$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Flask/Jinja2 notification platform with template test-send feature that renders user input server-side but doesn't return output (blind SSTI). Solution: Error-based exfiltration using exec('raise Exception(data)') via lipsum.__globals__ to leak flag from environment variable.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar