webProeasy
Tokens
hackerlab
Task: Cryptocurrency platform with token-based authentication. Solution: Discovered tokens are SHA256(username) without salt, forged administrator token to access admin profile and retrieve flag.
$ ls tags/ techniques/
sha256cookie_manipulationtoken_forgeryweak_authenticationuser_enumerationpredictable_tokensinsecure_token_generation
Token analysis and hash identificationSHA256 token forgeryUser enumeration via token validation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [pwn][Pro]Хаос на АЗС (Chaos at the Gas Station)— hackerlab
- [web][Pro]Печеньки с молочком (Cookies with Milk)— duckerz
- [web][Pro]Microchip— hackerlab
- [web][Pro]Та самая заметка (That Same Note)— hackerlab
- [web][Pro]Провальный код (Failed Code)— hackerlab