$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Identity management platform with public LDAP directory lookup, flag hidden in admin's description attribute not returned by API. Solution: Blind boolean-based LDAP injection in username parameter to extract description attribute character by character using wildcard matching.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar