<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Flask on L3B4nk4</title><link>https://blog.b4nk4.tech/tags/flask/</link><description>Recent content from L3B4nk4</description><generator>Hugo</generator><language>en-us</language><copyright>All articles on this blog are licensed under the BY-NC-SA license agreement unless otherwise stated. Please indicate the source when reprinting!</copyright><lastBuildDate>Thu, 26 Mar 2026 00:00:00 +0200</lastBuildDate><atom:link href="https://blog.b4nk4.tech/tags/flask/index.xml" rel="self" type="application/rss+xml"/><item><title>Python Sucks</title><link>https://blog.b4nk4.tech/post/python_sucks/</link><pubDate>Sat, 13 Sep 2025 00:00:00 +0200</pubDate><guid>https://blog.b4nk4.tech/post/python_sucks/</guid><description>
<![CDATA[<h1>Python Sucks</h1><p>Author: L3B4nk4()</p>
        
          A Flask challenge from Connectors CTF: SQL injection leads to admin access, the file viewer turns into arbitrary file read, and the exposed Werkzeug console finishes the box with RCE.
        
        <hr><p>Published on 2025-09-13 at <a href='https://blog.b4nk4.tech/'>L3B4nk4</a>, last modified on 2026-03-26</p>]]></description><category>writeup</category></item></channel></rss>