$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Flask web app with lottery ticket validation form. Solution: Bypass input validation with newline character (%0a) to exploit SSTI in Jinja2, extract SECRET_KEY from config, forge admin session with flask-unsign.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar