$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Flask/Gunicorn notes service where user posts are exposed at /posts/<sha256(username)>. Solution: compute sha256(admin), request the corresponding page, and read the flag from admin notes due to broken access control.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar