http://nihilhfjmj55gfbleupwl2ub7lvbhq4kkoioatiopahfqwkcnglsawyd.onion/HTB/Medium/47.html
The only difference being,
when we examine the network side of the webpage (F12, network, asc status codes) we see an interesting url which is /api/Account From here we are heavily hinted towards a json application running on .NET, if we inspect this /api/Account URL further, causing an error onto the Bearer header,
we are able to get hinted towards a de-serialization attack vector for the initial foothold. The trick here was to mess around with the Bearer parameter of the
request being...