2016from the authors’ own sites
SVATTT Quals 2016
1 challenge with 1 published solution between them. The writeups for this event were found on the authors’ own sites.
Where these writeups liveWeb1
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Solve it with:JWT decoder and signature verifierJWT alg=none bypass generatorWeb attack payload catalogJWT secret brute forceLearn: Sessions, tokens and access control
admincp (Web 200pts)
1 official solutionAlso written up in: quandqn.wordpress.com