Sorry, your browser cannot access this site
This page requires browser support (enable) JavaScript
Learn more >

题目描述

image-20250330122645983

(无附件)

观察

打开网站:

image-20250330122727122

注册个账号然后登录试试:

image-20250330122748728

image-20250330122803142

查看当前cookie:

image-20250330122836415

这段内容base64解码可以得到:

1
2
3
eyJ1c2VybmFtZSI6IjEyMyJ9

{"username":"123"}

渗透

将cookie改成

1
{"username":"admin"}

的base64,即

1
eyJ1c2VybmFtZSI6ImFkbWluIn0=

修改cookie然后刷新网页:

image-20250330123006122

image-20250330123042635

得到flag:HTB{s3ss10n_1nt3grity_1s_0v3r4tt3d_4nyw4ys}