前言
题目描述
I heard cookies and string formatting are safe in 2019?
http://challenges.fbctf.com:8083
(This problem does not require any brute force or scanning. We will ban your team if we detect brute force or scanning).
题解
1@1登录
session解个码
看来得想办法找到key
在name和address试了半天,没想到event_important才是注入点
先试试event_important=__dict__
tplmap跑了一圈没跑出来,可惜
key为
fb+wwn!n1yo+9c(9s6!_3o#nqm&&_ej$tez)$_ik36n8d7o6mr#y
构造一下session,结束