Referer-based access control | Apprentice
We are given the option to try out admin perms for ourselves. When we try to upgrade carlos credentials, we can intercept the request and see what’s behind the scene:
Unlike the previous labs, the request to elevate one’s credentials is simply a GET request. If the web app accepts Referer arbitrarily, we can simply change the session cookie to ours and solve the lab.