$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Express.js blogging platform behind nginx reverse proxy; X-Forwarded-Host header reflected unsanitized in canonical link tags, nginx caches responses with unkeyed X-Forwarded-Host, admin bot visits reported posts. Solution: poison nginx cache with XSS payload in X-Forwarded-Host header, trigger admin bot via post report, exfiltrate admin's flag cookie via same-origin comments API.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar