There were some awesome answers, well done 💥
The explanation: 🤓
NGINX looks for the explicit path "/secret", without caring about case sensitive. But, if we add an extra character to the path, NGINX will no longer block it cause it another path, an the request will be forwarded to the Flask backend.
The magic comes when Flask removes certain characters, for example \xA0.
So by requesting the path "/secret\xa0", we'll be able to bypass the NGINX rule and access our secret 🔥
Hackers 🔥
I’ve set up this Nginx that forwards traffic to a Flask server and blocks access to /secret - throwing 403 🛑
Can you find a way to bypass this restriction and access /secret? 🥷
Drop your ideas or tricks in the replies — let’s see how creative you can get! ⚡️