$ cat writeup.md…
$ cat writeup.md…
dicega
Spring Boot (Kotlin) + Thymeleaf web application with a Puppeteer admin bot. The app lets users create "postcards" with a name and flag stored in a JWT cookie. An admin bot logs in with the real flag, then visits an attacker-provided URL. The goal is to steal the flag from the admin's JWT cookie.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar