πŸ“Œ Info

This lab's administration interface has an authentication bypass vulnerability, but it is impractical to exploit without knowledge of a custom HTTP header used by the front-end.

Goal:

Hint:


image.png

image.png

ok this header will make me like local host user i will add in the request with endpoint β†’ /admin

X-Custom-IP-Authorization: 127.0.0.1

image.png