$ cat writeup.md…
$ cat writeup.md…
dicega
Harder variant ("b-side") of the Mirror Temple challenge. Same Spring Boot (Kotlin) + Thymeleaf + Puppeteer admin bot architecture. The app lets users create "postcards" with a name and flag stored in a JWT cookie. An admin bot logs in with the real flag, then visits an attacker-provided URL. The go
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar