← All labs
ExpertInsecure deserialization

Tampering with a signed-but-unverified token

50 points · about 90 minutes · flag format DC{...}
Server-Side RequestsInjection

Brief

Deserialization rebuilds an object from bytes. When those bytes come from the client and the format can encode types or behaviour, a crafted payload can make the server construct objects it never meant to — changing state, or in the worst case running code, the moment it reads them.

This lab: Tampering with a signed-but-unverified token. Feed the server a serialized object it will trust and rebuild.

Work it against your own copy of the target. When you have the flag, submit it below.

Objective

Find where the app rebuilds an object from data you control, tamper with that data, and make the reconstruction do something in your favour. Capture the flag it yields.

Sign in and join the Academy to submit a flag, take hints and track your progress.

Sign in

Walkthrough

Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.