Syclover tenth geeks title challenge web solution to a problem

The free time to enroll in a bit of clover recruit new game, the game time is one month, the topic came basis really fun, their explanations in mind here about the same time he did not do the subject followed writeup do it again

 

The first question: cl4y: before playing the first line and a cat! : Cat accompany me to play ctf!

 

 To review the elements after page. Find the source code inside tips:

 

 Here we need to get the cat to make a request variable is equal dog, you can get the flag

 

 

The second question: cl4y: Have you seen my knife it

 

 After entering the page is clearly a word Trojan, give away the flag

Syc password to connect using a kitchen knife

 

 There are flag this folder in the root directory, which is the flag of flag.txt

 

 

Third question: Lamber: BurpSuiiiiiit !!!: Pick up your burp, began fighting it

 

Suggesting the use of burpsuite, download the file is opened after sharing a jar package, think of it burpsuite increase extended functionality, import the Extender package

That is, choose Add extender option in the extensions of the inside of burpsuite

 

 With the addition of a output

 

 And prompts us to see the error page

Inside there:

OK, I'll give you the flag now. Here is your flag Syc{BurpExtender_Are_guns_F0r_Hack3rs}

Of course, the following are a base64 encoded, then decoded as follows: The first person to send a screenshot of the egg to Lamber, who will invite him to drink milk tea Ps:. Color Egg in Decompiled Source Code

The first discovery of human egg Lamber would ask him to drink milk tea

The eggs are decompiled source code inside of the jar

I do this topic before the time to find the eggs, not go into here

 

Available in more

Guess you like

Origin www.cnblogs.com/Cl0ud/p/11876018.html