Forum Discussion

wakedd's avatar
wakedd
Icon for Bronze II rankBronze II
23 days ago

Web App Hacking Lab

I am stuck on the last question of this lab.

Question 13 - Return to the /login page and log in as the admin of the site. What is the token you receive?

I have been trying to use OWASP ZAP but cant seem to figure it out.  Any help would be greatly appreciated.   Thanks.

 

  • TillyCorless's avatar
    TillyCorless
    Icon for Community Manager rankCommunity Manager

    Thanks wakedd

    I've passed on your query internally for a possible tip, however if in the meantime a fellow community member can offer any hints, please do!

  • TillyCorless's avatar
    TillyCorless
    Icon for Community Manager rankCommunity Manager

    Hi wakedd, can you share the full lab title with me please? I think you're referring to Intro to Web App Hacking: Dirbuster - Custom Headers, but can't be sure.

    Thanks!

    • wakedd's avatar
      wakedd
      Icon for Bronze II rankBronze II

      Intro to Web App Hacking: Mapping Web Applications

  • If it's 'Intro to Web App Hacking: Mapping Web Applications': I wonder how you solved the previous question: Did you just guess the solution in the answer box, or verified it?

    • wakedd's avatar
      wakedd
      Icon for Bronze II rankBronze II

      I actually looked at the robot.txt file and saw the /admin page listed in there

      • netcat's avatar
        netcat
        Icon for Silver I rankSilver I

        Aren't you curious to see what is forbidden for robots?