logon
Last updated
Last updated
Point: 100
Web Exploitation
The factory is hiding things from all of its users. Can you login as logon and find what they've been looking at? https://2019shell1.picoctf.com/problem/12284/ (link) or http://2019shell1.picoctf.com:12284
Hmm it doesn't seem to check anyone's password, except for 's?
After login, We'll check source code but nothing to get.
We decided to check cookie of this website using EditThisCookie extension on Google Chrome. We'll see a username: admin with value: False.
Try to change value to True then open source code again, we've got the flag
picoCTF{th3_c0nsp1r4cy_l1v3s_6f2c20e9}