Challenge - HTBank HackTheBox
by LOOOP - Saturday January 20, 2024 at 07:43 AM
#11
Parameter Pollution is really straight forward but how to bypass authentication?
xclow3n:xCl0w3n1337!! does not work
Reply
#12
(02-05-2024, 01:47 PM)Axura Wrote:
(02-02-2024, 06:53 PM)Steward Wrote: Parameter Pollution is really straight forward but how to bypass authentication?
xclow3n:xCl0w3n1337!! does not work

Tips: It's simpler than you thought. That's why it's `easy` level

Indeed, thank you, I missed the word "register" somehow and tried to bypass auth instead of just reg new user
Reply
#13
ye am passed, keywork:parameter pollution +hint Note about the amount reading handling function between python and php
Reply
#14
hint
Iterate the deposit amount and maybe try 1337
[Image: 65c24c1df7c1bf19720b2cf6.gif]
HackTheBox - 99% Done - Get any flags or pwn you need
https://xan6.mysellix.io/
Reply
#15
wtf am i doing wrong
Reply
#16
(01-23-2024, 11:32 AM)rat Wrote: it's super simple skid parameter pollution

 Can you give more hint please?
Reply
#17
(02-12-2024, 11:01 AM)am4na Wrote:
(01-23-2024, 11:32 AM)rat Wrote: it's super simple skid parameter pollution

 Can you give more hint please?

Research what is skid parameter pollution? You can also use tools such as mitm proxy with zaproxy. 

Also now the source code is included in the challenge. Try to understand what parameter to pollute, you can also use Burp if you want or script it out...
Reply
#18
(02-12-2024, 11:01 AM)am4na Wrote:
(01-23-2024, 11:32 AM)rat Wrote: it's super simple skid parameter pollution

 Can you give more hint please?

If you're still struggling to solve the challenge. You can watch the video here. https://youtu.be/QXypRX8eOfg
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 360 88,710 03-28-2026, 09:28 AM
Last Post: catsweet
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 16 2,276 03-28-2026, 03:32 AM
Last Post: lulaladrow
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 597 88,992 03-27-2026, 10:54 PM
Last Post: w3soul
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,490 03-27-2026, 07:22 PM
Last Post: stn
  All reversing challenge - HTB - Flags @ 02/03/2025 fr34cker 7 1,275 03-27-2026, 08:01 AM
Last Post: escowbang



 Users browsing this thread: 1 Guest(s)