$ cat writeup.md…
$ cat writeup.md…
CACTF2026
Task: HTB SecureCoding patch challenge; a Flask app behind a single Caddy reverse proxy uses ProxyFix(x_for=2) but only one real proxy fronts it, so IP-based internal-only access control can be spoofed. Solution: identify the X-Forwarded-For hop miscount, forge XFF 127.0.0.2 to reach the CROWN decree route, then fix by setting x_for=1 so Flask trusts only the hop the perimeter witnessed.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar