imagine we have this website

Untitled

now let’s intercept the request

Untitled

now let’s try to change the host header to the IP

Untitled

and as we see we go 403 forbidden

now let’s try to supply the challenge url to the GET and see what will happen

Untitled

as we see we bypassed the restriction

Untitled

as we see we go redirect to the admin page

Untitled

now let’s see the response in browser

Untitled

now let’s intercept the request

Untitled

Untitled

and we solved the lab