$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: DevRelay API platform uses OAuth 2.0 Authorization Code flow with no redirect_uri validation, plus an admin bot that visits user-submitted URLs. Solution: Craft malicious OAuth authorize URL redirecting the admin's auth code to a Request Bin, exchange the code for an access token, and access /api/admin/secrets.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar