Rating:
TL;DR bypass numeric only WAF via string coercion and bitwise operators, solve readflag via previously known ways.
Full description available in the writeup!
I don't remember