$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Django log-aggregation app using signed_cookies sessions with PickleSerializer; goal is to read /root/flag.txt. Solution: leak SECRET_KEY from a /debug/config endpoint (disclosed in robots.txt), forge a pickle session cookie with django.core.signing.dumps and a custom PickleSerializer, achieve RCE via __reduce__/os.system, copy the flag to /tmp/.logpulse_broadcast which the dashboard reflects.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar