$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Flask app with JWT authentication, source code provided. Solution: JWT None Algorithm Attack - the jwt.decode() allows 'none' algorithm and has verify_signature=False, enabling token forgery with admin privileges.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar