$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a Flask/Werkzeug web service lets users verify a flag through a separate `/check` endpoint. Solution: inspect the frontend JavaScript, detect that the API leaks whether the submitted value is a correct prefix, and brute-force the flag one character at a time until the endpoint returns full success.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar