""
we make the username administrator and learn the admin password.
data:image/s3,"s3://crabby-images/04b34/04b34c9ba729bdba135e2beba3339cfa5248a2d8" alt=""
We log in to the admin account with password information. We enter the admin panel and delete the Carlos user.
data:image/s3,"s3://crabby-images/44d53/44d5336afb4ba0d106acce5f601e027ea7445cf8" alt=""
data:image/s3,"s3://crabby-images/112df/112dfda10a1e06a76b22426d92c884f88d7e3804" alt=""