当前位置:网站首页>Cookie is used to collect the admin privileges CTF foundation problem
Cookie is used to collect the admin privileges CTF foundation problem
2022-08-02 04:01:00 【SevenCold】
A very basic ctf cookie question, if you don't know much about cookies, you can go here to see
https://blog.csdn.net/playboyanta123/article/details/79464684
Not much to say, go directly to the picture.
Source code is something useless.
According to the meaning of the question, we directly use burp to intercept and change the cookie
If the permission is insufficient after the naked packet capture, we directly change the cookie.
Comparing the u and r in the cookie, it will be found that both start with 351e766803, so let's decrypt (MD5) the following things.
Found that u is username and r is limited.
So we have to change the latter to get admin privileges.
is to change both u and r to 351e766803+md5 (admin), which is 351e76680321232f297a57a5a743894a0e4a801fc3.
Done!flag it appeared!
边栏推荐
- 12. What is JS
- (1)Thinkphp6入门、安装视图、模板渲染、变量赋值
- MOMENTUM: 2 vulnhub walkthrough
- (6) 学生信息管理系统设计
- ES6 array extension methods map, filter, reduce, fill and array traversal for…in for…of arr.forEach
- (3) Thinkphp6 database
- Scrapy爬虫遇见重定向301/302问题解决方法
- PHP8.2 version release administrator and release plan
- (7) superficial "crawlers" process (concept + practice)
- ES6 iterator explanation example
猜你喜欢
随机推荐
(8) requests、os、sys、re、_thread
Eric靶机渗透测试通关全教程
一个网络安全小白鼠的学习之路——nmap的基本使用
(6) Design of student information management system
Solve the problem of Zlibrary stuck/can't find the domain name/reached the limit, the latest address of Zlibrary
IO streams, byte stream and byte stream buffer
阿里云MySQL5.7安装以及部分主要问题(总和)
Shuriken: 1 vulnhub walkthrough
hackmyvm-random walkthrough
[league/flysystem]一个优雅且支持度非常高的文件操作接口
CTF入门之md5
CTF入门之php文件包含
(3) 字符串
TypeScript error error TS2469, error TS2731 solution
web渗透必玩的靶场——DVWA靶场 1(centos8.2+phpstudy安装环境)
(4) Function, Bug, Class and Object, Encapsulation, Inheritance, Polymorphism, Copy
CTF入门笔记之ping
Multithreading (implementing multithreading, thread synchronization, producer and consumer)
(3)Thinkphp6数据库
16.JS事件, 字符串和运算符









