$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: Next.js infra-monitoring app whose JWT is signed in the browser with a hardcoded HMAC secret shipped in the client bundle. Solution: recover the secret 'SecretKey-CriticalOps-2025' from the login page chunk, forge an HS256 admin token, and read the flag from an admin-visible ticket via GET /api/tickets.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar