Access control - Insecure Direct Object References
Objective: This lab stores user chat logs directly on the server’s file system, and retrieves them using static URLs. Solve the lab by finding the password for the user
carlos, and logging into their account.
This post is licensed under CC BY 4.0 by the author.





