HackTheBox - CriticalOps

HackTheBox - CriticalOps

Source: YouTube · IppSec · published Jun 25, 2025 · 15:29

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

This video demonstrates solving the "Critical Ops" teaser challenge for the upcoming Hack the System CTF, revealing a client-side JWT secret that allows privilege escalation to admin.

Key Takeaways:
• The Hack the System CTF runs June 27-29, featuring five web challenges derived from real bug bounty reports 0:06.
• Winners receive up to three Silver Academy vouchers, including eligibility for the Certified Bug Bounty Hunter exam 0:16.
• Two teaser challenges, "Critical Ops" and "Nova Energy," are available immediately on the CTF platform 0:24.
• Access the CTF by visiting the Hack the System Bug Bounty CTF page and clicking "play CTF" 0:39.
• The "Critical Ops" challenge was solved by finding a hardcoded JWT secret in the client-side JavaScript source code 0:45.
• The attacker forged an admin JWT token using the discovered secret to bypass authentication and retrieve the flag 2:30.

The event offers a practical opportunity to test web security skills against realistic scenarios using tools like Burp Suite and JWT editors.

Sources:

  • 0:06 CTF dates and challenge count
  • 0:16 Prizes for the winning team
  • 0:24 Teaser challenges availability
  • 0:39 How to access the CTF platform
  • 0:45 Challenge description and scope
  • 2:30 JWT forgery and flag retrieval

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

What's going on, YouTube? This is IPSC, and we'll be solving an easy web challenge that was created as a teaser for the Hack the System CTF, Hack the Box is running between June 27th and 29th. This CTF contains five web challenges based upon real bug bounty reports. It's free to join and the winning team will get up to three silver academy vouchers that will include the ability to take the certified bug bounty hunter exam. As part of the promotion for the event, two teaser challenges were created. I'll be covering critical ops challenge and OXDF will cover the Nova Energy. Both challenges are free to play now over on the CTF platform. And I'll put a link in the description for everything. Anyways, let's just hop in and start solving Critical Ops. So, to play this challenge, we're going to …