当前位置:网站首页>Tryhackme Christmas challenge 2021 advance of cyber 3-day1-idor vulnerability, insecure access control vulnerability
Tryhackme Christmas challenge 2021 advance of cyber 3-day1-idor vulnerability, insecure access control vulnerability
2022-07-01 09:51:00 【Full stack programmer webmaster】
Hello everyone , I meet you again , I'm your friend, Quan Jun .
List of articles
The first day
There is a problem with the cargo system , Let's find a way to repair !
IDOR Loophole What is it? ?
Insecure Direct Object Reference, Unsafe direct object reference , Is a privilege control vulnerability , Similar to ultra vires loopholes , That is, users access information they should not access , For example, I can only view my own information , But I can access other people's data by modifying some parameters .
Where it usually appears
Inquire about get request
post The value of the form
Users here id It's hidden , If modified , It may lead to arbitrary user password modification vulnerability
cookies
cookie Generally, some encrypted strings are used , However, some junior programmers may use some simple plaintext to transmit information
Take the following example , It can be modified by user_id To get information about other users
Challenge
On
The system has been tampered with , There's a problem ( Although I didn't see it hhhh
After a look, there are four function pages , The fourth is in line with the loophole we want to learn this time
Be able to see in url There are parameters in
Try to modify this value , Modify to 9 Found the person who tampered with the system
Click on Revert The button enables the system to recover
Challenging questions
1. seek santa The location of , according to user_id The changes found santa that will do
2. and 1 The same way of thinking
3. ditto
4. Just order it all user_id by 9 Of Revert You can recover flag
Publisher : Full stack programmer stack length , Reprint please indicate the source :https://javaforall.cn/131772.html Link to the original text :https://javaforall.cn
边栏推荐
- JS prototype trap
- Niuke monthly race 22 tree sub chain
- 我喜欢两个男人。。。
- Voice service notes
- 123. how to stop a thread?
- button按钮清除边框
- SQL 化是 ETL 增量生产的第一步,这样的架构的核心能力是什么?
- Error org apache. catalina. core. StandardContext. FilterStart start filter exception
- Unity tips for reducing the amount of code -- empty protection extension
- High precision factorial
猜你喜欢

华为帐号多端协同,打造美好互联生活

Flinkv1.13 implementation of financial anti fraud cases

Wechat emoticons are written into the judgment, and the OK and bomb you send may become "testimony in court"

一个悄然崛起的国产软件,低调又强大!

Hololens2 development -6-eyetracking and speech recognition

Live broadcast management project
![Clickhouse: Test on query speed of A-share minute data [Part 2]](/img/c8/42ba748d38546d3b0d2be9b33c5d0b.jpg)
Clickhouse: Test on query speed of A-share minute data [Part 2]

ESP8266 FreeRTOS开发环境搭建

Eat a rich woman's melon...

The stock position building rate of global funds and asset management reached a new low in 15 years
随机推荐
直播管理项目
Network counting 01 physical layer
一个悄然崛起的国产软件,低调又强大!
Eat a rich woman's melon...
Closure implementation iterator effect
121. thread scheduling: join() method and yield() method
122. Thread class thread method summary; Why is the thread start method start () not run ()?
华为帐号多端协同,打造美好互联生活
Hololens2 development -6-eyetracking and speech recognition
Dspic30f6014a LCD block display
Solution of EPS image blur by latex insertion
I like two men...
The market is relatively weak recently
High precision factorial
渗透常用工具-Goby
项目采购管理
mysql截取_mysql截取字符串的方法[通俗易懂]
【无标题】
Cortex M4 systick details
Tearful eyes, it's not easy to change jobs. Three rounds of interviews, four hours of soul torture