23.4 Lab: User ID controlled by request parameter with data leakage in redirect | 2023

This lab contains an access control vulnerability where sensitive information is leaked in the body of a redirect response. To solve the lab, obtain the API key for the user carlos and submit it as the solution | Karthikeyan Nagaraj

Karthikeyan Nagaraj
2 min readNov 17, 2023

Description

This lab contains an access control vulnerability where sensitive information is leaked in the body of a redirect response.

To solve the lab, obtain the API key for the user carlos and submit it as the solution.

You can log in to your own account using the following credentials: wiener:peter

Solution

  1. Log In to wiener Account
  2. Turn on Foxy Proxy and turn on the Intercept
  3. In the URL change the Username from wiener to carlos
  4. Capture that Request and send it to Repeater
  5. Now, send the Request, and in the Response, you can see that the API key carlos is disclosed

If you would like to support me so that I can create more free content — https://www.buymeacoffee.com/cyberw1ng

Thank you for Reading!

Happy Hacking ~

Author: Karthikeyan Nagaraj ~ Cyberw1ng

Telegram Channel for Ethical Hacking Dumps — https://t.me/ethicalhackingessentials

--

--

Karthikeyan Nagaraj

Security Researcher | Bug Hunter | Web Pentester | CTF Player | TryHackme Top 1% | AI Researcher | Blockchain Developer