$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Team analytics dashboard with login form vulnerable to NoSQL injection. Solution: Used MongoDB $ne operator injection (username[$ne]=user&password[$ne]=xxx) to bypass authentication and login as admin to access flag in admin panel.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar