Info πŸ“Œ

This lab stores user chat logs directly on the server's file system, and retrieves them using static URLs.

🎯 Goal:

Solve the lab by finding the password for the userΒ carlos, and logging into their account.


  1. The lab is idor the idea of this lab we will talk to the about after login with wiener : peter
  2. Start your proxy/interceptor (Burp, OWASP ZAP, or similar) and enable interception. πŸ•΅οΈβ€β™‚οΈ
  3. Start a chat or send a message so the transcript is created. πŸ’¬
  4. Click View transcript β€” a file will be downloaded πŸ“₯

image.png

i notice important thig from first time i pressed on view transcript it download 2(1).txt

why ??

why not 1 ??? for me

it’s indicate me there’s another one talk this chatbot and download it

we need to try to check about talking let’s send this request to burp suite and change form 2 β†’ 1

image.png

ooh we go the chat and in chat content we go the password

vjjsjpyrte1b3hg5wsi3 β†’ password