CTF toolkit: lib (net, crypto_utils), templates per category, scaffold, cheatsheet, ps_and_qs example
This commit is contained in:
@@ -0,0 +1,29 @@
|
||||
"""
|
||||
WEB skeleton — copy & fill. (p4-team style: read the source, find the
|
||||
sanitization-order bug, then script the request.)
|
||||
|
||||
Key lesson from 'piapiapia': filter() ran AFTER serialize() -> length
|
||||
manipulation / object injection. Always diff the order of sanitize vs use.
|
||||
"""
|
||||
import requests
|
||||
|
||||
BASE = "http://challenge.host:port"
|
||||
S = requests.Session()
|
||||
|
||||
|
||||
def get_token():
|
||||
r = S.get(BASE + "/login")
|
||||
# parse CSRF / cookies as needed
|
||||
return None
|
||||
|
||||
|
||||
def exploit():
|
||||
# 1) Find the input that bypasses validation (array, encoding, filter order).
|
||||
# 2) Craft payload.
|
||||
# 3) Send & parse response for flag.
|
||||
r = S.post(BASE + "/endpoint", data={"nickname[]": "PAYLOAD"})
|
||||
print(r.text)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
exploit()
|
||||
Reference in New Issue
Block a user