Lab link.
This lab has an admin panel at
/admin
, which identifies administrators using a forgeable cookie.Solve the lab by accessing the admin panel and using it to delete the user
carlos
.You can log in to your own account using the following credentials:
wiener:peter
We log in to the account using the user credentials provided. If we pay attention to the URL part, we see the “id=wiener” parameter.
data:image/s3,"s3://crabby-images/ee28f/ee28fdbaa8527b9c827bdaaf3bdeb0390417a03f" alt=""
If we make the id parameter admin in the URL, we display that we cannot access
If we examine the requests, we see that the admin value in the cookie is false.
data:image/s3,"s3://crabby-images/f0c86/f0c86ec30e10816305431bfa7776c8bd65522252" alt=""
We set the admin value to true.
data:image/s3,"s3://crabby-images/68449/6844993ab9ce78019066f420808e7dc39039dd97" alt=""
data:image/s3,"s3://crabby-images/e9428/e942882799affd6de6f20728553c9c46a3adc2fc" alt=""
data:image/s3,"s3://crabby-images/12ad8/12ad85bb5df6f266f863ab8fe138cfb35ba61f3a" alt=""
data:image/s3,"s3://crabby-images/506dd/506ddb14f6cd2c026efe9abac1d7a8a1054631d9" alt=""
We change the cookie value in the GET /admin request and try to delete the user carlos.
data:image/s3,"s3://crabby-images/557c8/557c876d5e509576a1b2610dc8cc6bbf68ad12af" alt=""
data:image/s3,"s3://crabby-images/de476/de47628e6ab78024402223c75c66a4a8463f041a" alt=""
data:image/s3,"s3://crabby-images/bdb12/bdb128f58fe29faf5bf55137fd38affd7483d040" alt=""
This time we need to change the cookie value in the GET /admin/delete?username=carlos request.