当前位置:网站首页>Cookie is used to collect the admin privileges CTF foundation problem
Cookie is used to collect the admin privileges CTF foundation problem
2022-08-02 04:01:00 【SevenCold】
A very basic ctf cookie question, if you don't know much about cookies, you can go here to see
https://blog.csdn.net/playboyanta123/article/details/79464684
Not much to say, go directly to the picture.
Source code is something useless.
According to the meaning of the question, we directly use burp to intercept and change the cookie
If the permission is insufficient after the naked packet capture, we directly change the cookie.
Comparing the u and r in the cookie, it will be found that both start with 351e766803, so let's decrypt (MD5) the following things.
Found that u is username and r is limited.
So we have to change the latter to get admin privileges.
is to change both u and r to 351e766803+md5 (admin), which is 351e76680321232f297a57a5a743894a0e4a801fc3.
Done!flag it appeared!
边栏推荐
猜你喜欢

Several interesting ways to open PHP: from basic to perverted

(2) Thinkphp6 template engine ** tag

hackmyvm-hopper walkthrough

PHP有哪些杀手级超厉害框架或库或应用?

文件包含漏洞

PHP8.2 version release administrator and release plan

文件上传漏洞

(7) superficial "crawlers" process (concept + practice)

(6) Design of student information management system

MySql Advanced -- Constraints
随机推荐
QR code generation API interface, which can be directly connected as an A tag
1. Beginning with PHP
hackmyvm: may walkthrough
13.JS输出内容和语法
Smart Tips for Frida Scripting in Kali Environment
PHP image compression to specified size
(4) Function, Bug, Class and Object, Encapsulation, Inheritance, Polymorphism, Copy
(3) 字符串
[campo/random-user-agent]随机伪造你的User-Agent
(7) superficial "crawlers" process (concept + practice)
CTF入门笔记之ping
c语言用栈实现计算中缀表达式
Pycharm打包项目为exe文件
12.什么是JS
PHP8.2 version release administrator and release plan
17. JS conditional statements and loops, and data type conversion
攻防世界—MISC 新手区1-12
(7) 浅学 “爬虫” 过程 (概念+练习)
PHP8.2中字符串变量解析的新用法
(1) introduction to Thinkphp6, installation view, template rendering, variable assignment