// Breach the Portal
A live, genuinely vulnerable employee login page — find the flaw and read data you shouldn't be able to.
// Target
// Your Toolbox
// Situation
A small internal tool for the campus IT team leaked its login URL. It's a basic username/password form — nothing fancy. Nothing about the page itself hints at a problem. Start by taking a look at what actually shipped in it.
// The Challenges
Read Between the Lines
Developers leave things behind in HTML comments they forget are visible to anyone who looks — view the portal's page source and see what turns up.
Target file: /lab/web-exploitation-portal (page source)Bypass the Login
You don't have a valid password for any account — you're not supposed to. Get past the login anyway, land in the administrator's account, and read what's sitting in their notes.
Broken Trust
The login form isn't the only way in. Something else this app does trusts you without ever really checking who you are.
None the Wiser
There's a "Remember Me" feature now too, and it hands out tokens to anyone who asks. Not every token that looks signed actually gets checked.