About
In this module of the Web Security Researcher learning path, Enterprise Web Hacking starts after Junior Pentester WAPT. You move from scanner-driven OWASP Top 10 findings into business-logic and trust-boundary failures that appear in enterprise APIs and their companion web portals. You work against a Ciberbots enterprise service that issues analyst tokens, tracks purchase-state transitions, exposes a GraphQL user query surface, and pairs those APIs with a cookie-backed employee profile portal reviewed by an internal administrator. You authenticate as a low-privilege analyst, abuse HTTP parameter pollution to force a finance approval transition, introspect GraphQL to read a cross-tenant executive secret, then pivot to the web portal with developer test credentials, plant stored XSS in a profile display name, and chain it to a CSRF credential change that yields administrator access. Upon completion of the module, students will be able to: - Abuse multi-value query parameters when a workflow reads the last actor instead of the authenticated role. - Use GraphQL introspection and object-id queries to prove broken object-level authorization (BOLA). - Chain stored XSS to same-origin authenticated actions when CSRF defenses and reauthentication are missing. - Map each finding to a concrete OWASP ASVS control and WSTG identifier for enterprise reporting. For inquiries, please write us at https://www.darkrelay.com/cybersecurity-course-inquiry
Overview
Acceptable Usage Policy
.1 step
Lab Access
.1 step
HTTP Parameter Pollution (HPP)
.5 steps