webmedium

Веб-центр (Web Center)

hl_hacker

Task: Web application with JWT authentication, login requires only username. Solution: Brute-force weak HS256 JWT secret with hashcat, forge admin token for role escalation.

$ ls tags/ techniques/
JWT HS256 secret brute-force with hashcatJWT token forgery with discovered secretRole escalation via payload manipulation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]