{
  "id": 11094232,
  "title": "Attacking APIs — Skills Assessment Writeup",
  "url": "https://urgent.news/2026/10/01/attacking-apis-skills-assessment-writeup",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T03:09:27.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/hassanelsayed30/attacking-apis-skills-assessment-writeup-5ggl"
  },
  "original_language": "en",
  "account": "The \"Attacking APIs\" Skills Assessment on Hack The Box presented a series of challenges, each demonstrating common web application security vulnerabilities. The lab involved exploiting authentication weaknesses, insecure password reset mechanisms, and a file inclusion vulnerability to obtain a flag located at /flag.txt.\n\nUpon initial authentication using the provided email and password, a valid JSON Web Token (JWT) was received, allowing access to restricted endpoints. The authenticated user had limited privileges, only capable of listing suppliers.\n\nDuring privilege enumeration, the lab revealed a potential password reset vector. The \"securityQuestion\" field, asking \"What is your favorite color?\", seemed innocuous but later proved exploitable. By targeting a supplier account and resetting its password using the security question, the flag was successfully changed.\n\nLogging in with the compromised supplier credentials yielded a fresh JWT. The \"professionalCVPDFFileURI\" field caught the tester's attention. Through a Patch request, the tester uploaded a file containing the flag to this field, which was later retrieved by making a GET request to the CV endpoint.\n\nThe flag, encoded in Base64, was decoded to reveal the secret: \"HTB{f*****************k}\". The key takeaways from this lab emphasized the importance of thoroughly enumerating user contexts and related objects, being cautious of weak security question implementations, and thoroughly testing user-controlled URI fields for potential SSRF and Local File Inclusion vulnerabilities. This assessment highlighted the critical need for secure authentication flows, password reset mechanisms, and input validation to prevent privilege escalation attacks.",
  "summary": "Introduction Walking through my solve of the Attacking APIs Skills Assessment. This one chains weak authentication flows, insecure password reset mechanisms, and a classic SSRF/Local File Inclusion vulnerability to read the flag from /flag.txt . What makes this lab interesting is how it forces you to move between different user contexts and carefully abuse a field that looks harmless at first…",
  "key_points": [
    "Exploited authentication weaknesses to obtain JWT",
    "Exploited insecure password reset mechanism to change flag",
    "Identified and exploited file inclusion vulnerability"
  ],
  "editors_take": "This lab highlights the need for secure authentication flows, robust password reset mechanisms, and thorough input validation to prevent attackers from exploiting vulnerabilities and escalating privileges.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}