Source code. We need to login as admin. Look at cookie name _letmein_session → Web uses framework Ruby on Rails Path traversal at /static?image=… → Read /proc/self/environ → Get SECRET_KEY_BASE → It’s used to encrypt and sign user’s session → Idea...