$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: bypass JWT authentication on a FastAPI application to gain admin access. Solution: exploit JWT algorithm confusion (CVE-2016-10555) by switching from RS256 to HS256 and signing with the public key, which the server uses as the HMAC secret.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar