πŸ›‘οΈ Security Lab Track A Β· Web Application Security Β· Stage 7

Track A Β· Stage 7

Web Application Security

Weak JWT β€” alg=none / forgery mediumnot started

The app authenticates with a JWT whose verification accepts the none algorithm. Forge a token with admin: true to access the admin area and read the flag.

loading simulator…

Cross-Site Request Forgery mediumnot started

A bank app changes the account email via a state-changing GET/POST with no CSRF token. Craft a malicious page that, when the logged-in victim opens it, changes their email β€” the 'admin bot' victim then reveals the flag.

loading simulator…