Question: Part 2 : All Your Credentials ( 0 2 completed ) Your team is participating in a challenge to see how easy it can be
Part : All Your Credentials completed
Your team is participating in a challenge to see how easy it can be to use SQL
injections to find the account information for all users on the Juice Shop web
application. Unfortunately, data breaches involving large batches of user information
are fairly common. Your team is doing this as an exercise to determine key
considerations in preventing large data breaches like this.
Your challenge is to retrieve a list of all users' email addresses and their roles by
using SQL exploitations that you learned in Parts and :
You must use Burp's Repeater to send one or more requests that will retrieve all
of the users' email addresses as well as their roles at the Juice Shop.
You cannot interact directly with the website in the Burp browser.
Make a screen captureshowing the modified search in the Request panel and
the JSON results with the user account information of a user whose role is
deluxe in the Response panel.
Document an explanationfor why the JSON object with the results in the
Response pane shows id name, description, price, etc., instead of email, role,
etc.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
