Mass-assigning your way into an admin group
50 points · about 90 minutes · flag formatDC{...}Brief
Access control is the rule that a request may only touch what its owner is allowed to touch. When the id of a record travels in the URL, the body or a header, and the server trusts it without checking who is asking, one account can read or change another's data by editing that id.
This lab: Mass-assigning your way into an admin group. Reach an object that was never yours by changing the id that names it.
Work it against your own copy of the target. When you have the flag, submit it below.
Objective
Find a request that names a record by id, change the id to one you do not own, and retrieve or modify data that should be out of reach. Capture the flag the exposed record holds.
Sign in and join the Academy to submit a flag, take hints and track your progress.
Sign inWalkthrough
Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.