HTB University CTF 2024 WEB
by problematicmatcher - Friday December 13, 2024 at 10:29 PM
#1
Discussion: I have started with Breaking bank, i think the key is to forge the Authorization header, i found this in the source code:
// TODO: is this secure enough?         if (!jku.startsWith('http://127.0.0.1:1337/')) {             throw new Error('Invalid token: jku claim does not start with http://127.0.0.1:1337/');         }
I am sure this is the intended way but i cannot seem to get the SSRF to work i keep getting an annoying "Invalid signature" error.
Reply
#2
I have the same issue...
Did you manage to make any progress?
Reply
#3
there is an open redirect that you can exploit and use your own public key to validate the jwt token
Reply
#4
(12-14-2024, 09:43 PM)wintercaptainsoldier Wrote: there is an open redirect that you can exploit and use your own public key to validate the jwt token

hello, did you complete EncoDecept?
pls any hint
Reply
#5
I had also the same issue...
Did you find a suitable solution please
Ban reason: Replying to someone else's scam report | Failure to follow the first fucking rule of the scam reports section (Permanent)
Reply
#6
still no solution? better rename the project
Ban reason: Leeching | http://raiddfzn73ir6iyxlf7nwytnujiflddog...an-Appeals if you feel this is incorrect. (Permanent)
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  HTB Academy - Active Directory Penetration Tester Path 2024 loganpaul09 19 10,558 09-01-2026, 06:25 AM
Last Post: adolfoL
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 95 27,406 08-31-2026, 03:15 PM
Last Post: Marlb0r0Man
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 367 114,937 08-31-2026, 03:05 PM
Last Post: Marlb0r0Man
  HTB Eloquia User and Root Flags - Insane Box 69646B 14 18,611 08-21-2026, 07:27 PM
Last Post: tangol
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 25 20,511 08-15-2026, 06:06 PM
Last Post: m4573rx



 Users browsing this thread: 1 Guest(s)