Forum Discussion

wakedd's avatar
wakedd
Icon for Bronze II rankBronze II
4 months ago

Web App Hacking Lab

I am stuck on the last question of this lab.

Question 13 - Return to the /login page and log in as the admin of the site. What is the token you receive?

I have been trying to use OWASP ZAP but cant seem to figure it out.  Any help would be greatly appreciated.   Thanks.

 

9 Replies

  • If it's 'Intro to Web App Hacking: Mapping Web Applications': I wonder how you solved the previous question: Did you just guess the solution in the answer box, or verified it?

    • JDeVillar's avatar
      JDeVillar
      New Member I

      I saw that admin was mentioned in the Briefing so I  used that

       

    • wakedd's avatar
      wakedd
      Icon for Bronze II rankBronze II

      I actually looked at the robot.txt file and saw the /admin page listed in there

      • netcat's avatar
        netcat
        Icon for Silver II rankSilver II

        Aren't you curious to see what is forbidden for robots?

  • TillyCorless's avatar
    TillyCorless
    Icon for Community Manager rankCommunity Manager

    Thanks wakedd

    I've passed on your query internally for a possible tip, however if in the meantime a fellow community member can offer any hints, please do!

    • JDeVillar's avatar
      JDeVillar
      New Member I

      Is there any answer for this one?  TillyCorless​ ??

      i have to complete this course and cannot log in as Admin and there is no instruction for how to 

       

  • TillyCorless's avatar
    TillyCorless
    Icon for Community Manager rankCommunity Manager

    Hi wakedd, can you share the full lab title with me please? I think you're referring to Intro to Web App Hacking: Dirbuster - Custom Headers, but can't be sure.

    Thanks!

    • wakedd's avatar
      wakedd
      Icon for Bronze II rankBronze II

      Intro to Web App Hacking: Mapping Web Applications