13.4.2
Review the source code for /users/invite. Determine why it cannot be exploited.
Read More
13.3.2
Expand the route_buster.py script to include PUT and PATCH methods.
Read More
13. Server Side Request Forgery

Read More
12.3 (P)
Since the Authorization header is allowed in the CORS requests, we would be able to send authenticated requests through a user's browser if we don't have network access to the application. Return t...
Read More
12.2.5
Using the shell, add a new user to Concord and authenticate as the new user.
Read More
12. Concord Authentication Bypass to RCE
=============================================================
Read More