$ cat writeup.md…
$ cat writeup.md…
sasctf
Task: a Python wrapper accepted an attacker-controlled JAR that pyjnius loaded inside a restricted Java HTTP client environment. Solution: skip the tempting pyjnius UAF path and use reflection on Java 21 FFM classes to call libc system(\"cat /app/flag.txt\").
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar