Burpoo
MediumWeb Security
Overview
SCENARIO
I've built this super secure vault application! I mean, I'm pretty confident in my skills as a developer. Authentication? Check! I'm using JWT tokens - industry standard, right? Rate limiting? Of course! I've implemented that too. I even added PIN protection for the vaults because, you know, security in layers and all that. I think I'm pretty good at finding workarounds to get things done efficiently, and as you can see, it was so easy for me to implement all these security features. The admin account is locked down tight - good luck getting in there!
flag format : Flag{}
Infrastructure
- Docker Container — HTTP on port 5000
Provided Files
- None ( BlackBox Challenge )
Job Positions
Ethical Hacker
Tags
JwtBroken Access ControlRate LimitingHttp HeadersBurp Suite