Difficulty
easy
Average duration
1 hrs
Technologies
PHP
HTML and CSS
cybersecurity
owasp-a03-injection
blue-team
threat-hunting
xss
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
HTML and CSS
cybersecurity
owasp-a03-injection
blue-team
threat-hunting
xss
In this lab, you will analyze a basic website for a software license store. An attacker has left an active vulnerability that allows JavaScript code to execute in the browser. Your mission as an analyst is to find the vulnerable file, identify the flaw, and validate your finding.
In this lab you will learn:
👉 This challenge uses the same virtual machine as the previous lab: Pwned! - Find the backdoor. If you already downloaded it, there's no need to do it again.
1 https://storage.googleapis.com/cybersecurity-machines/web-threats-lab.ova
student:4geeks-lab
, and open the website in your browser at:1 http://<ip_machine>/softwarelicenser/
SoftwareLicenser is an online store that sells digital licenses. Unknowingly, a developer left an active vulnerability in one of the site's forms. Your task is to find the absolute path of the vulnerable file, identify the exact point of failure, and validate it using validation.py.
1validate-xss
If correct, the challenge flag will be revealed:
1✅ Correct path! 2🎁 Flag: FLAG{EXAMPLE_FLAG}
Good luck, Analyst!
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
HTML and CSS
cybersecurity
owasp-a03-injection
blue-team
threat-hunting
xss
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
HTML and CSS
cybersecurity
owasp-a03-injection
blue-team
threat-hunting
xss
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
HTML and CSS
cybersecurity
owasp-a03-injection
blue-team
threat-hunting
xss
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
HTML and CSS
cybersecurity
owasp-a03-injection
blue-team
threat-hunting
xss
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
HTML and CSS
cybersecurity
owasp-a03-injection
blue-team
threat-hunting
xss
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
HTML and CSS
cybersecurity
owasp-a03-injection
blue-team
threat-hunting
xss