$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Flask ROT13 online encoder whose /encrypt endpoint feeds the ROT13'd input into render_template_string(), yielding Jinja2 SSTI and RCE. Solution: pre-ROT13-encode the SSTI payload so it decodes to valid Jinja2 after the server transform, then exfiltrate via lipsum.__globals__ os.popen; flag found in a trailing comment of /opt/app.py.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar