BugkuCTF-WEB4

$what=$_POST['what'];
echo $what;
if($what=='flag')
echo 'flag{****}';

启动BurpSuite,进行抓包

改变请求头为POST,

what=flag,即可获得

posted @ 2021-05-12 13:08  九八年的风  阅读(77)  评论(0编辑  收藏  举报