Xpath
Dojo #4
by YesWeHack
drag_indicator
drag_indicator
drag_indicator
Obfuscated code
The admin love to use obfuscated queries, but you want to prove him that security through obscurity is not failproof.
We know that a valid serial number is in the form 0000-0000-0000-0000
There is 7 valid serial for this XPATH query
BRUTEFORCE IS NOT ALLOWED
Goal
- Find the 7
$serial
that outputAccess granted!
- Submit your writeup report to the program, including details on how you reversed the code.
Hints
drag_indicator
INPUT
OUTPUT
drag_indicator
drag_indicator