30 lines
747 B
Python
30 lines
747 B
Python
"""
|
|
WEB skeleton — copy & fill. (p4-team style: read the source, find the
|
|
sanitization-order bug, then script the request.)
|
|
|
|
Key lesson from 'piapiapia': filter() ran AFTER serialize() -> length
|
|
manipulation / object injection. Always diff the order of sanitize vs use.
|
|
"""
|
|
import requests
|
|
|
|
BASE = "http://challenge.host:port"
|
|
S = requests.Session()
|
|
|
|
|
|
def get_token():
|
|
r = S.get(BASE + "/login")
|
|
# parse CSRF / cookies as needed
|
|
return None
|
|
|
|
|
|
def exploit():
|
|
# 1) Find the input that bypasses validation (array, encoding, filter order).
|
|
# 2) Craft payload.
|
|
# 3) Send & parse response for flag.
|
|
r = S.post(BASE + "/endpoint", data={"nickname[]": "PAYLOAD"})
|
|
print(r.text)
|
|
|
|
|
|
if __name__ == "__main__":
|
|
exploit()
|