Overview

Second marathon session — 30 more labs solved across JWT exploitation, advanced XSS evasion, CSRF SameSite bypasses, and more. Total across both sessions: ~60 labs.

JWT Attacks (5 Labs)

AttackTechniqueSeverity
Unverified signatureChange sub claim, keep original signatureP1
Algorithm noneSet alg to none, empty signature with trailing dotP1
Weak signing keyBrute force with hashcat, key was secret1P1
JWK header injectionEmbed RSA public key in jwk header, sign with own keyP1
kid path traversalSet kid to /dev/null, sign with null byteP1

Bug Bounty: Always decode JWTs. Check alg, kid, jwk, jku headers for injection.

XSS Evasion (16 Labs)

ContextPayload Pattern
HTML attribute" autofocus onfocus=alert(1)
Anchor hrefjavascript:alert(1) in website field
JS string‘-alert(1)-’ breaks string
Template literaldollar-brace alert interpolation
onclick handlerHTML entity quotes for single-quote injection
Backslash escapebackslash-quote-alert bypasses escape
Script tag closeClose existing script, open new one
AngularJSconstructor chain on $on object
SVG onlyanimatetransform onbegin event
Canonical linkaccesskey + onclick via URL params
document.write in selectClose select tag, inject img onerror
JSON responseUnescaped backslash breaks JSON string in dynamic code
Stored DOM replaceExtra angle brackets bypass single-replace
Most tags blockedbody onresize triggered via iframe resize
All standard tags blockedCustom tag with onfocus + tabindex + hash
XSS to CSRFStored XSS extracts CSRF token via XHR

CSRF Bypasses (6 Labs)

BypassTechnique
No defensesAuto-submit form
Token absentRemove csrf parameter — only validated if present
Method overridePOST to GET — token only checked on POST
SameSite Lax_method=POST in GET query string
SameSite StrictClient-side redirect gadget via path traversal
Token not tied to sessionUse attacker valid token for victim request

Other Techniques

  • NoSQL detection: Boolean injection to bypass filters
  • NoSQL auth bypass: Regex operator + not-equal password operator
  • File upload: Change Content-Type to image/jpeg, keep .php filename
  • GraphQL: Query hidden post ID with postPassword field
  • Access control: GET instead of POST for admin endpoint
  • Coupon stacking: Alternate two codes to bypass duplicate check
  • SQLi: WHERE clause injection and login bypass

Key Takeaways

  1. JWT is a goldmine — 5 attack vectors, all P1
  2. XSS evasion requires context awareness — 16 different payloads
  3. CSRF bypasses are systematic — remove, change method, exploit SameSite
  4. Never trust client-side controls

~60 labs solved across two sessions. Techniques for authorized testing only.