$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: PulseDesk support platform with password reset feature; hidden /api/v1/auth/password-policy endpoint uses token in unsanitized SQL LIKE query creating a boolean oracle. Solution: exploit blind SQLi with binary search on UNICODE(SUBSTR(...)) to extract admin's reset token character by character, then reset admin password and access the secret API master key.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar