当前位置:网站首页>Solution to the problem of breakthrough in OWASP juice shop shooting range
Solution to the problem of breakthrough in OWASP juice shop shooting range
2022-07-06 07:07:00 【smarthome_ man】
1、 Find hidden scoreboard
/#/score-board Will jump directly to the scoreboard
2、 Log in to the administrator account
Here you can try to use sql Enter the administrator interface by injecting
1、 No account number , No password to enter
’ or 0=0 –
2、 Have an account , No password to enter
**[email protected]'--**
3、xss attack
Enter in the search box <iframe src=“javascript:alert(xss
)”>
4、 Log in to the administrator interface , And don't report mistakes
stay url Input administration that will do
5、 To the store ⼀ A devastating sporadic feedback
Modify page code , Delete disabled that will do
6、 Register as ⽤ Household
1. Use fiddler The packet capturing tool captures the registered user's packet
2. Catch /api/Users Submit a request
3. add to “role”:“admin” jurisdiction
7、 Delete all 5 Star customer feedback
Enter the hidden administrator interface and enter /administration
Delete the five-star comment
8、 Make your order rich
utilize fiddler Tools , Grab the bag of goods in the shopping cart , Change the quantity of goods to a negative number , Send a request , Just finish shopping
9、 See more ⽤ Household shopping cart
1、 utilize fiddler Caught tools , Grab the shopping cart id, Then put the shopping cart id Change to other users id, Send a request
10、 Find the picture of the cat ⽚ Concurrent display ⽰
11、 send ⽤ The administrator's ⽤ Login with user credentials , Violent ⼒ Crack
12、 With other ⽤ Account name release ⼀ Some feedback
adopt fiddler Caught tools , Catch the feedback package , Then modify the user id, Just send
13、 With other ⽤ Household ⾝ Published product reviews or editors
whatever ⽤ Existing comments of users
adopt fiddler Caught tools , Catch the bag of comments , Then modify the user name , Just send
14、 Frequent sending Can I have a coupon code? Get excellent
benefit !
Brute force cracking
15、 Uploading is not .pdf or .zip Extended name ⽂ Pieces of ,
xml
Find... In the front-end code
You can modify it.
16、 Upload ⼤ On 100 kB Of ⽂ Pieces of , Other types
17、Nosql notes ⼊- Update multiple product reviews at the same time
18、 modify bender⽤ The password of the user - Don't make ⽤ notes ⼊ Of ⽅
type
1、 Login with universal password bender user
2、 Use the packet capture tool to grab the packet that changes the password
3、 Delete the original password url And send it
19、 Put other products ⼊ another ⼀ individual ⽤ Household shopping basket
20、 change OWASP SSL⾼ Level evidence ⼯ have (O-Saft) in
Of the link href by https://owasp.slack.com
边栏推荐
- 【服务器数据恢复】IBM服务器raid5两块硬盘离线数据恢复案例
- Latex文字加颜色的三种办法
- Uncaught typeerror: cannot red properties of undefined (reading 'beforeeach') solution
- Establishment and operation of cloud platform open source project environment
- The best way to learn SEO: search engine
- 首发织梦百度推送插件全自动收录优化seo收录模块
- 中青看点阅读新闻
- librosa音频处理教程
- leetcode59. 螺旋矩阵 II(中等)
- Raspberry pie serial port login and SSH login methods
猜你喜欢
[server data recovery] case of offline data recovery of two hard disks of IBM server RAID5
At the age of 26, I changed my career from finance to software testing. After four years of precipitation, I have been a 25K Test Development Engineer
Raspberry pie serial port login and SSH login methods
Babbitt | metauniverse daily must read: the group image of Chinese Internet enterprises pouring into metauniverse: "there are only various survival desires, and there is no ambition for forward-lookin
What is the biggest problem that fresh e-commerce is difficult to do now
Proteus -- Serial Communication parity flag mode
Leetcode59. spiral matrix II (medium)
作者已死?AI正用艺术征服人类
First knowledge of OpenGL es learning (1)
ROS learning_ Basics
随机推荐
GET 和 POST 请求类型的区别
PCL实现选框裁剪点云
呆错图床系统源码图片CDN加速与破解防盗链功能
Depth residual network
WPF之MVVM
Refer to how customer push e-commerce does content operation
简单描述 MySQL 中,索引,主键,唯一索引,联合索引 的区别,对数据库的性能有什么影响(从读写两方面)
【JDBC】快速入门教程
UWA pipeline version 2.2.1 update instructions
How to reconstruct the class explosion caused by m*n strategies?
How are the open source Netease cloud music API projects implemented?
Three methods of adding color to latex text
The ECU of 21 Audi q5l 45tfsi brushes is upgraded to master special adjustment, and the horsepower is safely and stably increased to 305 horsepower
leetcode841. 钥匙和房间(中等)
Arduino tutorial - Simon games
Practical guidance for interface automation testing (Part I): what preparations should be made for interface automation
leetcode59. 螺旋矩阵 II(中等)
Embed UE4 program into QT interface display
Wechat official account infinite callback authorization system source code, launched in the whole network
How to find a medical software testing institution? First flight software evaluation is an expert