CySCA 2015 - Web Application Pentest 3 - Love Letters
November 19, 2015 • nickw
Note: If you're interested in actually doing these challenges, check out this post on
how to get the environment set up.
Now that we’re logged in, lets take a poke around and see what we’re dealing with. There appears to be sections to:
- Apply for leave, where we submit a text request. Maybe XSS or Injection on this?
- Staff Directory, details about different staff members.
- The “Network Administrator” has some binary in his profile. We’ll decode that later.
- There seems to also be a message board. Maybe XSS or Injection.
- There’s also a mail inbox.