SGSajan Ghimireinsajanghimire.hashnode.devยทMar 21, 2025 ยท 4 min read2FA broken logicThis lab's two-factor authentication is vulnerable due to its flawed logic. To solve the lab, access Carlos's account page. Your credentials: wiener:peter Victim's username: carlos Analysis: Step 1: Observing the Authentication Process The first...00
SGSajan Ghimireinsajanghimire.hashnode.devยทMar 20, 2025 ยท 3 min readExploiting Business Logic: Bypassing Client-Side Controls to Manipulate PricingStep 1: Log in to the Application Open the lab in your browser. Log in using the provided credentials: Username: wiener Password: peter Navigate to the product page and locate the "Lightweight l33t leather jacket". Step 2: Add the Jacket to...00