Planet DesKel

DesKel's official page for CTF write-up, Electronic tutorial, review and etc.

12 September 2020

Webhacking.kr write-up: old-42

Link point tag
old-42 200 HTML

Hello there, welcome to another webhacking.kr CTF writeup. Today’s is all about HTML and some base64 encoding.

question

The goal is simple, download the restricted flag.docx file. Let’s check out the source code.

source

Referring to the code, there is a base64 encoded GET request value for ?down. Decode the value and we get the following result

decode

It is a file name but in base64! The answer is clear now, encode flag.docx in base 64 format

encode

Visit the following URL with the encoded text as ?down value.

https://webhacking.kr/challenge/web-20/?down=ZmxhZy5kb2N4

Download the flag an open up with docx reader such as Libreoffice docx reader.

solve

solve

tags: webhacking.kr - html

Thanks for reading. Follow my twitter for latest update

If you like this post, consider a small donation. Much appreciated. :)


Vortex


© 2020 DesKel