🖥️ Challenge / Machine Info

  • Platform: pentesterlab
  • Name / Title: jwt-weak
  • Difficulty: Easy
  • Target OS / Environment: Web
  • Key Vulnerability Focus: JWT / Hashcat cracking

Walkthrough

  1. Crack weak symmetric JWT signature offline using Hashcat.
  2. Modify user state payload to is_admin = true and sign with the cracked secret.