All Writeups

Comprehensive collection of CTF challenges, solutions, and insights.


Filter by tag:

WHAMazon! JWT 2 - Forge

Exploiting the JWT 'none' algorithm vulnerability to forge an unsigned admin token without knowing the signing secret.

WHAMazon! JWT 1 - WHAM Token

Extracting a JWT signing key from a netcat service, forging an admin token with jwt.io, and submitting it to gain elevated access and retrieve the flag.