$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: Flask notes app whose note filename is os.path.join(NOTES_DIR, f"{username}_{id}.html") with an arbitrary username — an absolute username yields arbitrary root-owned file write/read. Solution: leak SSH creds from a seeded note, SSH in as kevin, then abuse a sudo NOPASSWD script that runs `eval echo "$line"` on note lines by planting a note whose content contains $() — the key fix being that the note must end with a newline or bash `read` skips the final payload line.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar