$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Web app with subscription-based content and report functionality. Solution: Stored XSS via log injection with two-stage attack - create XSS payload in log, then trigger admin bot to visit it and exfiltrate cookies via webhook.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar