http://www.shiyanbar.com/ctf/1788
http://ctf5.shiyanbar.com/web/Session.php
源码:
<?php
session_start();
if (isset ($_GET['password'])) {
if ($_GET['password'] == $_SESSION['password'])
die ('Flag: '.$flag);
else
print '<p>Wrong guess.</p>';
}
mt_srand((microtime() ^ rand(1, 10000)) % rand(1, 10000) + rand(1, 10000));
?>
burp抓包,提交如下,另两者都为空,可以绕过判断
password=
PHPSESSID=