$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: KeyVault2FA 2FA management platform with OTP account import that fetches icon URLs server-side without validation. Solution: Exploit SSRF via image parameter in otpauth:// URI to access internal config service on localhost:3001/flag, with non-image response body leaked in body_preview field.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar