$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: banking platform with 2FA that issues JWT before OTP verification, containing otp_verified:false claim. Solution: use pre-authentication JWT to access API endpoints that don't validate the otp_verified claim, retrieving flag from account settings.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar