$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: InsightDash analytics platform with nginx caching proxy in front of Express.js; /api/me returns authenticated user profile; admin bot visits URLs from support tickets. Solution: Web cache deception via semicolon URL parser discrepancy — nginx sees /api/me;x.css as cacheable static file, Express routes it to /api/me; submit poisoned URL to admin bot, then fetch cached admin profile containing the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar