Version
By |
Version |
Comment |
noraj |
1.0 |
Creation |
CTF
Description
Can you somehow get the flag from [this][this] website?
[this]:http://yrmyzscnvh.abctf.xyz/web2/
Solution
- Display source code
CTRL + U
- We can see a base64 string
c3RvcHRoYXRqcw==
- So use
stopthatjs
as password and then you see HAAAAaaaaaaaa!
and the flag displayed very very shortly
- Yes because there is this fade script:
fade.js
- So block it, for example with NoScript =>
ABCTF{no(d3)_js_is_s3cur3_dasjkhadbkjfbjfdjbfsdajfasdl}