$ cat writeup.md…
$ cat writeup.md…
alfactf
Task: Social network with bot that visits user profiles and has flag cookie with httpOnly:false. Solution: Stored XSS via unsanitized avatar_url opens popup window that persists across bot navigation and steals cookie after bot logs in.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar