-
Go to the lab and view
robots.txt
by appending/robots.txt
to the lab URL. Notice that theDisallow
line discloses the path to the admin panel. -
In the URL bar, replace
/robots.txt
with/administrator-panel
to load the admin panel. -
Delete
carlos
.
Lab: Unprotected admin functionality
This lab has an unprotected admin panel.
Solve the lab by deleting the user carlos
.