I have become admin, manipulator of users
Process:
It was a page with Username (prefilled) and Password fields.
data:image/s3,"s3://crabby-images/b4a3e/b4a3e0e368cef3081f293b01f67f6b45660bcd64" alt=""
Entering any password and submitting. It shows a button to reset the password. But it also had a hidden field username.
data:image/s3,"s3://crabby-images/d5afa/d5afa049bb6df596534d27e7e8d33580d9342f76" alt=""
Click on Request Reset button and it sends a request to server with your username in POST data. It returns the password in response as a hidden input field.
Ek taraf se username daalo, dusri taraf se password nikalo.
Solution:
Intercept this request and change the username to admin. It will give admin’s new password.
data:image/s3,"s3://crabby-images/f672a/f672abb8df5a18899521d2398502cb08e5d991c9" alt=""
Now again submit the login form with username admin and password you got from response.
And we got the flag!
data:image/s3,"s3://crabby-images/c8a95/c8a95dd60610e61e638ec38e71213c0b7c1cdc81" alt=""
Leave a Reply