$ cat writeup.md…
$ cat writeup.md…
bug-makers
Task: Flask app with /read?file= endpoint blocks access to /app/forbidden/ via os.path.normpath() + startswith() check. Solution: bypass using /proc/self/cwd symlink which resolves to /app at OS level but is not normalized by normpath().
Permission denied (requires tier.pro)
Sign in with GitHub or Discord to continue. No email required.
$sign in$ grep --similar