ghostđź‘»sonofabot-sec:~#

I scan, I map, I exploit .... Ghost is in your shell!!!

View on GitHub

Easy Web

Could be simple could be hard, depends on you xD. Jk It’s nice and easy

Screenshot_20220515_191929

Heading on to the website, we notice something in the URL (bottom of the page)

Screenshot_20220515_174208

Let’s put this through burp or zap to intercept packets and see what’s going on here looking through the results of zap we the api field once again, let’s try changing the id parameter

Screenshot_20220515_175851

we notice there’s a source for id

Screenshot_20220515_193039

Reading everything about the source from Zap (or burp) you’ll notice something bout gimme-flag giving flag and any other, telling you they know nothing you speaking of.

Screenshot_20220515_180312

And there’s our flag



Back To Home