This lab’s email change feature contains a race condition that enables you to associate an arbitrary email address with your account. Someone with the address [email protected] has a pending invite to be an administrator for the site, but they have not yet created an account. Therefore, any user who successfully claims this address will automatically inherit admin privileges | Karthikeyan Nagaraj
This lab’s email change feature contains a race condition that enables you to associate an arbitrary email address with your account.
Someone with the address [email protected]
has a pending invite to be an administrator for the site, but they have not yet created an account. Therefore, any user who successfully claims this address will automatically inherit admin privileges.
To solve the lab:
- Identify a race condition that lets you claim an arbitrary email address.
- Change your email address to
[email protected]
. - Access the admin panel.
- Delete the user
carlos
You can log in to your own account with the following credentials: wiener:peter
.
You also have access to an email client, where you can view all emails sent to @exploit-<YOUR-EXPLOIT-SERVER-ID>.exploit-server.net
addresses.
- Log in to your Account with
wiener:peter
- Change the Email to
something@exploit-<YOUR-EXPLOIT-SERVER-ID>.exploit-server.net
addresses. - Capture the Above request and send it to the repeater 2 Times
- Change the email ID for one of the requests to
[email protected]
- Right-click, add the 2 requests to a Group, and send the Request in Parallel.
- Check your email client whether you have received an email that consists
[email protected].
- Click that link to change your mail, if not again send the parallel request to get the link.
- Then, navigate to My-Account, you can now able to see the Admin panel.
- Click on Admin Panel and delete the User Carlos to solve the Lab
A YouTube Channel for Cybersecurity Lab’s Poc and Write-ups
Telegram Channel for Free Ethical Hacking Dumps
Thank you for Reading!
Happy Ethical Hacking ~
Author: Karthikeyan Nagaraj ~ Cyberw1ng