Malicious Web Traffic Analysis
Level: Medium
Challenge: Malicious Web Traffic Analysis
Q1: What is the IP address of the web server?

Q2: What is the IP address of the attacker?
Q3: The attacker first tried to sign up on the website, however, he found a vulnerability that he could read the source code with. What is the name of the vulnerability?


Q4: There was a note in the source code, what is it?


Q5: After exploiting the previous vulnerability, the attacker got a hint about a possible username. What is the username that the attacker found?

Q6: The attacker tried to brute-force the password of the possible username that he found. What is the password of that user?


Q9: Once the attacker gained admin access, they exploited another vulnerability that led the attacker to read internal files that were located on the server. What payload did the attacker use?


Q10: The attacker was able to view all the users on the server. What is the last user that was created on the server?

Q11: The attacker also found an open redirect vulnerability. What is the URL the attacker tested the exploit with?


Last updated
