SESSION SECURITY

OBJECTIVE: execute a web assessment by following the below ROE from a bug bounty program.

  • The only URL in scope is "http://minilab.htb.net"

  • Attacking end-users through client-side attacks is in scope for this particular bug bounty program.

  • Test account credentials:

    • Email: heavycat106

    • Password: rocknrol

  • Through dirbusting, you identified the following endpoint "http://minilab.htb.net/submit-solution"

Read the flag residing in the admin's public profile. Answer format: [string]

Go through the PCAP file residing in the admin's public profile and identify the flag. Answer format: FLAG{string}

Last updated