$ cat writeup.md…
$ cat writeup.md…
HackTheBox
Task: Flask+SocketIO satellite ground station with telemetry TCP port, admin bot, and innerHTML XSS sink in packet ASCII rendering. Solution: craft valid CCSDS packet with HTML payload in printable ASCII region, trigger stored XSS in admin bot's browser to call privileged acquire_image endpoint, then retrieve flag image from unauthenticated telemetry API.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar