webeasy
Tokens
hackerlab
Task: Cryptocurrency platform with token-based authentication. Solution: Discovered tokens are SHA256(username) without salt, forged administrator token to access admin profile and retrieve flag.
$ ls tags/ techniques/
sha256cookie_manipulationtoken_forgeryweak_authenticationuser_enumerationpredictable_tokensinsecure_token_generation
Token analysis and hash identificationSHA256 token forgeryUser enumeration via token validation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]