$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: File storage platform with JSON API login endpoint vulnerable to JavaScript type coercion in password comparison. Solution: Send boolean true as password in JSON body to bypass authentication via loose comparison, then access admin config page for the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar