[/MNT/AIN LIB] [WEB] critical-integrity

Owww myy gaawwd, JWT trickery!

The challenge is to not login as guest, but login as admin and visit /admin.

There is a cookie set, which is a JWT

1771453601100-png.57



We can basically just change the user, to admin and encode it again:

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyIjoiYWRtaW4ifQ.lo6cc_YVMrNFnffGek_avzLJ_mgkuvBsSz52NO3_6Kk

1771453632866-png.58
View attachment 1771453632866.png

Then set it into our cookie and booom:

1771453647593-png.59


Flag received, ye obviously a beginner challenge but quiet cool to learn about JWT :)!!
 

Attachments

  • 1771453601100.png
    15.7 KB · Views: 2
  • 1771453647593.png
    10.9 KB · Views: 2
Back
Top