Websocket SQLi and Weak JWT Signing Key - "Bug Report Repo" [INTIGRITI 1337UP LIVE CTF 2023]

Опубликовано: 30 Март 2026
на канале: CryptoCat
2,406
123

Video walkthrough for "Bug Report Repo", a web challenge I made for the ‪@intigriti‬ 1337UP LIVE CTF 2023. The challenge had multiple parts; first you need to use an IDOR to find a hidden bug report from ethical_hacker. Next, you exploit SQL injection over websocket protocol (either with custom script, or modified proxy for SQLMap). Once you find creds in the DB for the hidden endpoint, you login to find only the admin can read the config. Since the server uses JWT-based authentication, you crack the HS256 signing key with a tool like jwt_tool/hashcat/john, and then forge a new token with the username "admin". Now you just need to swap the cookies to find your flag! Write-ups/tutorials aimed at beginners - Hope you enjoy 🙂 #INTIGRITI #CTF #Web #BugBounty

Write-up: https://cryptocat.me/blog/ctf/2023/in...

↢INTIGRITI 1337UPLIVE CTF↣
https://ctftime.org/event/2134
https://ctf.intigriti.io
  / discord  

👷‍♂️Resources🛠
https://cryptocat.me/resources

↢Chapters↣
0:00 Start
0:44 Explore functionality
1:37 Tamper with requests (IDOR)
2:20 Identify SQLi
3:25 Modify websocket SQLi proxy
4:50 SQLMap (proxied via burp suite)
6:16 Explore hidden endpoint
7:55 Crack JWT token with jwt_tool
8:46 Forge new token to login as admin
9:52 End