$ cat writeup.md…
$ cat writeup.md…
miptctf
Task: Web app with notes, two Flask backends (DEV/PROD) behind nginx, flag only on PROD via localhost, bot restricted to ports 443/4443. Solution: DNS HTTPS/SVCB record attack (RFC 9460) to redirect browser TCP connection to port 1337 while URL shows port 443, bypassing bot port check.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar