$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Express webhook platform with a settings API that deep-merges arbitrary JSON (prototype pollution) and a custom raw-socket HTTP adapter that emits headers unsanitized. Solution: pollute Object.prototype with a header whose value contains CRLF, smuggling a second HTTP request over the keep-alive socket to reach the gated /internal/credentials endpoint on localhost:3001 via full-read SSRF.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar