DEV Community

Discussion on: Hacker101 CTF - Micro-CMS v2

Collapse
 
bharatt13770141 profile image
Bharat_Thapa.php • Edited

on flag 1 what was the hint about? what does it mean by saying "What actions could you perform as a regular user on the last level, which you can't now?"

Collapse
 
caffiendkitten profile image
DaNeil C

I assumed that it was talking about how a regular users can only view pages but an admin can edit them and that is why the flag is on /page/edit/2.

Collapse
 
danbradster profile image
danbradster

It's saying that logged out users should not be able to edit pages, but in fact, if you can simulate the right POST request, it'll still go through, even when logged out.