A deliberately vulnerable REST API written in C# with ASP.NET Core and Entity Framework Core: SSO cookie authentication bypass, insecure JWT usage, weak password reset, SSRF, privilege escalation, insecure deserialization, XXE and SQL injection.
Pas commencéDockercommit d9bc201x86_64 · aarch64Secret
Exploit the API flaws to escalate from a registered user to an administrator.
Le brief de ce lab se trouve dans son dépôt.