1. /encrypt?data=<hex-or-text> returns hex of AES-ECB(data + SECRET) under a fixed key. ECB encrypts identical 16-byte blocks identically.
2. Byte-at-a-time: send 15 bytes 'A' so the first unknown SECRET byte lands as the 16th byte of block 0; record that block. Then brute-force the last byte by sending AAAAAAAAAAAAAAA? for every ? and matching the block. Repeat, shrinking the prefix, to recover each byte. Why: aligning one unknown byte per block and comparing to a dictionary of guesses leaks the secret one byte at a time.
3. Run the provided solve.py to recover the full flag.
Lesson: never use ECB; use an authenticated mode (AES-GCM) with random IVs.