$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Express.js API gateway dashboard behind nginx trusts X-Gateway-Role header for authorization without stripping it from external requests. Solution: Inject X-Gateway-Role: admin header to escalate from viewer to admin and access the secrets panel containing the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar