TravelEndpoint: 2025
Leaderboard

CWE
Tools & Techniques
Credentials
Enumeration
Login Page

Login Page: Source Code

/api/auth/login


dashboard

dashboard: source code


/api/bookings


Fuzzing Directories


JWT Attacks
jwt.io

Changing user_id:2


Cracking the jwt secret with hashcat


Creating a valid admin token with user_id:2



Who is Admin?


Some users have more privileges than others. Can you find something they shouldn't have left exposed?
Broken Object Level Authorization (BOLA)




Sometimes what you send isn't what's saved. Can you manipulate the system to reveal what is hidden?
Mass Assignment


Certain reports are meant for specific eyes only. Can you access what's not meant for you?
/api/admin/reports

A system's curiosity can sometimes lead it to unexpected places. Can you make it fetch something valuable?
Server Side Request Forgery












Data is only as secure as its weakest link. Can you uncover information that shouldn't be accessible?
Insecure Direct Object References (IDOR)


travelEndpoint.sh
Alternatives
Relevant Learning Sources
Last updated
