$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: analytics platform with tar.gz dataset import that extracts archives without path sanitization, and EJS report templates rendered server-side. Solution: craft a malicious tar.gz with path traversal (../../) to overwrite an EJS report template with RCE payload, then trigger template rendering to read /root/flag.txt.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar