Simon McCabe

OSCP · OSWP · PWPP · PWPA · PAPA · EnCE · Linux+ · LPIC-1 · Network+ · Security+ · Pentest+ · eJPT · eWPT · BSc · PGCert

Joystick (Websockets)


Lab can be found at: https://webverselabs-pro.com/

Quick and straightforward one today!

First, begin by registering, logging in and getting familiar with the page:

Make an order by going to one of the tabs along the top, selecting an item and checking out. After you’ve done this, go into your account area and look at your recent orders. Click “Track” (middle-right of pic):

Here you’ll notice websocket activity. Send to repeater:

Change the order id to 1 and hit send. You’ll be able to see an order that was placed by another registered user and the download_key will contain the flag:

Thanks for following along!

LinkedIn X YouTube GitHub