$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: exploit a Flask web app with a TrackingId cookie vulnerable to blind SQL injection against SQLite. Solution: use CASE WHEN with LOAD_EXTENSION as error oracle (X-Theme header change), binary search extraction of admin credentials via cookie injection, then login to /admin.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar