This is a write-up of of PortSwigger Academy’s “user ID controlled by request parameter with data leakage in redirect” lab.
You’ll need a Portswigger Academy account before you get started.
This is a walkthrough of PortSwigger Academy’s “user role can be modified in user profile” lab. You’ll need Burp Suite installed for this walkthrough (see instructions here).
You’ll also need
This blog post is for the first Apprentice-level “user role” lab within Portswigger’s Access Control lab category.
Before we get started, you’ll need a Portswigger Academy account. Log in and
This post covers the “no defenses” CSRF lab from PortSwigger. This lab is the only Apprentice-level lab within the OS command injection category. Before we get started, you’ll need a Portswigger