webeasy

Object Master

hackerlab

Task: Node.js/Express app with custom Storage class and JWT authentication, need to access admin panel. Solution: Prototype Pollution via __proto__ key in merge function to set isAdmin=true and bypass authentication check.

$ ls tags/ techniques/
Prototype Pollution via recursive merge functionAuthentication bypass via polluted prototypeJWT token-based session management

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]