$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: enterprise credential management platform with WebAuthn 2FA; team API over-exposes security device info and device removal lacks ownership validation. Solution: chain two IDORs — enumerate admin's WebAuthn credential_id via team API, delete admin's 2FA device as low-privilege user, login with leaked admin credentials, access protected notes containing the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar