Skip to content

Latest commit

 

History

History
16 lines (11 loc) · 711 Bytes

tasks 2.md

File metadata and controls

16 lines (11 loc) · 711 Bytes
  1. login me sql injection (admmin list user with search and bli) -> Done

  2. profile page -> broken access control. (is_admin => true) Mass assigment. -> [insecure design] -> Done

  3. profile/uuid -> update info. [broken access control] -> Done

  4. rce|command injection|xml entiity injection| LFI, RFI | Outdate component. -> Done

  5. Dashboard pull maps. -> SSRF | Filter | https://snowscan.io/htb-writeup-travel/# | show logs from localhost only. Done

  6. loggin monitoring failure -> ssrf 6

  7. jwt | identification and authentication failure

  8. software and data integirty failure | laravel deserialization.

use list blink inject in admin

jwt -> none -> cryto