HTB University CTF 2024 WEB
by problematicmatcher - Friday December 13, 2024 at 10:29 PM
#1
Discussion: I have started with Breaking bank, i think the key is to forge the Authorization header, i found this in the source code:
// TODO: is this secure enough?
        if (!jku.startsWith('http://127.0.0.1:1337/')) {
            throw new Error('Invalid token: jku claim does not start with http://127.0.0.1:1337/');
        }
I am sure this is the intended way but i cannot seem to get the SSRF to work i keep getting an annoying "Invalid signature" error.
Reply
#2
I have the same issue...
Did you manage to make any progress?
Reply
#3
there is an open redirect that you can exploit and use your own public key to validate the jwt token
Reply
#4
(Dec 14, 2024, 09:43 PM)wintercaptainsoldier Wrote: there is an open redirect that you can exploit and use your own public key to validate the jwt token

hello, did you complete EncoDecept?
pls any hint
Reply
#5
I had also the same issue...
Did you find a suitable solution please

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Replying to someone else's scam report | Failure to follow the first fucking rule of the scam reports section
Reply
#6
still no solution? better rename the project

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 87 3,234 Less than 1 minute ago
Last Post: darth_sidious
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 48 3,752 7 minutes ago
Last Post: darth_sidious
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 98 9,085 Yesterday, 08:05 PM
Last Post: Zacker90
  SVCHOST Injector 2026 opsecmaster67 0 99 Yesterday, 01:41 PM
Last Post: opsecmaster67
  Cold Seal 5.6 cracked Sensitive information can be exposed or stolen opsecmaster67 0 82 Yesterday, 01:38 PM
Last Post: opsecmaster67

Forum Jump:


 Users browsing this forum: 1 Guest(s)