Hintru ENES ← All labs
✎

Improve lab

Improved version of Tanuki: Flashcard Backup Restore

You are creating a new version of this lab. The original stays untouched. Your version will be signed by a cryptographic key generated in your browser β€” no email, no password. If you clear browser data without exporting your identity, you lose authorship over your contributions.

You do not have a signing identity yet in this browser.
1
Map the API from the client bundle
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

2
Authenticate and export a deck
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

3
Probe the restore endpoint's accepted format
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

4
Confirm that JSON field values are parsed as XML
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

5
Locate the JSON field injected into the DOCTYPE internal subset
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

6
Identify the correct file path past the decoys
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

7
Execute the full in-band file read and retrieve the flag
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.