$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Express 'Site Tester' headless-Chrome scraper with SSRF (stats-only oracle, http/https only). Solution: title 9.2.2.3 = CDP port 9223; host CSP-free attacker JS, fetch CORS-readable /json, open page-level CDP WebSocket, Target.createTarget(file:///app/flag.txt) + Runtime.evaluate to read and exfiltrate the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar