YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 18 · 4 min readFAM CTF : The Vault Door WriteupSummary NexaVault is a mock internal dashboard app that gates an "Admin Vault" panel behind a role claim in a JWT. The app issues a user-role token on login, stored in the nx_access cookie, and trusts00
WBWiktoria Blomgren Strandberginpentesting-dvwa.hashnode.dev·Mar 8 · 14 min readAuthorisation Bypass in DVWA1 Introduction In this post, the Authorisation Bypass vulnerability in the Damn Vulnerable Web Application (DVWA) is described. The objective for attacks on all levels is to identify any areas where a00