$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: SaaS monitoring dashboard with JWT HS256 authentication using kid header for key file selection — no path sanitization on kid parameter. Solution: Traverse kid to /dev/null to sign with empty key, forge administrator token using exact role value from /team page, access /admin/secrets vault for the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar