Bugku Administrator System

Source: Internet
Author: User

Topic links

Open the Web page, as is the case.

Guess the admin username is mostly admin, then the password randomly loses a test. The following page returns as follows.

What happens to IP-forbidden access? Then with the BP grab packet, found that there is a note in the source code ( <!-- dGVzdDEyMw== --> ), found to be BASE64 encryption, immediately online decryption to get test123, it is estimated that this is the password.

Retry, or IP disable access, consult the data and discover the X-forwarded-for header that can be implemented by using HTTP. Then add a pair of key pairs in the headers: x-forwarded-for:127.0.0.1 disguised as local access.

After the change, go a bit, then got flag:flag{85ff2ee4171396724bae20c0bd851f6b}

X-forwarded-for Bypass server IP address filtering

Bugku Administrator System

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.