Information#
Version#
By | Version | Comment |
---|---|---|
noraj | 1.0 | Creation |
CTF#
- Name : ABCTF 2016
- Website : http://abctf.xyz/
- Type : Online
- Format : Jeopardy - Student
- CTF Time : link
Description#
If you could become admin you would get a flag. Link
Solution#
- Launch Element Inspector of Firefox or the Firebug addon and use the network analyser.
- See the request cookie
e2FkbWluOmZhbHNlfQ==
- Un-base64 it:
- Edit the cookie and change the value to
{admin:true}
in base64
- Send it again with a proxy tool like Burp, ZAP, Temper Data
- And TADA! We get into the admin page:
Wow! You're an admin, maybe. Well anyway, here is your flag, ABCTF{don't_trust_th3_coooki3}