-
Go to the lab and view
robots.txtby appending/robots.txtto the lab URL. Notice that theDisallowline discloses the path to the admin panel. -
In the URL bar, replace
/robots.txtwith/administrator-panelto load the admin panel. -
Delete
carlos.
Lab: Unprotected admin functionality
This lab has an unprotected admin panel.
Solve the lab by deleting the user carlos.