BugkuCTF_Web——"Administrator System", "Website Hacked"

use tools

  1. Yujian WEB Directory Scan
  2. Burpsuite

1. "Administrator System

The topic is login account

Prompt the administrator system, first try adminto login and capture the account and password
Insert picture description here

Prompt to contact the local administrator

Insert picture description here
The page has a string of base64 encoding, and the password of the administrator account istest123

Insert picture description here
Try to test123log in to the account with a passwordadmin

Also prompted to contact the local administrator
Insert picture description here

Use X-Forwarded-Forpoint to local127.0.0.1

Get FLAG
Insert picture description here

flag{85ff2ee4171396724bae20c0bd851f6b}

2. "The website is hacked"

The topic is a website
Insert picture description here
that has been attacked. Now that it has been hacked and there are loopholes in the website, then there should be a backend and use the sword to scan

Insert picture description here
To access the shell, you need to find the password.
Insert picture description here
Use Burpsuite password dictionary to blast


Insert picture description here
Insert picture description here
Send the package to Intruder, set the payload and sort the results according to the response length

Insert picture description here
hackLogin with password to get FLAG

Insert picture description here

flag{hack_bug_ku035}

Finish

Welcome to leave a message in the comment area.
Thanks for browsing

Guess you like

Origin blog.csdn.net/Xxy605/article/details/108460505