Burpoo

MediumWeb Security

Overview

SCENARIO

I've built this super secure vault application! I mean, I'm pretty confident in my skills as a developer. Authentication? Check! I'm using JWT tokens - industry standard, right? Rate limiting? Of course! I've implemented that too. I even added PIN protection for the vaults because, you know, security in layers and all that. I think I'm pretty good at finding workarounds to get things done efficiently, and as you can see, it was so easy for me to implement all these security features. The admin account is locked down tight - good luck getting in there!
flag format : Flag{}

Infrastructure

- Docker Container — HTTP on port 5000

Provided Files

- None ( BlackBox Challenge )

Job Positions

Ethical Hacker

Tags

JwtBroken Access ControlRate LimitingHttp HeadersBurp Suite