Ad End 1 August 2025
Ad Ends 13 July 2025
ad End 25 October 2025
Ad Ends 20 April 2025
Ad expire at 5 August 2024
banner Expire 9 June 2025
banner Expire 25 October 2025
banner Expire 10 May 2025
What's new
Wizard's shop 2.0
Money Club cc shop
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
Yale Lodge
Kfc CLub
adv exp at 30 July 2025
Carding.pw carding forum
BidenCash Shop

Dark_Code_x

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 28, 2020
Messages
6,772
Reaction score
725
Points
212
Awards
2
  • Somebody Likes you
  • First post
The Vulnerability:

To restrict access to a specific page or file on the website, the page is returned completely to anyone who requests it but with a "302 Moved Temporarily" status and a Location header specifying an address to redirect to for unauthorized users or guests. The browser, being a good boy, immidietly follows the redirection to the location specified in the Location header before loading the contents of the page.

How to exploit it:

To let the browser load the contents of the page, we just need to intercept the response of the server and remove the Location header and voala!

- An example :
I will use burp suite .

First, we turn on intercept server response.


This is the response in burp proxy. You can see that the contents of the page are present in this response.


We remove the location header and forward the response to the browser.

The page is loaded in your browser! In this example, the page is a file management system.
 
Ad End 1 February 2024
Top