$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: VaultKeeper enterprise secrets management platform uses RS256 JWT authentication with exposed public key. Solution: JWT Algorithm Confusion attack (CVE-2016-10555) — changed alg from RS256 to HS256 and signed with the RSA public key as HMAC secret to forge admin token.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar