$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Flask app with source code, hint about 0x7F (127 = DEL = ghost input). Solution: Blind SSTI in Jinja2 - password field is rendered as template via from_string().render(), result saved as hash. Exploit by registering with SSTI payload and logging in with computed result, or use reverse shell.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar