Skip to main content

Calculat3 M3

Here! http://web.ctflearn.com/web7/ I forget how we were doing those calculations, but something tells me it was pretty insecure. We can start by performing some basic calculation like 1+1.

1

Let's check the Burpsuite Proxy > HTTP History.

2

Now let's send this request to the Repeater.

3

At the bottom of the request we can see the expression that we inputted.

We can replace the expression with ;ls and send the request.

4

Flag

CTFlearn{watch_0ut_f0r_th3_m0ng00s3}