HACKR.GG
LabsSession Token
JWT AttacksMedium

Session Token

FirstBank signs session JWTs with a weak secret. Crack it, forge a new token with role: admin.

Tools:jwt_toolcurlpython3 (PyJWT)
↗ View walkthrough
// Machine control
Checking session...
// Submit flag