Video walkthrough for "Bug Report Repo", a web challenge I made for the @intigriti 1337UP LIVE CTF 2023. The challenge had multiple parts; first you need to use an IDOR to find a hidden bug report from ethical_hacker. Next, you exploit SQL injection over websocket protocol (either with custom script, or modified proxy for SQLMap). Once you find creds in the DB for the hidden endpoint, you login to find only the admin can read the config. Since the server uses JWT-based authentication, you crack the HS256 signing key with a tool like jwt_tool/hashcat/john, and then forge a new token with the username "admin". Now you just need to swap the cookies to find your flag! Write-ups/tutorials aimed at beginners - Hope you enjoy 🙂 #INTIGRITI #CTF #Web #BugBounty
Write-up: https://cryptocat.me/blog/ctf/2023/in...
↢INTIGRITI 1337UPLIVE CTF↣
https://ctftime.org/event/2134
https://ctf.intigriti.io
/ discord
👷♂️Resources🛠
https://cryptocat.me/resources
↢Chapters↣
0:00 Start
0:44 Explore functionality
1:37 Tamper with requests (IDOR)
2:20 Identify SQLi
3:25 Modify websocket SQLi proxy
4:50 SQLMap (proxied via burp suite)
6:16 Explore hidden endpoint
7:55 Crack JWT token with jwt_tool
8:46 Forge new token to login as admin
9:52 End