DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

TryHeartMe - TryHackMe writeup

Access the hidden item in this Valentine's gift shop.

EasyWeb3 min read

Open the room on TryHackMe ↗ View on GitHub

Task 1. TryHeartMe

What is the flag?

THM{v4l3nt1n3_jwt_c00k13_t4mp3r_4dm1n_sh0p}

Accessing the Website

The objective of this room is straightforward. I need to purchase the hidden valenflag item from the TryHeartMe shop.

As soon as I started the lab, most of the initial enumeration was already handled.

image

The target application is running on port 5000, so I navigated directly to the web interface.

image

The application presents a login and signup page. I created a new account using random credentials and logged in.

image

Once inside, nothing immediately stood out. No hidden items were visible, so I decided to interact with the shop and attempt to purchase a product.

image

When I opened a product, I noticed two important things. First, I had zero credits, so purchasing anything was not possible. Second, the response clearly reflected my role as a user. That became the pivot point. If the application enforces role-based access, elevating privileges could expose additional functionality.

image

Intercepting the Request

To analyze how the application handles roles, I opened Burp Suite, refreshed the page, and intercepted the request.

image

Captured request:

GET /product/rose-bouquet HTTP/1.1
Host: 10.48.179.122:5000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:149.0) Gecko/20100101 Firefox/149.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Referer: http://10.48.179.122:5000/
Cookie: tryheartme_jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJlbWFpbCI6InRlc3RAdGVzdCIsInJvbGUiOiJ1c2VyIiwiY3JlZGl0cyI6MCwiaWF0IjoxNzc0ODAxOTgwLCJ0aGVtZSI6InZhbGVudGluZSJ9.pahhY7p5LRw9cUVE-0vAZYCVdqIMR89rYMrvbkxTZ6k
Upgrade-Insecure-Requests: 1
Priority: u=0, i

The key observation here is the tryheartme_jwt cookie. This token appears to store user-related data such as role and credits.

Decoding the JWT

I took the JWT token and decoded it using jwt.io.

tryheartme_jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJlbWFpbCI6InRlc3RAdGVzdCIsInJvbGUiOiJ1c2VyIiwiY3JlZGl0cyI6MCwiaWF0IjoxNzc0ODAxOTgwLCJ0aGVtZSI6InZhbGVudGluZSJ9.pahhY7p5LRw9cUVE-0vAZYCVdqIMR89rYMrvbkxTZ6k
image

After decoding, the payload revealed multiple fields including:

The role was set to user, and credits were set to 0.

Modifying the Token

At this point, I modified the payload directly. I changed the role to admin and increased the credits value.

image

Once updated, I copied the newly encoded token and replaced the original cookie inside the request.

image
After forwarding the request with the modified token, the changes were reflected immediately. My role was now elevated, and credits were no longer zero.
image

Accessing the Hidden Item

With the updated privileges, I navigated back to the shop.

image

A new hidden item appeared in the store that was not visible earlier. I proceeded to purchase it.

image

The purchase was successful, and the application returned the flag.

image

Flag

image
THM{v4l3nt1n3_jwt_c00k13_t4mp3r_4dm1n_sh0p}
image

NOTE: Make sure to replace the cookie in every request, as the modified token needs to be used consistently throughout the session.

Thanks for reading. I hope this walkthrough helped you along the way.