Padelify — TryHackMe

A padel-tournament portal behind a deny-list ModSecurity WAF falls to a three-step chain: a User-Agent header bypass, a stored XSS that steals a moderator bot’s session cookie, and an LFI that leaks admin creds via full per-character URL-encoding.

June 8, 2026 · 18 min · 3660 words · Th3B0yWh0L1v3d