Skip to content

Latest commit

 

History

History
82 lines (52 loc) · 2.66 KB

Web.md

File metadata and controls

82 lines (52 loc) · 2.66 KB

Stay Away Creepy Crawlers

Find the flag where they keep the creepy crawlers away.
http://167.71.246.232/
Alternate: http://167.71.246.232:8080/

To find the subdirectory, use dirb
dirb http://167.71.246.232/
http://167.71.246.232/robots.txt

flag{mr_roboto}

Source of All Evil

Find the flag here:
http://167.71.246.232/
Alternate: http://167.71.246.232:8080/

Check out the source code and the flag is in comment line

image

flag{best_implants_ever}

Can't Find It

Find the flag here:
http://167.71.246.232/
Alternate: http://167.71.246.232:8080/

Check out the source code and there is a subdirectory as images

image

http://167.71.246.232/images/ under this directory, we have the list of index for images subdirectory.

image

In this sub-directoy, try to list unlisted subdirectory.
http://167.71.246.232/images/flag

flag{404_oh_no}

Show Me What You Got

Find the "indexes" flag here: http://167.71.246.232/
Alternate: http://167.71.246.232:8080/

We knew that images subdirectory has two different file.

image

http://167.71.246.232/images/aljdi3sd.txt read the file.

flag{disable_directory_indexes}

Header For You Inspiration

Find the flag here: http://167.71.246.232/
Alternate: http://167.71.246.232:8080/

Send the request to Burp Suite and check out the response.

image

Alternate: Check out the source code and take a look Header

image

flag{headersftw}

Ripper Doc

Find the flag in the ripper doc list.
http://167.71.246.232/
Alternate: http://167.71.246.232:8080/

http://167.71.246.232:8080/certified_rippers.php check out this directory.

image

Send the request to Burp Suite.
There is Cookie: authenticated=false change it Cookie: authenticated=true

image

flag{messing_with_cookies}