$ cat writeup.md…
$ cat writeup.md…
cryptohack
Task: a CryptoHack JWT challenge issues and verifies HS256 tokens, with the flag gated behind admin:true; source comment hints the secret is the PyJWT readme example key. Solution: guess the default HS256 secret 'secret', forge a token with admin:true, and submit it to the authorise endpoint to recover the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar