$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Flask SAML 2.0 SSO app where signature verification (xml.etree, binds to signed assertion by ds:Reference URI) and attribute extraction (lxml, reads first <saml:Assertion>) use different XML parsers. Solution: XML Signature Wrapping — capture the genuine signed user assertion via normal login, prepend an unsigned forged Role=admin assertion as a sibling; verifier validates the real one, lxml trusts the forged first one, granting admin and the flag from /admin/settings.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar