Task 1. TryHeartMe
What is the flag?
THM{v4l3nt1n3_jwt_c00k13_t4mp3r_4dm1n_sh0p}
Accessing the Website
The objective of this room is straightforward. I need to purchase the hidden valenflag item from the TryHeartMe shop.
As soon as I started the lab, most of the initial enumeration was already handled.
The target application is running on port 5000, so I navigated directly to the web interface.
The application presents a login and signup page. I created a new account using random credentials and logged in.
Once inside, nothing immediately stood out. No hidden items were visible, so I decided to interact with the shop and attempt to purchase a product.
When I opened a product, I noticed two important things. First, I had zero credits, so purchasing anything was not possible. Second, the response clearly reflected my role as a user. That became the pivot point. If the application enforces role-based access, elevating privileges could expose additional functionality.
Intercepting the Request
To analyze how the application handles roles, I opened Burp Suite, refreshed the page, and intercepted the request.
Captured request:
GET /product/rose-bouquet HTTP/1.1
Host: 10.48.179.122:5000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:149.0) Gecko/20100101 Firefox/149.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Referer: http://10.48.179.122:5000/
Cookie: tryheartme_jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJlbWFpbCI6InRlc3RAdGVzdCIsInJvbGUiOiJ1c2VyIiwiY3JlZGl0cyI6MCwiaWF0IjoxNzc0ODAxOTgwLCJ0aGVtZSI6InZhbGVudGluZSJ9.pahhY7p5LRw9cUVE-0vAZYCVdqIMR89rYMrvbkxTZ6k
Upgrade-Insecure-Requests: 1
Priority: u=0, i
The key observation here is the tryheartme_jwt cookie. This token appears to store user-related data such as role and credits.
Decoding the JWT
I took the JWT token and decoded it using jwt.io.
tryheartme_jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJlbWFpbCI6InRlc3RAdGVzdCIsInJvbGUiOiJ1c2VyIiwiY3JlZGl0cyI6MCwiaWF0IjoxNzc0ODAxOTgwLCJ0aGVtZSI6InZhbGVudGluZSJ9.pahhY7p5LRw9cUVE-0vAZYCVdqIMR89rYMrvbkxTZ6k
After decoding, the payload revealed multiple fields including:
- role
- credits
- theme
The role was set to user, and credits were set to 0.
Modifying the Token
At this point, I modified the payload directly. I changed the role to admin and increased the credits value.
Once updated, I copied the newly encoded token and replaced the original cookie inside the request.
Accessing the Hidden Item
With the updated privileges, I navigated back to the shop.
A new hidden item appeared in the store that was not visible earlier. I proceeded to purchase it.
The purchase was successful, and the application returned the flag.
Flag
THM{v4l3nt1n3_jwt_c00k13_t4mp3r_4dm1n_sh0p}
NOTE: Make sure to replace the cookie in every request, as the modified token needs to be used consistently throughout the session.
Thanks for reading. I hope this walkthrough helped you along the way.