The role hidden in a base64 cookie
25 points · about 45 minutes · flag formatDC{...}Brief
Deserialization rebuilds an object from bytes. When those bytes come from the client and the format can encode types or behaviour, a crafted payload can make the server construct objects it never meant to — changing state, or in the worst case running code, the moment it reads them.
This lab: The role hidden in a base64 cookie. Feed the server a serialized object it will trust and rebuild.
Work it against your own copy of the target. When you have the flag, submit it below.
Objective
Find where the app rebuilds an object from data you control, tamper with that data, and make the reconstruction do something in your favour. Capture the flag it yields.
Sign in and join the Academy to submit a flag, take hints and track your progress.
Sign inWalkthrough
Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.