当前位置:网站首页>Cookie is used to collect the admin privileges CTF foundation problem
Cookie is used to collect the admin privileges CTF foundation problem
2022-08-02 04:01:00 【SevenCold】
A very basic ctf cookie question, if you don't know much about cookies, you can go here to see
https://blog.csdn.net/playboyanta123/article/details/79464684
Not much to say, go directly to the picture.
Source code is something useless.
According to the meaning of the question, we directly use burp to intercept and change the cookie
If the permission is insufficient after the naked packet capture, we directly change the cookie.
Comparing the u and r in the cookie, it will be found that both start with 351e766803, so let's decrypt (MD5) the following things.
Found that u is username and r is limited.
So we have to change the latter to get admin privileges.
is to change both u and r to 351e766803+md5 (admin), which is 351e76680321232f297a57a5a743894a0e4a801fc3.
Done!flag it appeared!
边栏推荐
- Shuriken: 1 vulnhub walkthrough
- Shuriken: 1 vulnhub walkthrough
- Orasi: 1 vulnhub walkthrough
- Stable and easy-to-use short connection generation platform, supporting API batch generation
- hackmyvm: juggling walkthrough
- (5) 模块与包、编码格式、文件操作、目录操作
- kali安装IDEA
- CTF之xxe
- [league/climate] A robust command-line function manipulation library
- PHP8.2将会有哪些新东西?
猜你喜欢
CSRF(跨站请求伪造)
New usage of string variable parsing in PHP8.2
IO stream, encoding table, character stream, character buffer stream
Pycharm打包项目为exe文件
(2)Thinkphp6模板引擎**标签
Offensive and defensive world - novice MISC area 1-12
Kali环境下Frida编写脚本智能提示
hackmyvm: kitty walkthrough
(4) Function, Bug, Class and Object, Encapsulation, Inheritance, Polymorphism, Copy
(6) Design of student information management system
随机推荐
Using PHPMailer send mail
[league/flysystem]一个优雅且支持度非常高的文件操作接口
PHP有哪些杀手级超厉害框架或库或应用?
一个网络安全小白鼠的学习之路——nmap的基本使用
13. JS output content and syntax
2.PHP变量、输出、EOF、条件语句
What will be new in PHP8.2?
MySql Advanced -- Constraints
hackmyvm-random walkthrough
php函数漏洞总结
[league/climate]一个功能健全的命令行功能操作库
Function hoisting and variable hoisting
CSRF(跨站请求伪造)
hackmyvm-random walkthrough
PHP8.2 version release administrator and release plan
easyswoole uses redis to perform geoRadiusByMember Count invalid fix
hackmyvm-bunny预排
Smart Tips for Frida Scripting in Kali Environment
SQL classification, DQL (Data Query Language), and corresponding SQL query statement demonstration
(1)Thinkphp6入门、安装视图、模板渲染、变量赋值