$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Content analytics platform with caching layer; query parameter reflected unsanitized in HTML meta tags but excluded from cache key. Solution: Web cache poisoning via unkeyed query string to inject XSS, then trigger admin bot visit to exfiltrate non-HttpOnly flag cookie through same-origin API endpoint.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar