raymond-devries / mlh-batch-1-ctf-writeups

This is a central repository for accumulating all the write-ups relating to the CTF put on for batch 1 MLH fellows.
10 stars 2 forks source link

Mr. MLH #34

Open raymond-devries opened 3 years ago

raymond-devries commented 3 years ago

Swift and Will have been working really hard to create a new security system for the MLH website, and now they've come up with this access system called "Mr. MLH". In this system, each user is determined by their User-Agent and every user has a hash code associated with them, and only one user is our "Mr. MLH" and has admin access.

They asked you, our security specialist hero, to help out testing to see if there are any flaws on the new system.

Access the website at 35.223.35.180:4000

Note: MLH User-Agents are all lowercase letters only