$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Flask/Werkzeug app whose custom fake-404 page builds a <script src> host from the X-Forwarded-For header and caches the response ~30s. Solution: poison the cache of an authenticated slash-username profile (unroutable → fake-404) so the admin approval bot loads attacker JS and exfiltrates its session cookie (the flag) via document.location OOB redirect.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar