I came up with this solution, and after capturing the flag, i noticed that all the other writeups made use of the DNS rebinding technique. Checking the code, you'll see that the "/flag" endpoint is only accessible from a local machine. You can either...
skelter.hashnode.dev1 min read
No responses yet.