Access & Authentication badge
Who are you, and what are you allowed to do? Broken access control, password storage, sessions, CSRF and JSON Web Tokens — the whole identity story, attack and defence.
| # | Exercise | Difficulty | Tier |
|---|---|---|---|
| 1 |
Broken Access Control
The bug you find by changing a number in the URL. Learn IDOR, why it is the most common serious web flaw, and the server-side check that stops it. |
Medium | 🔒 Pro |
| 2 |
How Passwords Are Stored and Cracked
Why sites store hashes not passwords, how attackers crack a leaked hash, and why a pinch of salt and a slow algorithm change everything. |
Medium | 🔒 Pro |
| 3 |
Session Management
A login is only as strong as the session it creates. Learn how session cookies work, the three ways they go wrong, and the flags and habits that keep them safe. |
Medium | 🔒 Pro |
| 4 |
Cross-Site Request Forgery (CSRF)
Your browser attaches your session cookie to every request to a site — even requests a different site told it to make. Learn how that is abused and the token that stops it. |
Medium | 🔒 Pro |
| 5 |
JSON Web Tokens (JWT)
A JWT lets a server trust a token instead of looking up a session — but only if it verifies the signature properly. Learn the structure, the classic mistakes, and how to use them safely. |
Hard | 🔒 Pro |