Category: (e.g., Web, Pwn, Forensics, Crypto, OSINT…)
Difficulty: (Easy/Medium/Hard)
Challenge Description / Prompt:
The endpoint improperly validated JWTs, allowing us to forge a token by modifying the algorithm field to "none", granting admin access.
strings, Wireshark, CyberChef)nmap)dirsearch, nikto)id parametergets() is used without bounds checking