Lab 2 Access Controls

 

Like usual I start by opening the page and seeing what it has to offer in terms of any vulnerabilities.

I then go to robots.txt because it often has information about admin pages that could be found. If it not found there then I would probably try to brute force the admin pages.


In the robots.txt I found that they don’t want crawlers on the /administrator-panel. This is an admin panel that a normal user might not have access to. But it is always good to try in case the website doesn’t have any verification or security when it comes to accessing unauthorized pages.


The page is not checking to see if I am authorized to access the page as such it gives me full admin access right away.


I then deleted the user without ever having to sign in or have any type of admin authorization.

Comments

Popular posts from this blog

Vulnerability Management(Nessus)

Active Directory Home Lab

TightVNC and Colasoft Packet Builder Lab