Web Application Security
The app authenticates with a JWT whose verification accepts the none algorithm. Forge a token with admin: true to access the admin area and read the flag.
loading simulatorβ¦
A bank app changes the account email via a state-changing GET/POST with no CSRF token. Craft a malicious page that, when the logged-in victim opens it, changes their email β the 'admin bot' victim then reveals the flag.
loading simulatorβ¦