Post

Huntress CTF 2025 — OFA Write-up

Huntress CTF 2025 — OFA Write-up

Two factors? In this economy??!!

I just logged in using the credentials admin:admin, and then the website prompted me to input a 6-digit one time passcode.

ofa-2.png

After looking around, I noticed there was a cookie called session assigned to me.

ofa-3.png

The format looked a lot like JSON WEB TOKENS, so I pasted it into jwt.io, and I found the OTP.

ofa-4.png

After pasting the OTP in the prompt, I got the flag.

ofa-5.png

This post is licensed under CC BY 4.0 by the author.