Forge the admin cookie — without the secret key

A server signs data as H(secret || data). You've intercepted one message (the secret is never sent). Can you extend it into something the server never signed — and still pass the MAC check — without ever learning the secret?

The intercepted message (this is all an attacker ever sees on the wire):

What you compute (never touching the secret):

Forged cookie you'd send back

Verifier A — H(secret || data)

mac = toyhash(secret + data)

Verifier B — H(secret || H(data))

mac = toyhash(secret + toyhash(data))