write-up(web)/webhacking.kr

[Webhakcing.kr] old-15

chanchand 2024. 7. 8. 22:35
반응형

문제풀이


 

- burp suite proxy

<html>
<head>
<title>Challenge 15</title>
</head>
<body>
<script>
  alert("Access_Denied");
  location.href='/';
  document.write("<a href=?getFlag>[Get Flag]</a>");
</script>
</body>

 

  document.write("<a href=?getFlag>[Get Flag]</a>");

 

 

- GET /challenge/js-2/?getFlag 

<script>alert('already solved');</script>
반응형

'write-up(web) > webhacking.kr' 카테고리의 다른 글

[Webhacking.kr] old-16  (0) 2024.07.08
[Webhacking.kr] old-26  (0) 2024.07.08
[Webhacking.kr] Memo Service  (0) 2023.11.05
[Webhacking.kr] 🍊  (0) 2023.11.03
[Webhacking.kr] baby toctou🍼  (0) 2023.11.03