$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Flask web app with terminal interface, user gets guest session, /get-flag requires admin. Solution: Bruteforce weak SECRET_KEY with flask-unsign, forge session cookie with _user_id=admin.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar