$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Express.js BI platform with a JWT secret hardcoded in client-side JS and an admin test-connection endpoint passing a hostname into a shell ping. Solution: leak the HS256 secret from /js/auth.js, forge an admin JWT, then OS command injection via the hostname field for RCE as root and read /root/flag.txt.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar