We demonstrated broken authentication vulnerability by changing cookie values. This was part of TryHackMe Overpass.

Broken authentication is listed as one of the top 10 web application vulnerabilities according to OWASP.

What happens when a group of broke Computer Science students try to make a password manager? Obviously a perfect commercial success!

Hack the machine and get the flag in user.txt

Escalate your privileges and get the flag in root.txt

