$ cat writeup.md…
$ cat writeup.md…
bluehensctf
Task: a Magic Link Login Service where POST /login leaks the magic-link UUID in the JSON response. Solution: request a login link for [email protected], extract the UUID from the response, visit /login/<uuid> to authenticate as admin, access /dashboard to retrieve the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar