Get-aHead

Point: 20

Category

Web Exploitation

Question

Find the flag being held on this server to get ahead of the competition http://mercury.picoctf.net:53554/

Hint

  • Hint 1: Maybe you have more than 2 choices

  • Hint 2: Check out tools like Burpsuite to modify your requests and look at the responses

Solution

Looking at the website, it's just 2 buttons to change the color on red and blue. I've looked at source code but nothing more.

Open Burp and try to look at request, as the name of the challenge with HEAD word in uppercase, I thought this is the hint and I've known about HEAD method so I've tried to change GET to HEAD and see what's happen -> I got the flag

HTTP/1.1 200 OK flag: picoCTF{r3j3ct_th3_du4l1ty_2e5ba39f} Content-type:
text/html; charset=UTF-8

Flag

picoCTF{r3j3ct_th3_du4l1ty_2e5ba39f}

Last updated