This lab's administration interface has an authentication bypass vulnerability, but it is impractical to exploit without knowledge of a custom HTTP header used by the front-end.
Goal:
carlos.Hint:
You can log in with the following credentials:
wiener:peter

ip local host and put in the request π
ok this header will make me like local host user i will add in the request with endpoint β /admin
X-Custom-IP-Authorization: 127.0.0.1

carlos user