Inconsistent handling of exceptional input
This lab does not adequately validate user input. You can exploit a logic flaw in its account registration process to gain access to administrative functionality.
While proxying traffic through Burp, open the lab and go to the Target -> Site map tab. Right-click on the lab domain and select Engagement tools -> Discover content to open the content discovery tool.
Click Session is not running to start the content discovery. After a short while, look at the Site map tab in the dialog. Notice that it discovered the path
Try to browse to
/admin. Although you don’t have access, an error message indicates that
Go to the account registration page. Notice the message telling
DontWannaCryemployees to use their company email address.
From the button in the lab banner, open the email client. Make a note of the unique ID in the domain name for your email server (
Go back to the lab and register with an exceptionally long email address in the format:
very-long-string should be at least 200 characters long.
Go to the email client and notice that you have received a confirmation email. Click the link to complete the registration process.
Log in and go to the My account page. The email address has been truncated to
Log out and go back to the account registration page.
Register a new account with another long email address, but this time include
dontwannacry.comas a subdomain in the email address:
Make sure that the
very-long-string is the right number of characters so that the “m” at the end of
@dontwannacry.com is character
Go to the email client and click the link in the confirmation email that you have received. Log in to your new account and notice that you now have access to the admin panel. The confirmation email was successfully sent to your email client, but the application server truncated the address associated with your account to 255 characters. As a result, you have been able to register with what appears to be a valid
@dontwannacry.comaddress. You can confirm this from the My account page.
Go to the admin panel and delete Carlos to solve the lab.
An attacker will need to access the admin panel and delete Carlos.