URL: https://lab12.sqrsec.com/

Difficulty: Medium

Notes:

  1. No password/account bruteforce is needed!

  2. XSS is out of scope

  3. Only the web interface port 443 is in-scope

Objective

  1. Use the Hacker Browser to retrieve the flag

  2. Flag format is UUID