$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: OAuth 2.0 SSO platform with regex-based redirect_uri validation where dot is unescaped, admin bot visits support ticket URLs. Solution: Bypass redirect_uri regex by replacing dot with dash, capture admin's authorization code via callback tester, exchange for access token to retrieve flag from userinfo endpoint.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar