webProeasy
YOFA 1.0
bug-makers
Task: Node.js/Express web app with JWT auth, admin panel, and provided source code containing leftover initialization script. Solution: grep source for hardcoded admin password in config/init-db.js, login as admin, access /admin/flag.
$ ls tags/ techniques/
source_code_grephardcoded_password_extractionadmin_login_with_leaked_credentials
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]YOFA 2.0— bug-makers
- [web][Pro]Lanternfall— neurogrid
- [web][Pro]Object Master— hackerlab
- [web][Pro]Lab 12 — NewsGrid — JWT Algorithm Confusion— hackadvisor
- [web][Pro]Personal Blog— uoftctf2026