webProeasy

YOFA 1.0

bug-makers

Task: Node.js/Express web app with JWT auth, admin panel, and provided source code containing leftover initialization script. Solution: grep source for hardcoded admin password in config/init-db.js, login as admin, access /admin/flag.

$ ls tags/ techniques/
source_code_grephardcoded_password_extractionadmin_login_with_leaked_credentials

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups