stuck on https://govagriculture.web.ctfcompetition.com/ this task, any help?
Same here. Unless there's some steganography, I'm really all out of ideas. I see see the content of folders (/static/, /static/images/, etc), but that doesn't help. I can't get anything out of /admin and the content of /post don't appear anywhere for any sort of XSS attack.
If the server is parsing your input, maybe you can find a way for the server to leak more than it wants.
If you want more information, or simply the answer, PM me.