picoCTF 2022 | Power Cookie Write-up

Challenge description

Can you get the flag? Go to this website and see what you can discover.

Category: Web Exploitation


This is the first cookie-based challenge of the 2022 batch, and a simple one to start off with.

Let’s get started by going to the website in the challenge description, and pressing “Continue as guest”.

At this point, you will need some form of cookie editor for your browser. As I am using firefox, I am using an extension called Cookie-editor. Using your editor of choice, you will be able to find a cookie named isAdmin with the value of 0. Change this value to 1 and refresh the website.

That’s all you need to get the flag!

