> For the complete documentation index, see [llms.txt](https://kunalwalavalkar.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kunalwalavalkar.gitbook.io/write-ups/portswigger-labs/server-side-topics/information-disclosure/authentication-bypass-via-information-disclosure.md).

# Authentication bypass via information disclosure

https\://portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-authentication-bypass

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2F9BREdzwvRiRLRa2UyXeZ%2F1.png?alt=media&amp;token=e6bf6b67-14d6-4af4-9e43-f2e97a7bf383" alt=""><figcaption></figcaption></figure>

Let's login using the following credentials:

| Username | Password |
| -------- | -------- |
| wiener   | peter    |

Once we have logged in, we can try to access the `/admin` page.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FvMRtZvdL8iNaoaP8XnYg%2F3.png?alt=media&amp;token=ac1e7950-e0bd-44ee-b5cb-eb475fbcbc98" alt=""><figcaption></figcaption></figure>

As we can see the admin panel is only accessible to local users. Since we are proxying the request through Burp Suite, we will be able to see the request in the `Proxy > HTTP History` tab.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FfQd0ejEnMwG5Vygf7ZzF%2F4.png?alt=media&amp;token=1c7e6d31-4e8e-47d2-a4e6-9227df259beb" alt=""><figcaption></figcaption></figure>

Let's forward this request to the `Repeater` for further modification. Once in the `Repeater`, let's modify the method to TRACE and send the request.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2Fzut11irusFVOWMEOKqAz%2F5.png?alt=media&amp;token=7ce64938-c323-4b5a-a6bd-870c15ae5a3f" alt=""><figcaption></figcaption></figure>

In the response, the returns contains the `X-Custom-IP-Authorization` header which is set to our IP address. Let's go into the `Proxy settings` tab.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2F6gb2Yl3FDt2TuSlSNRt5%2F6.png?alt=media&amp;token=1a99d81a-21f8-4872-a831-621a36dd15db" alt=""><figcaption></figcaption></figure>

Next we have to scroll down to `Match and Replace` and click `Add`. Inside the `Replace` field, paste the following:

```
X-Custom-IP-Authorization: 127.0.0.1
```

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FmwUhqkt3If9DvIMGn8PW%2F7.png?alt=media&amp;token=9b65de39-1e17-4617-9272-6bd1c7595af8" alt=""><figcaption></figcaption></figure>

This header will now be added to every request that we send. Therefore, we will be treated as local users and will have access to the admin panel.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FfJUkGaXdA92gToW6BgzB%2F8.png?alt=media&amp;token=61f2fbbc-28fa-4aaf-a4fd-1d230fac5955" alt=""><figcaption></figcaption></figure>

Let's go inside and delete the `carlos` user.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FnvKblVuIJJ2CohY78CpC%2F10.png?alt=media&amp;token=eac62c05-5f48-4ead-bbd7-4a2611b3505b" alt=""><figcaption></figcaption></figure>

We have solved the lab.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FgkTvNHuo2thW7VRcWeaA%2F11.png?alt=media&amp;token=7dd086d4-09e2-4be7-92a2-0360c6867d0b" alt=""><figcaption></figcaption></figure>
