Skills Assessment

  • Obtain the flag.

We can see a login panel and a option of create account -->

I try to create a account with the usename admin and with his passwords policy -->

admin : Ad3456789012

BUT! I have the name admin but not the privileges of admin ... this means that the admin user did not exist

okay, se that, eneumate users by error -->

If i set bad the password of us user (in this casea admin), get a error, do ffuf -->

AHA! gladys! DO BRUTE FORCE! Before that, maybe we should be shot the rockyou and the ffuz -->

OPAA! 2FA, np if i intercept it with burp i can see the parameter and it i can use intruto to do brute force:

BUTT! i see the rate limit of the app. After 3 unsuccessful tries, the page redirects back to the login.php

After intercept again the login peticion, i can see that the web, after i loging and otorgate the cookie, he response redirect me to /2fa.php, me question is... can i redirect me to profile.php direct and bypass the 2fa ??? -->

Apparently IT FOUND... but he get us 302 found... maybe change to 200 OK -->

HAHAHA NICE

Last updated