webhard
OmniWatch (session replay)
HackTheBox
Task: a Varnish-fronted Zig and Flask application with CRLF injection, reflected XSS, LFI, JWT handling, and SQLi. Solution: poison the oracle cache to steal a moderator JWT, read the JWT secret via LFI, forge an admin token, insert its signature with stacked SQLi, and access the admin page.
$ ls tags/ techniques/
jwt_forgeryreflected_xsscrlf_header_injectionvarnish_cache_poisoningcookie_stealingstacked_sqlilfi_absolute_pathbot_timing
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub to get started.
$ssh [email protected]