Unprotected admin functionality
Unprotected admin functionality
Unprotected functionality refers to a scenario where sensitive features of an application lack adequate protection, allowing users to access administrative functions through direct URL manipulation or brute-force tactics, regardless of their intended user roles or permissions.
Visit and complete the original lab on PortSwigger's website
New to Burp Suite? Learn how to set up Burp Suite for the first time.
LAB
This lab has an unprotected admin panel.
Solve the lab by deleting the user carlos.
Steps to solve the LAB:
Start the Lab:
Start the lab by navigating to the provided URL.
Exploring Robots.txt:
Once the lab is open, add "/robots.txt" to the URL in the browser address bar. This file often reveals hidden directories or files that are not indexed by search engines.
3. Identifying Administrator Panel:
Upon viewing the robots.txt file, you may notice a reference to an "Administrator-panel". This indicates the presence of an administrative area within the application.
4. Accessing the Admin Panel:
Now, append "/Administrator-panel" to the URL in the browser address bar and navigate to this location. By doing so, you gain access to the administrative panel of the application.
5. Taking Action:
Within the admin panel, you may find various functionalities, including user management. Use this access to locate and delete the user named "Carlos", as instructed by the lab requirements.
6. Completion:
Congratulations! By successfully accessing the admin panel and performing the required action of deleting the user "Carlos", you have solved the lab. Take note of the techniques used and the importance of securing administrative functionalities to prevent unauthorized access in real-world scenarios.