School recently prepared to run a network attack flag race, do not speak, find the platform of the West to practice. Some of the questions are very interesting, decided to write down the idea.
Title Link: http://www.shiyanbar.com/ctf/examctfdetail/32
Click to find the hint IP is not in the Allow list,
Then review the source code, send a tricky.
You can see the meaning of the code. If the IP is in 1.1.1.1. Then you can get the key. So let us think of a powerful Firefox plugin. IP can be forged. So the next idea is to use the Firefox plugin modify header forged IP. It's such a pleasant decision.
Download good modify header plugin. Look at the example below. First "Open Modifyheader"
Then set it as follows. (value is set at the IP you want to fake) set it up after opening "open" because here I am open after the diagram, so the following red icon shows "Stop"
After the "open" is set. Refresh the page, the gratifying thing happened.
OK, key got it: Http_client
Submit Key ... 20 points ...
West PU CTF problem-solving ideas-"seemingly a bit difficult"