Urgent.News

What's breaking now, across thousands of outlets.

Tech

Attacking APIs — Skills Assessment Writeup

Introduction Walking through my solve of the Attacking APIs Skills Assessment. This one chains weak authentication flows, insecure password reset mechanisms, and a classic SSRF/Local File Inclusion vulnerability to read the flag from /flag.txt . What makes this lab interesting is how it forces you to move between different user contexts and carefully abuse a field that looks harmless at first…

The "Attacking APIs" Skills Assessment on Hack The Box presented a series of challenges, each demonstrating common web application security vulnerabilities. The lab involved exploiting authentication weaknesses, insecure password reset mechanisms, and a file inclusion vulnerability to obtain a flag located at /flag.txt.

Upon initial authentication using the provided email and password, a valid JSON Web Token (JWT) was received, allowing access to restricted endpoints. The authenticated user had limited privileges, only capable of listing suppliers.

During privilege enumeration, the lab revealed a potential password reset vector. The "securityQuestion" field, asking "What is your favorite color?", seemed innocuous but later proved exploitable. By targeting a supplier account and resetting its password using the security question, the flag was successfully changed.

Logging in with the compromised supplier credentials yielded a fresh JWT. The "professionalCVPDFFileURI" field caught the tester's attention. Through a Patch request, the tester uploaded a file containing the flag to this field, which was later retrieved by making a GET request to the CV endpoint.

The flag, encoded in Base64, was decoded to reveal the secret: "HTB{f*****************k}". The key takeaways from this lab emphasized the importance of thoroughly enumerating user contexts and related objects, being cautious of weak security question implementations, and thoroughly testing user-controlled URI fields for potential SSRF and Local File Inclusion vulnerabilities.

This assessment highlighted the critical need for secure authentication flows, password reset mechanisms, and input validation to prevent privilege escalation attacks.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Empty is a result. Loading is a state.

The result element exists. It even contains text. Unfortunately, the text says Loading... instead. The check is green before the useful result has arrived.

  • Result element exists with "Loading..." text instead of desired content
  • Difficulty distinguishing empty result from loading state with simple browser check
  • Browser readiness assessment clarifies empty vs loading result distinction

More from Thursday 1 October →