0x13 - Lab 13
URL: https://lab13.sqrsec.com/
Difficulty: Medium
Login: wally:wally
Notes:
No password/account bruteforce is needed!
XSS is out of scope
Only the web interface port 443 is in-scope
Objective
Trick the app and buy the flag without paying!
The flags are in a format similar to
SqrSec Flag : UUID