BUUCTF: The Hijacked Mysterious Gift

Subject address: https://buuoj.cn/challenges#%E8%A2%AB%E5%8A%AB%E6%8C%81%E7%9A%84%E7%A5%9E%E7%A7%98% E7%A4%BC%E7%89%A9

Insert picture description here
Insert picture description here
wiresharkOpen analysis

Insert picture description here
Filtered httppackets

Insert picture description here
I found that this package looks like a login, and trace this package

Insert picture description here
Looks like username and password

PS C:\Users\Administrator> php -r "echo md5('adminaadminb');"
1d240aafe21a86afc11f38a45b541a49
flag{
    
    1d240aafe21a86afc11f38a45b541a49}

Guess you like

Origin blog.csdn.net/mochu7777777/article/details/108890334