Challenge 5: Bit flipper ------------------------ GET /token -> a fresh session token (hex IV||CT) for user=guest. POST /login -> body = a token (hex IV||CT). The app trusts whatever it decrypts to. Get it to read user=admin. There is no integrity check on the token. That is not an accident.