Access Control
Medium · IDOR

Hashed IDs Are Still IDs

A legacy SecureLearn integration hides numeric student IDs by placing an MD5 digest in the profile URL. The development team treats the digest as an authorization control. Test whether predictable hashing changes who the server allows you to access.

Objective

Derive another student's MD5-based profile key, access the record, and recover the flag.

Target

SecureLearn

Usernamestudent1
Passwordstudent123
Launch target

Submit flag