$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Web app with login system that logs failed attempts with User-Agent. Solution: Stored XSS via User-Agent injection, bypassing WAF with string concatenation and bracket notation, stealing admin cookies via location redirect.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar