当前位置:网站首页>Ctfhub eggs
Ctfhub eggs
2022-06-25 04:55:00 【Cn Sirius】
ctfhub Colored eggs
Tools Colored eggs
At first, the idea was that there were tools 8 page , I want to grab a bag and change it to see if there is page 9
I found that no matter which page limit All are 12 but offset in flux
therefore
Set the parameters like this
In the length of 1000 To 6、7 Double click any one of them Click response see Respond to package
On the last line
home page Colored eggs
api Two lines of words are hidden in the middle box
ctfhub{c18732f48a96c40d40a06e74b1305706}
Topic entry Colored eggs
stay web-ssrf Some questions in the middle column will appear when the parameters are wrong
For details, see ctfhub-ssrfpost The last line introduces
official account
A batch of eggs in the official account !
First, bind
Then order colored eggs
It prompts you to reply to the correct keywords
I *#@%
I replied
Colored eggs key word egg ctfhub CTFHub Here, take you CTFer One's own ……
What a surprise flag
Submission Colored eggs
Only the first half was found
In the title submission and wp At the end of the submission page
ctfhub{
029e02eb3a1
e8c49b1132b5
15b652a5f3a8
62013}
Finally, the rest of the egg was not found
After searching the Internet, I realized : thank anweilx Of wp
The first line is at the end of the two pages
The second line is the source code of the two pages Search separately Reward One on the top line is base64 Then turn url One is hex decode
The third line is the picture steganography of the two pages throw sth. into winhex
The fourth line has a hint
aes 256 ecb decode
Other colored eggs
The rest can be searched on the corresponding page egg You can get
边栏推荐
- Upgrade PHP to php7 The impact of X (2), the obsolescence of mcrypt decryption
- WPF 使用 MAUI 的自绘制逻辑
- Why PHP is not safe
- 基于Cortex-M3、M4的精准延时(系统定时器SysTick延时,可用于STM32、ADuCM4050等)
- Méthode de récupération des données d'ouverture du disque dur à l'état solide
- buuctf web
- Virtual honeypot Honeyd installation and deployment
- 分布式websocket搭建方案
- Implementation of websocket long connection by workman under laravel
- SRC platform summary
猜你喜欢

【FLink】access closed classloader classloader.check-leaked-classloader

Kotlin compose listens to the soft keyboard and clicks enter to submit the event

JS arguments

第九章 APP项目测试(2) 测试工具

Difference between asemi high power FET and triode

Méthode de récupération des données d'ouverture du disque dur à l'état solide

dotnet-exec 0.4.0 released

Code scanning payment flow chart of Alipay payment function developed by PHP

MySQL concept and operation (III)

Bingbing's learning notes: implementation of circular queue
随机推荐
XML (VIII)
Ranorex Studio 10.1 Crack
JS call() and apply()
How to make colleagues under the same LAN connect to their own MySQL database
电脑的dwg文件怎么打开
2.0springmvc uses restful
How to download and use Xiaobai one click reload on the official website
The SQL response is slow. What are your troubleshooting ideas?
There is 404 in the laravel visit, except the home page is redirected; Index php
Google Earth engine (GEE) - Global jrc/gsw1_ 1 / batch download of yearlyhistory dataset (China region)
Kotlin Compose 完善toDo项目 Surface 渲染背景 与阴影
为什么SQL语句命中索引比不命中索引要快?
Concat() in JS
Upgrade PHP to php7 The impact of X (I). The problem of session retention. Keep login
ORA-00800: soft external error
Specific operations for uploading pictures in PHP
Penetration information collection steps (simplified version)
OpenSea PHP开发包
Method of opening data recovery of solid state disk
MySQL concept and operation (III)