Abusing HTTP Misconfigurations

Abusing HTTP Misconfigurations Skills Assessment - Easy anyone to help me i can’t bypass the password reset function

++++++++++++++++++ please anyone to help me

Hi!
Did you follow it?

1 Like

okey i figured it out i am in hard skill assesment

1 Like

I’m stuck on the easy skills assessment. I don’t get your hint. I tried to open 2 tabs in Firefox (with and without Burb etc.) and tried all the possibilities. No success.

1 Like

For future people looking. You will need to login with the given account. There is somthing you can interact with on the site that will allow you to puzzle the session varible correctly :slight_smile:

2 Likes

I found several extra endpoints on the website and tried to use them, bypassing the default page. That is, I would complete the first step of reset or register, and then copy a non-default page url into the browser. However, this was to no luck and would go back to login. Was the useful thing on the signed-in version for the website not an endpoint?

K I figured it out. The advice on having two tabs open was good. A user must be logged in while the login forms are being manipulated.