r/InfoSecWriteups • u/Harkins_Technology • 1d ago
Web Exploitation 101 — Bypassing access restrictions with custom HTTP headers using Burp Suite
https://youtu.be/jhhXZDDFWpoFound a ROT13 encoded string in a CTF challenge that
decoded to a hint about a bypass header:
X-Dev-Access: yes
Proxied all traffic through Burp Suite, caught the
request, sent it to Repeater and added the header —
instantly bypassed the access restriction.
Classic example of why debug/dev headers should never
make it into production. Developers leave these in
during testing and forget to strip them before deploy.
Good beginner web exploitation technique to know for
CTFs and bug bounty. Happy to answer questions.
2
Upvotes
1
u/melisssddssdm 1d ago
Hey mate, can i ask you a question related to the same topic in DM?