$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: OAuth 2.0 identity platform with Dynamic Client Registration (RFC 7591) where logo_uri is fetched server-side without SSRF protections. Solution: Registered OAuth client with logo_uri pointing to localhost:3001 internal metadata service, then accessed the logo endpoint to exfiltrate secrets including the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar