ctf-writeup/DeadSec CTF 2023/FRSS
Muhammad Daffa 8925316c31 feat: added 2 CTF writeup 2023-05-21 21:57:52 +07:00
..
images feat: added 2 CTF writeup 2023-05-21 21:57:52 +07:00
README.md feat: added 2 CTF writeup 2023-05-21 21:57:52 +07:00

README.md

FRSS

-

About the Challenge

We got a websites that can make requests to other websites and display the response

preview

We need to access /hehe.txt by using that feature. However there is a limit of characters that we can input into that form

preview_2

How to Solve?

In order to read the flag, we need to access the website internally and access the /hehe.txt endpoint

At first, I inputted 127.0.0.1/hehe.txt but the response is Oh no no, url is too long I can't handle it. And then I and found this payload

PayloadAllTheThings

So, my final payload was:

0.0.0.0/hehe.txt

flag

dead{Ashiiiibaaa_you_hAv3_Pybass_chA11}