webProeasy
Object Master
hackerlab
Task: Node.js/Express app with custom Storage class and JWT authentication, need to access admin panel. Solution: Prototype Pollution via __proto__ key in merge function to set isAdmin=true and bypass authentication check.
$ ls tags/ techniques/
Prototype Pollution via recursive merge functionAuthentication bypass via polluted prototypeJWT token-based session management
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Personal Blog— uoftctf2026
- [web][Pro]board_of_secrets— miptctf
- [web][free]AgriWeb— hackthebox
- [web][Pro]Lab 303 — DevGateway — Broken Access Control in Admin API— hackadvisor
- [web][Pro]Провальный код (Failed Code)— hackerlab