Tampering with a signed-but-unverified token
50 points · about 90 minutes · flag formatDC{...}Brief
Deserialization rebuilds an object from bytes. When those bytes come from the client and the format can encode types or behaviour, a crafted payload can make the server construct objects it never meant to — changing state, or in the worst case running code, the moment it reads them.
This lab: Tampering with a signed-but-unverified token. Feed the server a serialized object it will trust and rebuild.
Work it against your own copy of the target. When you have the flag, submit it below.
Objective
Find where the app rebuilds an object from data you control, tamper with that data, and make the reconstruction do something in your favour. Capture the flag it yields.
Sign in and join the Academy to submit a flag, take hints and track your progress.
Sign inWalkthrough
Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.