0xIncaInsider
HomeBlogArchivesTagsCollectionsAbout
← Writeups
·

Insecure direct object references

This lab stores user chat logs directly on the server's file system, and retrieves them using static URLs.

Solve the lab by finding the password for the user carlos, and logging into their account.


https://0a1b00c9041159f3820e974200cf0044.web-security-academy.net/

// 0xIncaInsider — offensive security research