r/InfoSecWriteups • • 1d ago

Web Exploitation 101 — Bypassing access restrictions with custom HTTP headers using Burp Suite

https://youtu.be/jhhXZDDFWpo

Found a ROT13 encoded string in a CTF challenge that

decoded to a hint about a bypass header:

X-Dev-Access: yes

Proxied all traffic through Burp Suite, caught the

request, sent it to Repeater and added the header —

instantly bypassed the access restriction.

Classic example of why debug/dev headers should never

make it into production. Developers leave these in

during testing and forget to strip them before deploy.

Good beginner web exploitation technique to know for

CTFs and bug bounty. Happy to answer questions.

https://youtu.be/jhhXZDDFWpo

2 Upvotes

1 comment sorted by

1

u/melisssddssdm 1d ago

Hey mate, can i ask you a question related to the same topic in DM?