CTF Web安全

[b01lers2020]Scrambled(python脚本编写)

Posted on 2020-04-16,1 min read

cookie中存在transmissions字段
内容是kxkxkxkxshfd16kxkxkxkxsh
去除kxkxkxkxsh就剩下fd16
这个意思是。d是第flag的第16位。第15位是f

写个脚本即可

import requests
from urllib.parse import unquote
url='http://d1653c98-47b9-4f04-b138-71cf1c76520c.node3.buuoj.cn/'
r=requests.session()
cookie=r.get(url).cookies
data=[0]*100
for i in range(300):
    cookie=r.get(url).cookies
    key=unquote(requests.utils.dict_from_cookiejar(cookie)['transmissions'].replace('kxkxkxkxsh',''))[2:]
    value=unquote(requests.utils.dict_from_cookiejar(cookie)['transmissions'].replace('kxkxkxkxsh',''))[0:1]
    data[int(key)]=valuee
for i in data:
    print(i,end='')

下一篇: fmkq的简化版'如此木大'详解(SSRF。python格式化字符串)→