webeasy

Login Problems

hackerlab

Task: a Flask/Werkzeug login page hides its authentication logic in a JSFuck-obfuscated frontend script. Solution: deobfuscate /static/hell.js, recover the hardcoded admin credentials, and log in as admin with the leaked password.

$ ls tags/ techniques/
javascript_deobfuscationclient_side_secret_extractionclient_side_auth_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]