$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a Flask/Werkzeug site used an HS256 JWT in a cookie for authentication and stored the user's role directly inside the token. Solution: recover the weak signing secret, forge an admin token, and send it to /admin to escalate privileges and reveal the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar