Ir al contenido
cyberhub.es
  • Home
  • CTFs resueltos
    • PicoCTF
      • PicoCTF 2024 writeup
  • Portswigger Lab writeup
    • Access control
    • API Testing
    • CORS
    • Cross-site scripting
    • CSRF
    • File upload
    • GraphQL API vulnerabilities
    • NoSQL injection
    • OS command injection
    • Path traversal
    • SQL injection
    • SSRF
    • Web LLM attacks
    • WebSockets
  • Home
  • CTFs resueltos
    • PicoCTF
      • PicoCTF 2024 writeup
  • Portswigger Lab writeup
    • Access control
    • API Testing
    • CORS
    • Cross-site scripting
    • CSRF
    • File upload
    • GraphQL API vulnerabilities
    • NoSQL injection
    • OS command injection
    • Path traversal
    • SQL injection
    • SSRF
    • Web LLM attacks
    • WebSockets

Categoría: API Testing

Exploiting a mass assignment vulnerability writeup

Descripción To solve the lab, find and exploit a mass assignment vulnerability to buy a Lightweight l33t Leather Jacket. You can log in to your own account using the following credentials: wiener:peter. Required knowledgeTo solve this lab, you’ll need to know: These points are covered in our API Testing Academy topic. Exploiting a mass assignment […]

Finding and exploiting an unused API endpoint

Descripción To solve the lab, exploit a hidden API endpoint to buy a Lightweight l33t Leather Jacket. You can log in to your own account using the following credentials: wiener:peter. Required knowledgeTo solve this lab, you’ll need to know: These points are covered in our API Testing Academy topic. Finding and exploiting an unused API […]

Exploiting server-side parameter pollution in a query string Portswigger Lab Solution

Nuestro objetivo es entrar como «administrator» y eliminar al usuario «carlos». Al entrar nos encontramos con la estructura de una tienda online que, tras explorar, vemos que tiene un apartado de «My account», donde podemos iniciar sesión o indicar que hemos olvidado la contraseña. Una vez realizadas todas las acciones posibles, las exploramos en el […]

cyberhub.es
  • Política de Cookies

Todos los derechos reservados