# Shady Oaks Financial

Level: Easy\
Points: 10\
Type: Daily Challenge

Lab Interface

<figure><img src="https://559802299-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F8C3FiojCIEtxH7nox2Do%2Fuploads%2FGvwLgfzrFd70d4uCe3ry%2Fimage.png?alt=media&#x26;token=5a112e15-31f8-4dc5-a53d-2811a09eda28" alt=""><figcaption></figcaption></figure>

After login, we get JWT as:

```
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6NCwidXNlcm5hbWUiOiJzdXNoaWwiLCJyb2xlIjoidXNlciIsImlhdCI6MTc3MjgxMzY1M30.DlQBKe4708GVJ1jMIkpWTStnsIcxDaZXc4WJMnzN9hU
```

<figure><img src="https://559802299-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F8C3FiojCIEtxH7nox2Do%2Fuploads%2F27NfU1vMYtc2EwL0dxOS%2Fimage.png?alt=media&#x26;token=f494252d-a8b3-4b8f-b94b-c14aa7f5f20d" alt=""><figcaption></figcaption></figure>

edit the \
`algo` to `none` \
`id` to `1`\
`role` to `admin`

<figure><img src="https://559802299-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F8C3FiojCIEtxH7nox2Do%2Fuploads%2FKccBnvRFkGGxuO0sUXtJ%2Fimage.png?alt=media&#x26;token=92315a99-d1a9-4aed-8f2a-3813fb91503e" alt=""><figcaption></figcaption></figure>

Then send the request, we now have access to the admin panel

To get flag: GET request to /api/admin/flag

<figure><img src="https://559802299-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F8C3FiojCIEtxH7nox2Do%2Fuploads%2F25MstRobqvAQLH76277N%2Fimage.png?alt=media&#x26;token=fe416c33-6231-4cc0-841e-d8577c12d1e1" alt=""><figcaption></figcaption></figure>
