$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: OAuth gateway platform with redirect_uri validation that checks protocol and TLD format but does not normalize Unicode characters. Solution: register OAuth app with IDN homograph redirect_uri (Cyrillic і U+0456 instead of Latin i), trick admin bot into authorizing, steal auth code from Authorization Log, exchange for token, access admin secrets.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar