$ cat writeup.md…
$ cat writeup.md…
duckerz
Task: Notes app with Telegram auth, get admin password hash. Solution: Predict UUID tokens using extracted MAC address + race condition to get admin JWT, then boolean-based SQLi via f-string in is_user_exists() to extract hash character by character.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar