$ cat writeup.md…
$ cat writeup.md…
kalmarctf
Task: a Flask service cloned an attacker-controlled Git repository, created `headlocation`, then executed `git show HEAD` from inside that path. Solution: hide a bare repository at `headlocation`, force a promisor fetch for a missing object, and use repo-local `sshCommand` to run `/flagout` and exfiltrate the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar